Elliptic Curve vs Quantum: The 2026 Estimates From Google, IonQ Authors and Others
Why elliptic curves matter
Elliptic curve cryptography protects most modern HTTPS connections, many messaging apps and the signatures on Bitcoin, Ethereum and Solana-style wallets. Its quantum weakness is the same one as RSA: Shor's algorithm can solve the underlying discrete logarithm problem. A 256-bit curve is smaller than a 2048-bit RSA key, so the quantum machine needed can be smaller too. That is why curve estimates draw so much attention. It also fits what the Global Risk Institute analysis noted: its survey asked only about RSA, while elliptic curves are a more immediate worry for many organizations (a view reported by PostQuantum.com).
Google Quantum AI, 30 March 2026
The whitepaper is titled "Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities: Resource Estimates and Mitigations." Authors include Ryan Babbush, Craig Gidney and Hartmut Neven of Google, with Justin Drake of the Ethereum Foundation and Dan Boneh of Stanford. From the abstract I read directly:
- Shor's algorithm for the 256-bit secp256k1 curve can run with at most 1,200 logical qubits and 90 million Toffoli gates, or at most 1,450 logical qubits and 70 million Toffoli gates.
- On superconducting hardware with 10 to the minus 3 physical error rates and planar connectivity, those circuits could execute in minutes using fewer than half a million physical qubits.
- To avoid handing out an attack recipe, the authors used a zero-knowledge proof to validate the results without disclosing the circuits.
- They split machines into "fast-clock" (superconducting, photonic) and "slow-clock" (neutral atom, ion trap) types, and say first fast-clock machines could enable "on-spend" attacks on public mempool transactions of some cryptocurrencies.
- They urge vulnerable communities to move to post-quantum cryptography without delay.
A secondary report adds that after a public key is revealed, the remaining computation takes roughly nine minutes. I could not confirm that figure in the part of the paper I read, so treat it as reported only. The whitepaper is a company document with its own review path, not a finished machine, and the abstract speaks of the "expected emergence" of such computers, not a date. For how this plays out for coins, see will quantum break Bitcoin and Solana and exposed public keys.
IonQ authors, September 2026
IACR ePrint 2026/1916, by IonQ researchers, is titled "Computing 256-bit elliptic curve discrete logarithms in 26 days on a fault-tolerant trapped-ion quantum computer with 20,000 qubits." The abstract reports about 1,450 logical qubits and 40 million Toffoli gates, and about 25.7 days of execution using 19,397 physical qubits, with an estimated 63% success probability, for IonQ's "Walking Cat Architecture." It was received 8 September 2026. This is a company-authored preprint about a machine that does not exist. It shows the trade-off clearly: fewer qubits, far more time (see resource estimates explained).
Georgia Tech preprint, September 2026
Tech Times reports on a preprint by Sunghyeon Jo and Gye Jin Lee (IACR ePrint 2026/2014) claiming about 5n/2 logical qubits for an n-bit prime field curve, an improvement of roughly 17% over an earlier 3n coefficient, with a lower Toffoli count. The article stresses that it is a preprint, that it gives no concrete P-256 figure, and that the extrapolation to 256 bits (around 640 logical qubits) is the article's own, not the paper's. I read only this secondary report.
Side by side
| Source (date) | Logical qubits | Physical qubits and time |
|---|---|---|
| Google Quantum AI (30 Mar 2026) | Up to 1,200 or up to 1,450 | Under 500,000, minutes, superconducting assumptions |
| IonQ authors (Sep 2026) | About 1,450 | About 19,397, about 25.7 days, trapped ions |
| Georgia Tech preprint (Sep 2026, via press) | 5n/2 plus smaller terms | Not stated in the coverage I read |
Reading this calmly
- Different models, not a race to a date. Each paper assumes its own hardware. None says a date.
- Nothing here is built. Hardware has to reach the scale, speed and error rates assumed.
- Policy matters. The Google paper treats migration as the answer, and chains and companies have time to act. See PKI challenges and crypto agility.
I could not verify other 2025 elliptic curve papers beyond what is named above, so this is not a complete literature survey. This is education, not financial advice, with no price view on any token. The QNT memecoin is independent of Quantinuum Ltd.
Sources and further reading
- Babbush et al., Google Quantum AI (30 March 2026): Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities, whitepaper
- IonQ authors (September 2026): Computing 256-bit elliptic curve discrete logarithms in 26 days on a fault-tolerant trapped-ion quantum computer, IACR ePrint 2026/1916
- Tech Times (15 September 2026): coverage of the Georgia Tech elliptic curve preprint
- The Quantum Insider (31 March 2026): three papers rewriting the quantum threat timeline
- PostQuantum.com: analysis of the Quantum Threat Timeline Report 2025
Reported as of 2026-10-09. Resource estimates are theoretical preprints or whitepapers, surveys are opinion, and government dates are planning targets, so check the primary documents. Nothing here is financial advice or a prediction of any asset price. The QNT memecoin is independent of Quantinuum Ltd, the real company, and of every lab, chain and government named on this page.
Frequently asked questions
How many qubits could break Bitcoin's curve according to Google?
Google Quantum AI's 30 March 2026 whitepaper reported circuits for secp256k1 with up to 1,200 logical qubits and 90 million Toffoli gates, or up to 1,450 and 70 million, running in minutes on fewer than half a million physical superconducting qubits under its stated assumptions.
Does this mean Bitcoin is broken?
No. No such machine exists. The whitepaper itself urges migration to post-quantum cryptography, which gives the community time to act.
Why did one paper say 26 days?
An IonQ-authored preprint reported about 25.7 days on 19,397 trapped-ion physical qubits. Slow-clock hardware can use fewer qubits but takes longer.
Keep reading
- Elliptic Curve Cryptography Explained for Crypto Users
Elliptic curve cryptography secures Bitcoin and Solana wallets. Learn how it works in plain English and why a large quantum computer could threaten it. - Will Quantum Computers Break Bitcoin and Solana?
A calm, factual look at the quantum threat to Bitcoin, Solana and other blockchains, what is safe now, and what could change. - Exposed Public Keys and Address Reuse: Who Is Actually Vulnerable to Quantum?
Why some coins are more exposed to a future quantum attack than others, and how address reuse and Taproot play into it.
All Quantum computing guides | Back to top | Search the site
Main pages: Quantum computing explained | Quantum and crypto | Companies | Quantum news | Glossary