Every time someone attempts to create an unbreakable password or send a private message, they must trust a number. That number is supposed to be one that a computer has generated completely at random. Unfortunately, no computer has been able to actually guarantee that this number is truly random. Until now.
To get truly random numbers, physicists at ETH Zurich in Switzerland turned to the quantum world. They can prove that the numbers their technique spits out really are random (with only a vanishingly small chance that they are wrong).
A number that’s proven to be random can help protect private data through encryption. Here’s why. Encryption works by turning private information into a scrambled code using a secret “key.” The key is built from a random number. If that number is truly random, then no one can unscramble the information without the key. However, if it’s not truly random, a hacker could figure out the pattern behind it and reconstruct the key. And that would expose the formerly masked information.
“When randomness is weak, the keys built from it become guessable. An attacker can shrink work that should take billions of years into something practical,” explains David Holtzman. In other words, a guessing game that could take longer than the age of the universe becomes a task that a computer might pull off in months or years.
Holtzman did not take part in the new work. Still, he knows about such things. He’s worked as a cryptographer for the U.S. National Security Agency and now runs a cybersecurity firm called Naoris Quantum Protocol.
The new study cites real cases where weak randomness let attackers steal private data — and offers a new solution.

Solving the bias problem
Regular computers haven’t been able to make truly random numbers because those machines are designed to be predictable. In a normal computer, the same starting conditions should always produce the same outcome. To create a “random” number, these devices use a formula and a starting number, called a “seed.” And while the outcome may look random, it’s really only sort of random.
Scientists call this pseudo-randomness. Why? If someone guesses the seed, they can rebuild the whole sequence of steps a computer takes to make a “random” number. This will break the code meant to securely mask data.
But a natural solution exists in the quantum world. The word “quantum” describes the very smallest things in our universe, such as tiny particles. In this realm of microscopic particles, physical processes are actually random. In fact, researchers have already used quantum devices to generate randomness. But so far, no device used to capture that randomness has been perfect. Small hardware flaws have kept the results from being perfectly random.
In the past, researchers have tried to build better, less-biased devices. The ETH Zurich team found a different way: a two-part system that works even if the devices are imperfect. The setup relies on running two experiments at once, in two different places, explains physicist Renato Renner. This kept the results of one from being able to directly affect the other.
Think of the split experiments like two rubber balls. The balls look the same. But each one has its own tiny surface imperfections. Those unique features give each ball its own slight bias, making it bounce one way more often than another. Because each ball was made separately, its imperfections have nothing to do with the other’s.
In the same way, ETH Zurich’s two devices each produced random numbers with its own bias. But because the devices were separated, the biases in their outputs were completely unrelated. Renner’s team collected results from its two experiments, then combined their findings. To do this, they used something called a randomness extractor.
That extractor doesn’t fix either experiment’s output to be perfectly random on its own. Instead, it looks at the two outputs together. Then it combines them using a mathematical formula. Because the flaws in each device’s random number are unrelated, combining them cancels those flaws out. The result is truly unpredictable.
For the ETH Zurich experiment, the team used two quantum devices 30 meters (about 100 feet) apart. This separation made sure no signal — even if it were traveling at the speed of light — could pass between them before each outcome was generated. It’s one guarantee that the output from one could not influence the other.

Each device measured the outcome of a quantum event, such as a photon passing through a light-splitting device. Running the results from both through the randomness extractor increased the randomness already present in each.
Renner’s group described how it did this on May 27 in Nature.
Passing the ‘Bell test’
Proving randomness is very hard, says Nicole Yunger Halpern, who did not take part in the new work. “We can certify a random-number generator only by proving that no possible attack can have corrupted it,” explains this quantum physicist. She works at the U.S. National Institute of Standards and Technology in Gaithersburg, Md.
To confirm that the output from its extractor was genuine, the ETH Zurich team used something known as a Bell test. This physics test proves a quantum result wasn’t faked or planned in advance.
Passing this test meant something important. The team didn’t have to trust that their devices were perfect. A device might have a hidden flaw or secretly been tampered with. Either way, it couldn’t fake the exact pattern found. This pattern could only be due to genuine, unpredictable quantum behavior.
Scientists call this type of proof “device-independent.” The certainty comes from the test itself. There is no need for blind faith in the equipment or the test setup.
In 2025, a team led by Minzhao Liu at JPMorgan Chase in New York City claimed it had generated numbers with “certified randomness.” However, its claim relied on one big premise. It assumed that no classical — that is, non-quantum — computer would ever be powerful enough to copy its results. (Otherwise, a hacker using an ordinary computer might eventually guess or predict that team’s random numbers.)
“Our result,” says Renner, “does not require any [limits] on the capabilities of someone trying to predict the randomness.” As such, he claims this is the first real-world showcase that natural quantum randomness can be turned into something perfectly random. Renner and a co-worker first proposed this idea in 2012. Now, he’s helped show it’s true.
Do you have a science question? We can help!
Submit your question here, and we might answer it an upcoming issue of Science News Explores

