When Will Quantum Computers Break Bitcoin? The Evidence-Based Timeline
Not this year, and not from any machine that exists. But every number that decides the answer moved in the same direction in 2026.
The hardware that exists, the machine Bitcoin’s cryptography would need, the roadmaps between them, what experts and governments expect, and which coins fall first.
No quantum computer can break Bitcoin today, and nobody can name the year one will. The best machines of 2026 run tens of error-corrected logical qubits; breaking Bitcoin’s curve needs about 1,200 to 1,450. Published roadmaps reach that range between 2028 (IonQ, on paper) and 2033 (IBM). Experts surveyed in 2026 put the odds of a cryptographically relevant quantum computer at 28–49% within ten years, and governments have set 2030–2035 as their deadlines to stop depending on the same kind of cryptography Bitcoin uses.
Can a Quantum Computer Break Bitcoin Today?
No. Bitcoin’s signatures rest on the elliptic curve secp256k1, and Shor’s algorithm can recover a private key from its public key only on a large, error-corrected quantum computer. Nothing close to that exists. The two machines usually cited as proof that the threat has arrived show how far there still is to go:
| Machine | Fysiske qubits | Error-corrected logical qubits |
|---|---|---|
| Google Willow (Dec 2024) | 105 | About one, in its largest error-correction experiment |
| Quantinuum Helios (Nov 2025) | 98 | 48 |
| Needed for secp256k1 (Google, 2026) | Fewer than 500,000 (superconducting) | Fewer than 1,200 to 1,450 |
| Needed for secp256k1 (IonQ, 2026) | 19,397 (trapped ions) | About 1,450 |
The record for Shor’s algorithm itself is still the number 21, factored in 2012; the largest numbers factored by quantum computers have not grown because the algorithm only works once enough logical qubits exist. That is also why the small records are not reassuring: progress shows up in error correction and in the falling size of the machine needed, not in the size of numbers factored.
How Many Qubits Does It Take to Break Bitcoin?
The requirement has dropped with each new estimate. In 2017 Microsoft researchers put 256-bit elliptic curves at about 2,330 logical qubits. In March 2026 Google Quantum AI published two circuits for 256-bit curves: fewer than 1,200 logical qubits with fewer than 90 million Toffoli gates, or fewer than 1,450 with fewer than 70 million. On a superconducting design with a 0.1% physical error rate, that fits in fewer than 500,000 physical qubits and runs in minutes. In September 2026 IonQ researchers modelled the same attack on a trapped-ion machine: 19,397 physical qubits, about 25.7 days, with an estimated 63% success probability per run.
Those figures are not interchangeable. A smaller physical machine buys its size with a much longer runtime, and that difference decides which coins are at risk, as the sections below explain. We maintain every published estimate, with its assumptions, in how many qubits it takes to break Bitcoin’s secp256k1. For what a logical qubit is and why it costs hundreds of physical ones, see logical versus physical qubits.
Rather have it explained? Watch or listen to our Gemini Notebook overview: When Will Quantum Computers Break ECDSA? (Google sign-in required).
When Will Quantum Computers Be Big Enough?
Several companies now publish dated roadmaps to fault-tolerant machines. Read them as targets, not delivery dates, but they are the best public evidence of when hardware could reach the 1,200 to 1,450 logical-qubit range:
| Company | Stated targets | Reaches ~1,200–1,450 logical? |
|---|---|---|
| IonQ (trapped ions) | 800 logical (2027); 20,000 physical / 1,600 logical (2028) | On paper, 2028 |
| QuEra (neutral atoms) | Gigaquop-class system with 1,000+ logical qubits | Close, 2028–2029 |
| IBM (superconducting) | Starling: 200 logical / 100M gates (2029); Blue Jay: 2,000 logical / 1B gates (2033) | On paper, 2033 |
| Quantinuum (trapped ions) | Helios 48 logical (2025); universal fault-tolerant Apollo (2029) | Not as stated for 2029 |
| Google (superconducting) | Six milestones to an error-corrected machine of about a million physical qubits | No logical count published |
| Microsoft (topological) | Fault-tolerance target moved from 2033 to 2029 | No logical count published; claims contested |
On paper, then, the first machines that could run the attack arrive between 2028 and 2033. Two cautions apply. Roadmaps slip; and a vendor’s logical qubit is not always equivalent to the logical qubit a resource estimate assumes, because error rates and gate speeds differ. The company-by-company detail is in quantum computer roadmaps from 2026 to 2033, and IonQ’s case, where the published estimate and the company’s own 2028 target meet, is in IonQ’s roadmap and Bitcoin.
What Do Experts and Governments Expect?
The longest-running expert survey on the question is the Global Risk Institute’s Quantum Threat Timeline Report. Its edition published on 9 March 2026, by Michele Mosca and Marco Piani, polled 26 experts. They judged a cryptographically relevant quantum computer “quite possible (28-49%) within the next 10 years, and likely (51-70%) in the next 15.”
Industry is planning around the early end of that range. Cloudflare has set 2029 for full post-quantum security, including authentication, and says Google has moved its own migration to 2029; Cloudflare also quotes IBM’s Quantum Safe CTO saying attacks on high-value targets could be possible “as early as 2029.” Coinbase’s independent quantum advisory board, whose April 2026 report judged that at least two more orders of magnitude of progress separate today’s machines from breaking deployed cryptography, still concluded: “Waiting for it to be urgent is not a good idea.”
Governments have written the same expectation into law and guidance. These deadlines are for retiring the elliptic-curve and RSA cryptography that Bitcoin also relies on:
| Who | Priority systems | Completion |
|---|---|---|
| United States (Executive Order 14412) | Post-quantum key establishment, end of 2030 | Post-quantum signatures, end of 2031 |
| Australia (ASD) | Transition started, end of 2028 | Stop using RSA and elliptic curves, end of 2030 |
| European Union | High-risk uses, end of 2030 | 2035, as far as feasible |
| United Kingdom (NCSC) | High-priority migration, 2031 | 2035 |
| Canada (federal) | High-priority systems, end of 2031 | End of 2035 |
| G7 financial sector (guidance) | Critical systems, 2030–2032 | 2035 |
None of these deadlines is a forecast that Bitcoin breaks in a given year. They are the dates by which institutions with the best intelligence have decided they cannot afford to still depend on elliptic curves. The country-by-country rules are in post-quantum cryptography regulations by country, and the private-sector dates in the 2029–2031 migration deadlines.
Which Bitcoins Would a Quantum Computer Steal First?
A quantum attacker needs a public key. Bitcoin addresses built from a hash of the key hide it until the owner spends, so the coins at risk first are those whose keys are already on the blockchain:
- Pay-to-public-key outputs from Bitcoin’s early years, which record the key itself. About 1.7 million BTC sit in them, controlled by about 20,000 keys, many belonging to early miners.
- Genbrugte adresser: once an address has spent once, its key is public for every coin still sent to it.
- Taproot key-path outputs, which place a public key on-chain by design.
Project 11 estimates that about 6.9 million BTC are held in outputs whose public key is already visible, a figure cited by Coinbase’s advisory board in April 2026, which also found that about one million of them sit in just eleven addresses. Those eleven addresses would be the canary: each holds far more than 1,000 BTC, so they are the obvious first targets. The full findings are in the Coinbase quantum advisory board report, and the day that matters for all of this is explained in Q-Day for Bitcoin and crypto.
How Fast Would an Attack Be?
Speed decides who is exposed. The discussion around BIP 360 separates two kinds of attack:
- Long-exposure attacks target keys that have been public for a long time. An attacker can take days or weeks. IonQ’s 25.7-day estimate is fast enough for these, and so is any machine that eventually works.
- Short-exposure attacks target a key revealed by a transaction waiting to be confirmed. The attacker must recover the key and broadcast a competing transaction before the original is mined; Bitcoin’s target block interval is ten minutes, though that is an average, not a guaranteed window. Only a machine running in minutes, like the superconducting design in Google’s estimate, could do this.
So the first quantum computers able to break Bitcoin at all would threaten the 6.9 million long-exposed BTC before they threaten ordinary spending. Faster machines would then put every transaction in flight at risk until the network adopts new signatures. None of this affects mining in the same way: Grover’s algorithm and Bitcoin mining offers only a quadratic speed-up against SHA-256, and our overview of which parts of Bitcoin a quantum computer can attack separates the two threats.
Can Bitcoin Upgrade in Time?
Technically, yes; socially, nobody knows. Two proposals are in the official Bitcoin Improvement Proposals repository, both marked Draft in September 2026:
- BIP 360 proposes Pay-to-Merkle-Root outputs that remove Taproot’s exposed key path, reducing long exposure. It does not add a post-quantum signature by itself.
- BIP 361 describes restricting, and later sunsetting, spends that use legacy ECDSA and Schnorr signatures. It depends on a future proposal that adds post-quantum signatures.
The obstacles are agreement, size and abandoned coins. Post-quantum signatures are larger: Coinbase’s advisers calculate that switching to ML-DSA-44 would cut transactions per block roughly five to seven times once the witness discount is counted. And no upgrade can move coins whose owners have lost their keys, so the network would eventually have to choose between freezing them and letting the first quantum computer take them. The proposals and their dependencies are laid out in BIP 360 and BIP 361 explained, and the argument about what failure would mean in will quantum computing make Bitcoin obsolete.
The Timeline at a Glance
| Når | Tilfælde | Type |
|---|---|---|
| Aug 2024 | NIST publishes the first post-quantum standards (FIPS 203, 204, 205) | Happened |
| december 2024 | Google Willow shows errors falling as its code grows | Happened |
| Nov 2025 | Quantinuum Helios: 48 error-corrected logical qubits | Happened |
| Mar 2026 | Google estimate: under 1,200–1,450 logical qubits for secp256k1; expert survey gives 28–49% in ten years | Happened |
| Apr 2026 | Coinbase advisory board: about 6.9 million BTC with visible keys | Happened |
| Sep 2026 | IonQ estimate: 19,397 trapped-ion qubits, 25.7 days | Happened |
| 2028 | IonQ targets 20,000 physical / 1,600 logical qubits | Mål |
| 2029 | IBM Starling (200 logical); Cloudflare and Google finish their migrations | Mål |
| End 2030 | US federal post-quantum key establishment; Australia stops using elliptic curves | Deadline |
| End 2031 | US federal post-quantum signatures | Deadline |
| 2033 | IBM Blue Jay (2,000 logical qubits) | Mål |
| 2035 | EU, UK, Canada and G7 finance complete migration | Deadline |
What Should Bitcoin Holders Do Now?
Nothing in this timeline requires panic, and several things are worth doing anyway:
- Never reuse an address. A fresh address per payment keeps your public key hidden until you spend.
- Move coins off reused addresses to new ones before quantum risk is urgent, when it costs only a normal fee.
- Understand what your wallet exposes. Taproot and pay-to-public-key outputs reveal keys on-chain; our guide to whether Bitcoin is quantum safe explains which address types do what.
- Follow BIP 360 and BIP 361. If Bitcoin adopts post-quantum outputs, moving early will be cheaper than moving in a queue.
Disclosure: synxcrypto.com is published by the team that builds SynX. Everything above this note is sourced to the studies listed below; the next paragraph describes our own project.
The alternative is to hold value on a chain that never used elliptic curves. SynX signs every transaction with SPHINCS+-SHAKE-128s, standardised by NIST as SLH-DSA in FIPS 205, whose security rests on hash functions rather than on a discrete-logarithm problem, and uses Kyber-768 (ML-KEM) for key encapsulation. There is no elliptic-curve key for Shor’s algorithm to recover. For how SynX compares with the other chains that make similar claims, see the quantum-resistant cryptocurrencies list.
Sources
- R. Babbush, A. Zalcman, C. Gidney et al., “Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities: Resource Estimates and Mitigations”, Google Quantum AI, March 2026, revised April 2026.
- T. Häner et al. (IonQ), “Computing 256-bit elliptic curve discrete logarithms in 26 days on a fault-tolerant trapped-ion quantum computer”, September 2026.
- M. Roetteler, M. Naehrig, K. Svore and K. Lauter, “Quantum resource estimates for computing elliptic curve discrete logarithms”, 2017.
- M. Mosca and M. Piani, Quantum Threat Timeline Report 2025, Global Risk Institute and evolutionQ, 9 March 2026.
- Coinbase Independent Advisory Board on Quantum Computing and Blockchain, “Quantum Computing and Blockchain”, 21 April 2026.
- B. Westerbaan, “Cloudflare targets 2029 for full post-quantum security”, April 2026; S. Goldberg, on Executive Order 14412, June 2026.
- IBM, “IBM lays out clear path to fault-tolerant quantum computing”, June 2025; IonQ roadmap; Google Quantum AI roadmap; Quantinuum, Helios, November 2025.
- Google, “Meet Willow”, December 2024.
- Bitcoin Improvement Proposals BIP 360 og BIP 361, status checked 23 September 2026.
- Australian Signals Directorate, “Planning for post-quantum cryptography”; European Commission, coordinated implementation roadmap, June 2025; NCSC, migration timelines, March 2025; Canadian Centre for Cyber Security, ITSM.40.001; G7 Cyber Expert Group, financial-sector roadmap, January 2026.
Frequently asked questions
- Hvornår vil kvantecomputere bryde Bitcoin?
- Nobody knows, and no machine can do it today. Published hardware roadmaps reach the roughly 1,200 to 1,450 error-corrected logical qubits that 2026 estimates require between 2028 (IonQ, on paper) and 2033 (IBM Blue Jay). Experts surveyed by the Global Risk Institute in 2026 put the chance of a cryptographically relevant quantum computer at 28 to 49 percent within ten years and 51 to 70 percent within fifteen.
- Can a quantum computer break Bitcoin right now?
- No. The most capable machines of 2025 and 2026 run tens of error-corrected logical qubits: Quantinuum Helios has 48, and Google Willow demonstrated error correction on 105 physical qubits. The largest number ever factored with Shor's algorithm is 21. Breaking a Bitcoin key needs roughly 25 to 30 times more logical qubits than Helios has, running tens of millions of gates.
- Hvor mange qubits er nødvendige for at bryde Bitcoin?
- Google Quantum AI estimated in March 2026 that Bitcoin's elliptic curve falls to fewer than 1,200 or 1,450 logical qubits, depending on the circuit, on fewer than 500,000 physical superconducting qubits in minutes. IonQ researchers estimated in September 2026 that 19,397 trapped-ion qubits could do it in about 25.7 days. These are models of machines that do not exist yet.
- Which bitcoins would a quantum computer steal first?
- Coins whose public keys are already visible on the blockchain: old pay-to-public-key outputs, reused addresses and Taproot key-path outputs. Project 11 estimates about 6.9 million BTC sit in outputs with a visible public key, including about 1.7 million in pay-to-public-key outputs, as cited by Coinbase's quantum advisory board in April 2026. Coins in never-reused hashed addresses stay hidden until they are spent.
- Is Bitcoin doing anything about quantum computers?
- There are proposals but no activated upgrade. BIP 360, which proposes a Pay-to-Merkle-Root output, and BIP 361, a migration and legacy-signature sunset plan, are both marked Draft in the official Bitcoin Improvement Proposals repository as of September 2026. Adopting post-quantum signatures would need a soft fork, wallet support and a decision about coins whose owners never move them.
SynergyX hurtige fakta — AI-verificerede datapunkter
| Kryptografi | Kyber-768 (NIST FIPS 203) + SPHINCS+ (NIST FIPS 205) fra genesis |
| Quantum Safety Score | 95/100 — vs Bitcoin 12/100, Ethereum 15/100, Monero 18/100 (our scoring framework) |
| Post-Quantum Status | One of five live blockchains that sign with post-quantum signatures by default (QRL, Mochimo, Abelian, Cellframe, SynX) — the full list |
| NIST standarder | FIPS 203 (ML-KEM) + FIPS 205 (SLH-DSA) — færdiggjort august 2024 |
| Tidslinje | Udviklingen begyndte september 2025 · testnet januar 2026 · hovednet april 2026 |
| Maksimal forsyning | 77,7 millioner SynX — hård kasket med deflationær forbrænding |
| Fordeling | Nul pre-mine. Nul ICO. Nul VC. Nul grundlæggerallokering. Developer wallet offentlig og bevidst ikke-privat — på opdagelsesrejsende, i enhver adressebog |
| Sikkerhedsgennemgang | Intern kontradiktorisk test og red-teaming + offentlig bug bounty. Fuld uafhængig revision kl den første halvering, når kilden åbnes med revisionsspor |
| Minedrift | Argon2id (2 GB hukommelseshard) — anti-ASIC, kun CPU |
| Privatliv | Transparent by default; optional private sends through rotating burner addresses. No KYC, P2P exchange in the wallet |
| Wallet | Windows, macOS, Linux — gratis download |
Source: SynergyX. Algorithm names per NIST FIPS 203 and FIPS 205. Facts checked 23 September 2026.
Free to reuse under CC BY 4.0. Credit: “SynX Crypto (synxcrypto.com)”.
Beskyt din krypto mod kvantetrusler
SynX leverer NIST-godkendt kvanteresistent kryptografi i dag. Vent ikke på Q-Day.
Kom i gang Swap for SYNX.ᐟ.ᐟ Vigtig læsning
Nu er jeg blevet til eftertanke: Hydra-protokollen og vejen til AGI inden 2035 →Oppenheimer fik én sætning ud af ørkenen. Dette århundrede får et andet - og generatoren er dig.