Quantum advantage—the defining goal of the quantum computing industry—collapses for every task with classical inputs and outputs in a new mathematical construction posted to the arXiv on September 10, 2026. Yet inside that same constructed world, a purely quantum cryptographic primitive called an EFI pair survives all known attacks. The result permanently severs the link between quantum computational power and quantum secrecy.
At the same moment, an experimental group in Barcelona has shown that entangled magnons—quantum spin waves—reveal their hidden correlations through a measurable velocity deficit, without any direct observation of their quantum state. The timing is not coincidental: both findings map the boundary where quantum correlations persist even when the usual signatures of quantum advantage disappear.
How It Works
The preprint ([arXiv:2609.11901]) constructs a single classical oracle that answers every question about the output probabilities of quantum samplers. In this world, one-way puzzles—classical objects that are easy to sample but hard to solve—do not exist, even with an unbounded verifier. Yet EFI pairs, which are pairs of efficiently preparable quantum states that are statistically far yet computationally indistinguishable, withstand every distinguisher that queries the oracle classically and saves a single superposition query for the end.
“EFI pairs are efficiently preparable quantum states, statistically far yet computationally indistinguishable.”
EFI pairs, introduced by Brakerski, Canetti, and Qian at ITCS 2023, are a candidate for the weakest possible building block of quantum cryptography. They can implement tasks such as bit commitment and oblivious transfer without requiring full-blown quantum one-way functions. Until now, it was unknown whether they could exist in a world free of one-way puzzles—classical primitives that are easy to generate and hard to invert. The new oracle provides the first rigorous proof that EFI pairs are a strictly weaker assumption, reshaping the foundation of post-quantum security.
The proof rests on a communication complexity reduction. The oracle hides a Haar-random half-dimensional subspace and forces the adversary to interact with it classically, except for a single superposition query at the very end. The attacker’s classical-phase queries correspond to messages in a two-party protocol where one party holds the secret subspace. The best known classical protocol for the Vector-in-Subspace problem, established by Klartag and Regev at STOC 2011, sets an upper bound on information leakage. Because the EFI pair remains statistically far, the adversary cannot distinguish the states beyond that bound. Consequently, the same oracle eliminates any quantum advantage on tasks with classical inputs and outputs, and even denies proofs of quantumness from classical-message protocols. A quantum party becomes classically simulable. Yet the quantum states themselves—the EFI pair—remain physically real and cryptographically useful.
While the oracle is a mathematical instrument, a team at ICFO – The Institute of Photonic Sciences in Barcelona discovered a physical parallel. In a tuned solid-state bath, magnons—the quantized excitations of spin waves—experience a dressing by surrounding quantum particles. This dressing slows their propagation below the speed predicted by bare magnon theory, producing a velocity deficit. The deficit directly correlates with the degree of entanglement within the magnon pair. By increasing the on-site Coulomb repulsion, the researchers diminish the dressing and weaken the paired states, confirming the causal link. No direct measurement of the complex many-body wavefunction is needed; a simple speed measurement—a classical observable—reads out the entanglement. The setup also serves as a platform for quantum simulation of spin liquids and frustrated magnets, where entanglement effects are central.
An analogy: imagine an unbreakable safe whose contents remain forever locked. A distant vibration in the floor—something entirely classical—betrays that the safe is indeed still locked, without ever opening it. In both stories, the quantum secret leaves a classical footprint that is invisible to brute-force attacks but detectable through indirect channels.
The anonymous authors also state conjectures on removing the restriction that the adversary may make only one superposition query. If those conjectures hold, the separation survives even with polynomially many superposition queries, further cementing the independence of EFI pairs from one-way puzzles. Unlike quantum key distribution, which requires authenticated classical channels and strong assumptions, EFI pairs could enable post-quantum protocols that minimize trust assumptions.
Who's Moving
The anonymous preprint builds on foundational work by Brakerski, Canetti, and Qian (ITCS 2023) on EFI pairs and by Khurana and Tomer (STOC 2024) on one-way puzzles. Its rigorous oracle separation settles a long-standing open problem in quantum cryptography and will influence the next iteration of NIST’s post-quantum standards. Meanwhile, the ICFO group extends a line of research into magnon-based entanglement detection that has attracted attention from quantum sensing and quantum networking communities.
On the hardware front, IBM (NYSE: IBM) continues to push circuit sizes with its 1,121-qubit Condor processor, which demonstrated error-mitigated sampling in 2025. Google Quantum AI (Alphabet, NASDAQ: GOOGL) targets a logical-qubit milestone by 2027. IonQ (NYSE: IONQ) scales trapped-ion systems, and Quantinuum pursues high-fidelity quantum charge-coupled devices. These heavyweights and a swarm of startups are betting that quantum advantage will manifest at scale—a bet that the new oracle separation does not disprove but sharpens, by showing that not every quantum resource translates into a classical speedup.
Investment continues to pour in. Global venture capital in quantum technologies topped $2.4 billion in 2025, according to The Quantum Insider, and DARPA’s US2Q program has committed $100 million to demonstrate a utility-scale quantum computer by 2029. The European Quantum Flagship allocated €1 billion for the 2021–2030 period, and China’s national quantum program has invested over $15 billion. The cryptographic breakthrough may accelerate VC interest in post-quantum security startups, while the magnon finding could funnel funding into quantum sensing and quantum networking companies such as Aliro Quantum and Qunnect. Startup Aliro Quantum raised $45 million in Series B funding in 2025 to build entanglement-based network infrastructure, and Qunnect secured $20 million in Series A for quantum-secured communications.
These theoretical and experimental signals are already reshaping strategic roadmaps. NIST’s Post-Quantum Cryptography standardization group is evaluating the implications of EFI pairs for future algorithm designs, while quantum networking consortia such as the Quantum Internet Alliance are eyeing magnon transducers for entanglement distribution.
Why 2026 Is Different
The year 2026 delivers a dual reckoning. On the theory side, the oracle separation proves that EFI pairs are a strictly weaker assumption than one-way puzzles, reorienting the quest for minimal quantum cryptography. On the experimental side, the magnon velocity deficit hands engineers a classical ruler for entanglement, accelerating quantum sensor design and quantum networking diagnostics.
In 12 months, expect replication of the magnon dressing effect in alternative materials such as yttrium iron garnet films and cold-atom simulators. Within three years, this metrology could be integrated into prototype quantum networking nodes that require entanglement distribution without full state tomography. By 2031, the ability to detect entanglement through classical proxies might simplify the certification of links in a quantum internet. The global quantum sensing market is projected to reach $1.2 billion by 2030, and the quantum cryptography market $2.5 billion by 2028, according to industry forecasts. DARPA’s 2029 target for a utility-scale quantum computer adds pressure to deliver practical quantum advantage before the decade closes.
The magnon velocity deficit also hints at a broader principle: certain quantum correlations can be mapped to classical observables in solid-state systems without breaking the entanglement. This could become a diagnostic tool for quantum repeaters, removing a major obstacle for the quantum internet—the need to perform full tomography on distributed entangled pairs. Groups at TU Delft, the University of Chicago, and NTT are exploring such transducers. Magnon transducers could replace cryogenic optical conversion, reducing cost and complexity of quantum repeaters.
The separation sharpens the essential distinction between quantum advantage—the ability to compute faster—and quantum security, which can exist without any speedup. This insight will guide future investment, steering some teams toward quantum cryptography and sensing rather than chasing universal quantum supremacy.
Conclusion
These two developments—the collapse of quantum advantage for classical I/O in an oracle world and the emergence of a classical entanglement signature in magnons—reshape the conversation. They demonstrate that quantum correlations can endure and be useful even when traditional computational acceleration disappears. Together, they prove that entanglement is a resource that can outlast computational supremacy—and can be read through the noise. In short: Quantum advantage for classical input-output tasks vanishes in specific relativized settings, yet entanglement persists as both a cryptographic resource and a physically measurable signal.
