On September 8, 2026, IonQ published a design for a future quantum computer with about 20,000 physical qubits that could solve the mathematical problem underlying Bitcoin's digital signatures in 25.7 days per attempt. The study works out the required circuits in concrete detail, including error correction and ion movement. It does not mean Bitcoin has actually been broken. Still, it moves the debate over quantum attacks away from "how many qubits are needed" and toward which machine precision, run for how long, would put which funds at risk. To judge the "26 days" figure, you have to consider the success probability together with how long a public key is visible to an attacker.

AD

"26 days" is the time for a single attempt

The technical paper by IonQ's Thomas Häner and colleagues targets secp256k1, the elliptic curve Bitcoin uses. The research applies Shor's algorithm to the elliptic-curve discrete logarithm problem, whose difficulty is what makes it hard to derive a private key from a public key. The paper is dated September 3 and was published by IonQ on its own website. We could not confirm publication in a peer-reviewed journal.

The central estimate is 19,397 physical qubits and 25.7 days, but the latter is the time for one attempt, not a guaranteed time to success. The paper gives two different estimates of overall success probability: 40.7% and 63.3%.

The 40.7% figure starts from a rigorous mathematical lower bound on the algorithm's success probability and combines it with the effects of approximation and estimated logical errors in the hardware. The 63.3% figure starts from an estimate that places additional assumptions on the mathematical portion. Even the 40.7% number therefore includes a physical device model, and it should not be read as an unconditional guarantee for a real machine.

The scale needed when repetition is required can be calculated from the paper's own numbers. If a 25.7-day attempt is repeated independently with the same success probability, cumulative success probability exceeds 95% after 6 attempts (154.2 days) at 40.7%, or after 3 attempts (77.1 days) at 63.3%.

Assumed per-attempt success probability Minimum attempts for cumulative success above 95% Compute time if run sequentially
40.7% 6 154.2 days
63.3% 3 77.1 days

This is a conditional calculation using the success probability estimates on page 7 of the paper and the 25.7-day figure, with cumulative probability computed as 1 − (1 − p)^n and time as 25.7 days × n. It does not include extra time for machine stoppages, recovery, or reinitialization. It is not a forecast of a real-world break, but it shows how far off the reading "it will surely succeed after 26 days" would be.

Inside the design that fits into about 20,000 qubits

The computation uses 1,457 logical qubits and about 39 million Toffoli gates. A logical qubit is a unit of computation that spreads information across multiple physical qubits and protects it with error correction. The number of physical qubits does not equal the number of qubits that can be reliably used for computation.

IonQ reworked its "Walking Cat" design, announced in April, for this calculation. Ions are moved across a plane to link qubits in distant locations, and information is protected with quantum low-density parity-check (qLDPC) codes. The Q102 code adopted here can store 22 logical qubits in 102 data qubits, but auxiliary qubits for detecting errors and other resources are needed separately. Counting those auxiliary resources brings the total to 19,397.

The arithmetic circuit was also shortened. The paper says it improved on circuits from earlier research, reducing the Toffoli gate count from about 58 million to about 39 million. It also adds a circuit that supplies the special quantum states used in Toffoli operations, allowing the related CCZ operation to be executed efficiently. Compared with an implementation that simply decomposes it into smaller operations, the time for this operation is cut to 1/31.

However, the 31-fold speedup is a comparison of that particular operation, not a claim that the entire Bitcoin-breaking calculation became 31 times faster. The computation also requires moving and measuring information. The paper translates each part into a sequence of measurements executable on the device, estimating 75,251,329 measurement layers in total. With an average of about 29.5 milliseconds per layer, it arrives at the roughly 25.7-day runtime.

This level of detail is the study's value. Earlier research has already proposed using fewer qubits, and lining up figures from machines built on different approaches does not establish a performance ranking. IonQ's design examines whether other computations can proceed while qubits are being moved and whether the necessary auxiliary states can be supplied in time.

In addition, secp256k1 has a feature that makes calculations easier to simplify: the form of its prime. The qubit counts and days here cannot be carried over directly to breaking other elliptic curves or RSA.

AD

Remaining hardware challenges: error rates and long-duration operation

The paper assumes an error rate of 0.01% for two-qubit gates and 0.001% for single-qubit operations. These settings rest on experiments with small ion-based devices and achievable performance, but they are not measurement results from running a roughly 20,000-qubit machine for about 26 days.

The model also anticipates that ions carrying the qubits will be lost during computation. It assumes ion loss does not cascade to other ions, and spare ions are replenished as the computation continues. The device's total count includes 34 shared spare ions, and the required average replenishment rate is estimated at about 9.7 ions per second.

Achieving that replenishment rate is a separate challenge from protecting computational information over a long period while replenishing. The paper combines memory errors, errors in states used for computation, depletion of spare ions, and other factors, estimating the probability of logical failure at about 26%. That combination also assumes the individual failure mechanisms are statistically independent. The success probability figures rest on an accumulation of such specific conditions.

At the Superion 256 announcement the same day, IonQ reported manufacturing a 256-qubit QPU at SkyWater and first ion trapping on a prototype. Deliveries to customers are planned for 2027. For Superion 10K, being developed as the first generation to run Walking Cat, the company gave an outlook of achieving full fault tolerance through CMOS integration in the lab in 2027 and commercially in 2028.

Manufacturing and trapping results, future product plans, and a design for cryptographic computation each represent different levels of achievement. IonQ itself explains that no quantum computer capable of running this calculation exists today, and that it has not touched any real wallets or networks. There is no basis for reading the 2028 roadmap as the year Bitcoin will definitely be broken.

Long-exposed public keys become a problem first

What is at risk in Bitcoin is the digital signature that proves authority to spend funds. If a private key can be recovered from a public key, an attacker can forge signatures posing as the owner for any spending that key authorizes. This research does not demonstrate breaking SHA-256, which is used in mining, or rewriting the blockchain's full history. The target is the discrete logarithm problem corresponding to a single public key, and it is not a calculation that decrypts every wallet at once in 26 days.

In addition to conventional ECDSA signatures, the Schnorr signatures used in Taproot also use secp256k1. Because they depend on the same mathematical problem, the name "Schnorr" alone does not avoid quantum attacks.

Furthermore, the time available to an attacker varies with how funds are held. The Bitcoin improvement proposal BIP 360 distinguishes between attacks on public keys exposed over a long period and attacks carried out within the waiting time for a transaction to be confirmed.

Fund state / format How the public key appears Relation to this estimate
P2PK Public key recorded from the start While funds remain, key recovery can be attempted over an extended time
Taproot P2TR Output public key recorded The key-path spending route becomes a target for long-exposure attacks
P2PKH / P2WPKH with public key not yet exposed Hash of the public key recorded Recovery computation from this public key may not be startable from the record alone
Reused funds after the public key was revealed in a spend The same key becomes known Funds remaining under the same key, among others, can become long-exposure targets

The classification is based on "Long Exposure vs Short Exposure Attacks" in BIP 360. However, exposure also occurs through other routes such as extended public keys, so this table does not establish safety from address format alone.

Even when a public key is hidden behind a hash, it is revealed at spend time so the signature can be verified. Recovering the private key and cutting into the transaction within that short window would generally require a machine far faster than one running calculations over weeks. By contrast, if funds remain for a long time under keys that are already public, an attacker has time to run the computation.

So as the 25.7-day estimate approaches reality, the first problem may be long-dormant exposed keys, before any scenario in which transfers are seized instantly. A judgment that "it can't finish before confirmation, so it isn't a threat" overlooks these funds.

AD

Hiding public keys and post-quantum signatures serve different roles

BIP 360 proposes a new output type, "Pay-to-Merkle-Root (P2MR)." It removes the route present in Taproot that allows spending with a valid signature for a public key, and instead uses the hash of a tree structure that bundles spending conditions. By not carelessly exposing public keys, it can offer resistance to key recovery over a long period.

However, as of September 9, 2026, BIP 360 is in Draft status and is not an adopted feature. The proposal itself does not include introducing post-quantum signatures, and leaves protection against short exposure at spend time to the future addition of a signature scheme. Hiding keys while funds are held and ensuring signatures cannot be forged even when keys are public are different kinds of defense.

Post-quantum signatures themselves do have standards. On August 13, 2024, the U.S. National Institute of Standards and Technology (NIST) standardized ML-DSA and SLH-DSA. These are not methods for concealing transmitted content but for verifying a signer's authenticity and that data has not been altered, which is the kind of technology that addresses the authentication problem here.

Even so, a completed standard does not mean Bitcoin's signatures will be swapped automatically. New validation rules must be introduced to the network, wallets must handle the new formats, and existing funds must be moved. While the qubit count on the research side shrinks, the defending side needs time to carry out implementation and migration.

Moving existing funds is a matter of both technology and consensus

Some proposals would set a migration deadline. BIP 361 assumes quantum-resistant outputs are introduced, then about three years after activation would prohibit sending funds to destinations vulnerable to quantum attack, and two years after that would impose recovery conditions on spending with the old ECDSA and Schnorr signatures that distinguish quantum attackers from legitimate holders.

This, too, is a Draft and not a deadline settled for Bitcoin. Because the starting point is a future activation, no specific calendar year can be calculated as a migration deadline at present.

The hard part is how to treat funds that could not be migrated. If spending were allowed on the strength of a private key derived from a public key alone, a future quantum attacker could satisfy that condition as well. Conversely, restricting old spending could impair legitimate holders' access. BIP 361 considers mechanisms to rescue holders through knowledge a quantum attacker cannot obtain merely by solving for the private key, such as information used in wallet key generation, but says how far existing funds can be covered is undetermined.

IonQ's paper has not fixed a deadline for this migration problem. Even so, the more detailed the conditions for building the machine become, the easier it is for Bitcoin to compare them with the time its own migration will take. On the quantum computing side, what is needed is a demonstration of sustaining large-scale logical operations while maintaining the assumed error rates and replenishment. On the Bitcoin side, the decision inputs are whether waiting for that demonstration before starting the debate would be too late, and what executable migration procedure exists, including rescue of existing funds.