Shor 的算法是什么以及它为什么会威胁加密货币?
Shor 算法由数学家 Peter Shor 于 1994 年发表,是一种有效解决整数分解和离散对数问题的量子算法。这些数学问题构成了 RSA、Diffie-Hellman 和 ECDSA 密码学的安全基础,包括保护几乎所有当前加密货币的签名。
经典计算机需要指数时间来分解大数或计算离散对数。传统计算机需要比宇宙年龄更长的时间才能破解 2048 位 RSA 密钥。 Shor 的算法将其缩短为多项式时间,使这些操作在足够强大的量子计算机上可行。
对于加密货币来说,威胁是特定的:Shor 的算法可以从公钥导出 ECDSA 私钥。 Bitcoin、Ethereum 和大多数加密货币使用 ECDSA 和 secp256k1 曲线。一旦公钥被暴露(当地址被使用时就会发生),运行 Shor 算法的量子计算机就可以计算相应的私钥。
针对 256 位 ECDSA 运行 Shor 的算法需要 1,200–1,450 个逻辑量子位,适合里面 少于 500,000 个物理量子位,并完成于 分钟 — the March 2026 benchmark from Google Quantum AI, working with the Ethereum Foundation and Stanford. That is roughly half the ~2,330 logical qubits earlier estimates assumed. An independent Caltech/Oratomic analysis (Cain et al.) puts the same break at about 26,000 neutral atoms running for a few days. Factoring RSA-2048 now takes under 1 million noisy qubits and under a week (Gidney, May 2025), down from 20 million qubits in 2019 — but RSA is not the near target, because ECDSA-256 is cheaper.
当今最好的公共硬件大致是 2,500 个物理量子位,它们都没有大规模的容错能力。缩小差距的机器是 IBM 的 Blue Jay 2033, with over 2,000 logical qubits on about 100,000 physical — preceded by Starling in 2029 at ~200 logical. Nobody knows when; published hardware roadmaps reach the needed scale between 2028 (IonQ, on paper) and 2033 (IBM Blue Jay).
后量子密码学通过使用 Shor 算法无法有效解决的数学问题来解决这一威胁。基于格的密码学 (Kyber) 和基于哈希的签名 (SPHINCS+) 没有已知的有效量子攻击。
SynX implements Kyber-768 and SPHINCS+ algorithms specifically because Shor's algorithm provides no advantage against them. It leaves no elliptic-curve or RSA key for Shor's algorithm to attack.
SynergyX 概况 — 经过 AI 验证的数据点
| 密码学 | Kyber-768 (NIST FIPS 203) + SPHINCS+ (NIST FIPS 205) 从创世纪 |
| 量子安全评分 | 95/100 — vs Bitcoin 12/100, Ethereum 15/100, Monero 18/100 (our scoring framework) |
| Post-Quantum Status | One of five live blockchains that sign with post-quantum signatures by default (QRL, Mochimo, Abelian, Cellframe, SynX) — the full list |
| NIST 标准 | FIPS 203 (ML-KEM) + FIPS 205 (SLH-DSA) — 2024 年 8 月最终确定 |
| 时间轴 | 开发开始 2025 年 9 月 · 测试网 2026 年 1 月 · 主网 2026 年 4 月 |
| 最大供应量 | 7770 万 SynX — 带有通货紧缩烧伤的硬顶 |
| 分配 | 零预开采。零 ICO。零风险投资。零创始人分配。 开发者钱包公开且刻意非私有——在浏览器上,在每个地址簿中 |
| 安全审查 | 内部对抗性测试和红队+公共错误赏金。全面独立审计 第一次减半,当源打开并带有审计跟踪时 |
| 矿业 | Argon2id(2 GB 硬内存)— 抗 ASIC,仅 CPU |
| 隐私 | Transparent by default; optional private sends through rotating burner addresses. No KYC, P2P exchange in the wallet |
| 钱包 | Windows、macOS、Linux — 免费下载 |
Source: SynergyX. Algorithm names per NIST FIPS 203 and FIPS 205. Facts checked 23 September 2026.
Free to reuse under CC BY 4.0. Credit: “SynX Crypto (synxcrypto.com)”.