The Quantum Threat to Bitcoin Is Being Measured With the Wrong Instrument
Resource estimates are collapsing faster than hardware is growing, and both curves are drawn by people with something at stake
This is analysis. It interprets events and their context, and it is not financial advice.
The standard way to track the quantum threat to Bitcoin is to watch qubit counts. Every chip announcement gets read as a step toward a finish line, and the implied question is always the same: how much further.
That instrument is measuring the wrong thing. Over the past nine years the number that has moved furthest is not the size of any machine. It is the estimate of how large a machine would have to be, and it has fallen by more than three orders of magnitude. Three papers published between March and July 2026 moved it again, and one of them was co-authored by people who are not selling quantum hardware at all.
If the finish line is walking toward the runner, counting the runner's steps tells you very little.
Three papers in six months
Take the state of published knowledge in early 2026 and compare it to the state in August.
On 30 March 2026, a group led by Ryan Babbush at Google Quantum AI, including Craig Gidney and with Dan Boneh and Justin Drake among the co-authors, published resource estimates specifically for Bitcoin's curve. Their figures: 1,200 logical qubits and no more than 90 million Toffoli gates in the qubit-frugal variant, or 1,450 logical qubits and no more than 70 million gates in the gate-frugal one. Physically, fewer than half a million superconducting qubits at a physical error rate of 10^-3.
On the same day, a separate group including John Preskill, Manuel Endres and Dolev Bluvstein published an estimate for a different hardware family. On reconfigurable neutral atoms, they argue, Shor's algorithm becomes possible with as few as 10,000 physical qubits, and a P-256 discrete logarithm could run in a few days on 26,000.
On 15 July 2026, Han Luo and co-authors published a circuit that computes the same discrete logarithm using 835 logical qubits, by trading width against depth.
Now the comparison. In 2017, Martin Roetteler, Michael Naehrig, Krysta Svore and Kristin Lauter published what remained the reference estimate for most of a decade: 2,330 logical qubits and 1.26 x 10^11 Toffoli gates for a 256-bit curve.
| Published | Logical qubits | Toffoli gates |
|---|---|---|
| June 2017, Roetteler et al. | 2,330 | 1.26 x 10^11 |
| March 2026, Babbush et al., low-gate | 1,450 | 7 x 10^7 |
| March 2026, Babbush et al., low-qubit | 1,200 | 9 x 10^7 |
| July 2026, Luo et al. | 835 | roughly 1.66 x 10^9 |
The qubit requirement roughly halved. The gate count fell by a factor of about 1,400.
The algorithms got cheaper, the physics did not
This is the part that gets lost when the numbers are reported one at a time as breakthroughs.
Nothing in the underlying physics changed between 2017 and 2026. No new particle, no new coherence regime, no discovery that qubits are easier to hold than we thought. What changed is that people got better at writing the circuit. Gidney's own progression makes this unusually legible, because he revised his own work rather than someone else's. In 2019 he and Martin Ekerå estimated that factoring a 2048-bit RSA number would take 20 million noisy qubits and eight hours. In May 2025 he put the same task at fewer than one million qubits and under a week, a twenty-fold reduction, and he named the sources: approximate residue arithmetic, yoked surface codes for idle storage, and magic state cultivation. All three are engineering of the computation, not of the machine.
The Luo result is the same phenomenon pushed to its edge, and it comes with a caution that the headline number hides. Their circuit uses roughly twenty times more Toffoli gates than the space-optimised competition, and the paper provides no circuit depth and no physical compilation. A narrower circuit that has to run far longer is not obviously an easier machine to build. Reporting 835 against 1,200 as though they were the same kind of number is a category error, and it is the same one we found running through Bitcoin's most widely quoted price model, where the corridor everybody cites turned out to have been fitted separately from the model it gets attributed to. A number that travels well is not the same as a number that means what its travellers think.
Reading all of this together, the honest summary is that the attack has become cheaper to describe. Whether it has become closer to possible is a separate question, and it depends on a curve that has moved far less.
Two curves, and only one of them is a machine
Set the estimate against what anyone has actually built.
Error-corrected logical qubits are the right unit, because raw qubit counts say nothing about whether a long calculation survives. Measured that way, the public record is short. Quantinuum demonstrated 4 logical qubits in April 2024, 12 in September 2024, and 48 on its Helios system in November 2025, at a two-to-one encoding rate on 98 physical qubits. IBM's roadmap targets Starling for 2029, a machine specified at 200 logical qubits running circuits of 100 million gates. Quantinuum's roadmap promises "hundreds of logical qubits" by 2030.
Now hold that against the requirement. Even the friendliest published estimate wants 835 logical qubits. The most detailed one wants 1,200, held stable through 90 million Toffoli gates.
Two things follow, and they cut in opposite directions.
The first is that IBM's 2029 target has the gate depth and roughly a sixth of the width. A machine that can run 100 million gates on 200 logical qubits is not a machine that can run 90 million gates on 1,200. But it is close enough that the remaining problem looks like scaling rather than invention, which is exactly what its builders claim.
The second is that the demonstrated numbers are still small enough that the entire debate rests on roadmaps. Forty-eight is a real, measured, published figure. One thousand two hundred is a target that has never been approached by anyone, and error correction has historically become harder rather than easier as systems grow.
Our reading, and it is an interpretation rather than a finding: the timeline question as usually posed is not answerable, and not because the data is missing. It is not answerable because one of its two terms is a research output rather than a physical quantity. Hardware progress can be extrapolated badly. An estimate that depends on the next clever circuit cannot be extrapolated at all.
Nine minutes is a different threat than nine hours
One number in the Google paper matters more for Bitcoin than any of the qubit counts, and it has been widely under-reported.
Their estimate for wall-clock runtime is 18 to 23 minutes for the full attack. From a primed state, where the front of the computation has been precomputed, it drops to roughly 9 to 12 minutes.
That crosses a threshold specific to Bitcoin. As long as an attack takes hours or days, only permanently exposed public keys are reachable, which Glassnode measured at 1.92 million bitcoin of structural exposure in May 2026, out of 6.04 million exposed at rest in total. Those are old coins, dormant coins, coins in reused addresses. Painful, concentrated, and largely nobody's active balance.
Below the block interval, the exposure becomes universal. Every ordinary spend publishes its public key into the mempool and waits. An attacker who can derive a key inside that window can race a competing transaction, and the target is not a category of coin but any coin in motion. The mechanics of that difference are worth understanding before the numbers mean anything.
The authors put the implication plainly enough that it deserves quoting: "it is conceivable that the existence of early CRQCs may first be detected on the blockchain rather than announced." A capable machine has an obvious first use that is also its own disclosure.
What Palmer's ceiling does and does not say
Against all of that stands the most interesting counter-argument of 2026, and it deserves to be represented accurately rather than in either of its two popular distortions.
On 16 March 2026 the physicist Tim Palmer, of the Department of Physics at the University of Oxford, published a theory in PNAS called Rational Quantum Mechanics. It proposes that the state space of quantum mechanics is finely discrete rather than continuous, with standard quantum mechanics recovered as the singular limit of infinite fineness. From that discreteness follows a finite quantity Palmer calls Qubit Information Capacity: the information contained in N qubits grows linearly with N, while the dimensions of the state space grow exponentially, so above some threshold there is not enough information in the system to specify even one bit per dimension.
Palmer estimates that threshold at roughly 200 for quantum dot qubits, 300 for photonic qubits and 400 for ion traps, with an absolute ceiling of around 1,000 derived from a photon at the lowest frequency the age of the universe permits. His companion paper states the consequence directly: "the exponential advantage of quantum algorithms that utilise the quantum fourier transform, will cease in quantum computers which utilise more than 1,000 perfect (i.e. logical) qubits."
He also closes an obvious escape route. Shielding does not help, because a quantum computer "will always be gravitationally coupled to the rest of the universe" by the principle of equivalence, which means a machine on the far side of the moon is subject to the same bound.
Three things need saying, and the popular coverage tends to say only one of them.
The paper is peer reviewed and published in PNAS. That is a stronger footing than almost any other contrarian argument in this field, and dismissing it as fringe is not accurate.
It is also a proposed departure from standard quantum mechanics rather than a result within it. Palmer frames it as falsifiable, on his own account within about five years, and specifically predicts that a machine approaching the threshold will show a distinctive breakdown rather than a clean stop. Betting on it means betting that quantum mechanics is wrong in a way nobody has yet detected.
And the paper does not mention Bitcoin. Not once. Its worked example is RSA-2048, where Shor's circuit needs 2,049 qubits and therefore exceeds any plausible ceiling by a wide margin. The Oxford physics department's own announcement of the paper mentions neither Bitcoin nor cryptocurrency. Extending the argument to secp256k1 is defensible, since Shor for discrete logarithms also relies on the quantum Fourier transform, but that extension belongs to readers and not to Palmer.
The extension is also uncomfortably tight. Palmer's ceiling of roughly 1,000 now sits between two current estimates for Bitcoin's curve, above Luo's 835 and below Babbush's 1,200. In 2017, with the requirement at 2,330, the ceiling argument had a comfortable margin. It no longer does.
The 400-qubit argument that undercuts itself
The Palmer result is often paired with an older one for independent support, and this is where the popular account goes wrong in a way that is checkable.
In 2007 the physicist Paul Davies published a paper deriving a limit from the total information content of the observable universe. Using Seth Lloyd's bound of 10^122 bits, he noted that a generic entangled state of more than about 400 particles would have more components than the universe has bits, and wrote that this "signals a fundamental physical limit. It seems to me that it must."
The number is real and the reasoning is elegant. The problem is what comes next in the same paper.
Davies immediately qualifies it: "On the face of it, the limit of 400 particles is stringent enough to challenge the quantum computation industry. The foregoing analysis, however, is overly simplistic." He gives two reasons. The dimensionality of a Hilbert space is not an invariant, so a change of basis can reduce it. And the more relevant measure is the number of independent parameters, not the raw dimension count.
Then he names the exception, and the exception is the entire subject of this article. Quantum computing, he writes, does not aim to control arbitrary entangled states but a measure-zero subset associated with specific problems, and those may be specifiable by a short algorithm even when their amplitude count is astronomical. His example is explicit: "Shor's algorithm for factorization, which is algorithmically simple by definition, since its input state can be specified and there is a simple association between the input data and the initial quantum state."
Davies raised the 400-qubit bound and, in the same paper, identified Shor's algorithm as the most likely thing to slip past it. Citing him as independent confirmation that Shor's algorithm will fail above 400 qubits inverts what he wrote.
Palmer himself handles this correctly. He notes the numerical similarity between his roughly 400 and Davies's roughly 400 and asks whether it is a coincidence, answering that he thinks not. He claims agreement in magnitude, not endorsement. The distortion enters downstream.
Everyone measuring this has something to sell
This is uncomfortable to write and it applies in both directions, which is why it is worth writing.
Quantum hardware companies benefit from the threat being credible and near. Google Quantum AI publishes the estimates that make the attack look cheapest, and Google builds the machines. Project Eleven paid one bitcoin in April 2026 for the largest quantum attack on elliptic curve cryptography to date, which was a 15-bit key, and Project Eleven also builds quantum-safe Bitcoin infrastructure. Blockstream employs the authors of the leading post-quantum signature proposal for Bitcoin and sells Bitcoin infrastructure.
Bitcoin media and Bitcoin companies benefit from the reassuring reading, and the incentive there is at least as strong. A headline saying quantum computers will never break Bitcoin travels further in this industry than one saying the required machine got smaller again.
None of this makes anyone dishonest. Google's paper is careful, checkable, and its methods are published. Project Eleven's prize produced a real result and reported the key length honestly. The point is narrower: the two curves in this article are drawn almost entirely by parties who benefit from where they are drawn, and there is no disinterested referee producing either number.
The one exception is worth naming. Palmer is a climate physicist at Oxford with no evident commercial interest in Bitcoin, quantum hardware, or cryptography. That is a reason to read him carefully. It is not a reason to believe the physics, which stands or falls on its own.
The fight is not about cryptography
The technical answers largely exist. What does not exist is agreement about who they apply to.
The replacement signature is designed. NIST standardised a stateless hash-based scheme in August 2024, and Blockstream's SHRINCS proposal, published as a draft BIP on 27 August 2026, gets a stateful path down to roughly 580 bytes with a stateless fallback at roughly 4,300 to 4,500. That is workable. The proposal also says, in its own text, that a security proof is still outstanding.
The disagreement is about the coins nobody will migrate. BIP-361, drafted by Jameson Lopp and five co-authors in February 2026, proposes a phased sunset: no sends to vulnerable addresses about three years after activation, and legacy signatures stop validating about two years after that. Its own motivation states that "over 34% of all bitcoin have revealed a public key on-chain". Under that proposal, whatever has not moved by the deadline is frozen permanently.
Adam Back has argued the opposite, that optional upgrades plus roughly a decade of voluntary migration is safer than a scheduled deadline, on the grounds that Bitcoin's developers have repeatedly coordinated fast when something became urgent. BIP-360, the more conservative proposal, sidesteps the question entirely by removing the vulnerable spending path without specifying any post-quantum scheme or any deadline.
Both positions are coherent, and neither is a cryptographic claim. One says that leaving millions of bitcoin as a standing bounty is a systemic risk to everyone. The other says a protocol that can decide to stop honouring valid signatures has given up something more important than the coins. This is the same argument Bitcoin has had before about who is allowed to change the rules, with much higher stakes and a clock attached.
There is a useful precedent in the other direction. When AI-assisted tooling exposed a wave of flaws in Bitcoin's software periphery, the base layer was not implicated, because proof of work rests on physics rather than on a mathematical assumption. Quantum computing is the mirror image. It threatens the mathematical assumption and leaves the physics alone.
One more precedent is worth holding in view, because it is the closest thing Bitcoin has to a rehearsal. A key that has been derived is not a bug that a release can fix. Bitcoin met a small version of that problem when a firmware flaw produced seeds that no later update could retroactively strengthen. The scale was tiny and the mechanism was different. The shape was identical: once the secret is reachable, patching the software that generated it does nothing for the coins already sitting behind it. Whatever migration path Bitcoin picks has to be finished before the capability exists, not after, and that is a scheduling constraint rather than a cryptographic one.
What would show this reading is wrong
The thesis of this piece is that the quantum timeline is unknowable in principle rather than merely unknown, because one of its two terms is a research output. Four things would undermine it, and they are worth stating in advance.
If logical qubit counts keep climbing on schedule. If demonstrated error-corrected qubits move from 48 into the hundreds by 2029 as IBM and Quantinuum promise, then hardware is the binding curve after all and it is extrapolable. The estimate story would be a distraction.
If the estimates stop falling. Three revisions in a decade is a pattern, not a law. If the resource requirement settles for several years, the target has stopped moving and the remaining distance becomes a real distance.
If a sub-500-qubit estimate survives full scrutiny. Luo's 835 has no depth analysis. If someone publishes a comparably narrow circuit with a complete physical compilation and it holds up, the gap argued here is smaller than described.
If Palmer's prediction is tested and fails. He says a breakdown should appear as machines approach one thousand entangled logical qubits, within about five years. If quantum mechanics holds cleanly through that point, the ceiling argument is finished and this reading loses one of its legs.
And one event would make all of it obsolete at once. If a well-funded, quantum-vulnerable output moves without its owner, the argument stops being about estimates. Until then, the most defensible position is the one almost nobody finds satisfying: the exposure is real and measurable, the defence is designed and undeployed, the machine does not exist, and nobody can tell you when it will, including the people building it.
That is also, in a different sense, the least interesting question about the whole affair.
Frequently Asked Questions
Because it treats the finish line as fixed. Between 2017 and 2026 the published estimate of what it would take to break Bitcoin's curve fell from 2,330 logical qubits and 1.26 x 10^11 Toffoli gates to 1,200 logical qubits and 9 x 10^7 gates. The gate count alone fell by a factor of roughly 1,400. A gap that shrinks from both ends cannot be projected forward from hardware progress alone.
It does not mention Bitcoin. The paper argues that entangled qubit counts are capped at roughly one thousand and that RSA-2048 will therefore never be factored. Applying that to Bitcoin's elliptic curve is a reasonable inference, because Shor's algorithm for discrete logarithms also relies on the quantum Fourier transform, but it is an inference by readers rather than a claim by the author.
Less than it is usually made to look. Davies derived roughly 400 from the information content of the observable universe in 2007, then called his own analysis overly simplistic in the next paragraph and named Shor's algorithm as the likely exception, on the grounds that its input state is algorithmically simple by definition. The number is real. The support it offers is weaker than the summary version.
A machine holding around one thousand error-corrected logical qubits entangled through a deep circuit. That is the point where Palmer says the exponential advantage disappears and where several current resource estimates say an attack becomes feasible. Both predictions live in the same window, which is new. Before 2026 the required resources sat far above any proposed ceiling.
Sources
- 1.Babbush, Zalcman, Gidney et al. — Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities: Resource Estimates and Mitigations
- 2.Roetteler, Naehrig, Svore, Lauter — Quantum Resource Estimates for Computing Elliptic Curve Discrete Logarithms
- 3.Luo et al. — Space-Efficient Quantum Algorithm for Elliptic Curve Discrete Logarithms with Resource Estimation
- 4.Cain, Xu, King, Picard, Levine, Endres, Preskill, Huang, Bluvstein — Shor's Algorithm Is Possible with as Few as 10,000 Reconfigurable Atomic Qubits
- 5.Gidney, Ekerå — How to Factor 2048 Bit RSA Integers in 8 Hours Using 20 Million Noisy Qubits
- 6.Gidney — How to Factor 2048 Bit RSA Integers with Less than a Million Noisy Qubits
- 7.Palmer — Rational Quantum Mechanics: Testing Quantum Theory with Quantum Computers, PNAS
- 8.Palmer — Solving the Mysteries of Quantum Mechanics: Why Nature Abhors a Continuum
- 9.University of Oxford Department of Physics — Rational Quantum Mechanics: A New Theory of Quantum Physics
- 10.Davies — The Implications of a Cosmological Information Bound for Complexity, Quantum Information and the Nature of Physical Law
- 11.Willsch et al. — The State of Factoring on Quantum Computers
- 12.Quantinuum — Introducing Helios
- 13.Quantinuum — Accelerated Roadmap to Universal, Fully Fault-Tolerant Quantum Computing by 2030
- 14.IBM Quantum — IBM Lays Out Clear Path to Fault-Tolerant Quantum Computing
- 15.Glassnode Research — Measuring Bitcoin's Quantum-Exposed Supply
- 16.BIP-360 — Pay-to-Merkle-Root
- 17.BIP-361 — Post Quantum Migration and Legacy Signature Sunset
- 18.Nick, Blockstream Research — OP_CHECKSHRINCS, a Hash-Based Signature Opcode for Post-Quantum Bitcoin
- 19.Project Eleven — Q-Day Prize Awarded for Largest Quantum Attack on Elliptic Curve Cryptography to Date
- 20.Coinbase Quantum Advisory Council — Post-Quantum Migration and Abandoned Coins
- 21.NIST IR 8547 — Transition to Post-Quantum Cryptography Standards
- 22.Aggarwal, Brennen, Lee, Santha, Tomamichel — Quantum Attacks on Bitcoin, and How to Protect Against Them