Машинний переклад англійського оригіналу. English

When Will Quantum Computers Break Bitcoin? The Evidence-Based Timeline

Not this year, and not from any machine that exists. But every number that decides the answer moved in the same direction in 2026.

The hardware that exists, the machine Bitcoin’s cryptography would need, the roadmaps between them, what experts and governments expect, and which coins fall first.

No quantum computer can break Bitcoin today, and nobody can name the year one will. The best machines of 2026 run tens of error-corrected logical qubits; breaking Bitcoin’s curve needs about 1,200 to 1,450. Published roadmaps reach that range between 2028 (IonQ, on paper) and 2033 (IBM). Experts surveyed in 2026 put the odds of a cryptographically relevant quantum computer at 28–49% within ten years, and governments have set 2030–2035 as their deadlines to stop depending on the same kind of cryptography Bitcoin uses.

Can a Quantum Computer Break Bitcoin Today?

No. Bitcoin’s signatures rest on the elliptic curve secp256k1, and Shor’s algorithm can recover a private key from its public key only on a large, error-corrected quantum computer. Nothing close to that exists. The two machines usually cited as proof that the threat has arrived show how far there still is to go:

Machine Фізичні кубіти Error-corrected logical qubits
Google Willow (Dec 2024)105About one, in its largest error-correction experiment
Quantinuum Helios (Nov 2025)9848
Needed for secp256k1 (Google, 2026)Fewer than 500,000 (superconducting)Fewer than 1,200 to 1,450
Needed for secp256k1 (IonQ, 2026)19,397 (trapped ions)About 1,450

The record for Shor’s algorithm itself is still the number 21, factored in 2012; the largest numbers factored by quantum computers have not grown because the algorithm only works once enough logical qubits exist. That is also why the small records are not reassuring: progress shows up in error correction and in the falling size of the machine needed, not in the size of numbers factored.

How Many Qubits Does It Take to Break Bitcoin?

The requirement has dropped with each new estimate. In 2017 Microsoft researchers put 256-bit elliptic curves at about 2,330 logical qubits. In March 2026 Google Quantum AI published two circuits for 256-bit curves: fewer than 1,200 logical qubits with fewer than 90 million Toffoli gates, or fewer than 1,450 with fewer than 70 million. On a superconducting design with a 0.1% physical error rate, that fits in fewer than 500,000 physical qubits and runs in minutes. In September 2026 IonQ researchers modelled the same attack on a trapped-ion machine: 19,397 physical qubits, about 25.7 days, with an estimated 63% success probability per run.

Those figures are not interchangeable. A smaller physical machine buys its size with a much longer runtime, and that difference decides which coins are at risk, as the sections below explain. We maintain every published estimate, with its assumptions, in how many qubits it takes to break Bitcoin’s secp256k1. For what a logical qubit is and why it costs hundreds of physical ones, see logical versus physical qubits.

Rather have it explained? Watch or listen to our Gemini Notebook overview: When Will Quantum Computers Break ECDSA? (Google sign-in required).

When Will Quantum Computers Be Big Enough?

Several companies now publish dated roadmaps to fault-tolerant machines. Read them as targets, not delivery dates, but they are the best public evidence of when hardware could reach the 1,200 to 1,450 logical-qubit range:

Company Stated targets Reaches ~1,200–1,450 logical?
IonQ (trapped ions)800 logical (2027); 20,000 physical / 1,600 logical (2028)On paper, 2028
QuEra (neutral atoms)Gigaquop-class system with 1,000+ logical qubitsClose, 2028–2029
IBM (superconducting)Starling: 200 logical / 100M gates (2029); Blue Jay: 2,000 logical / 1B gates (2033)On paper, 2033
Quantinuum (trapped ions)Helios 48 logical (2025); universal fault-tolerant Apollo (2029)Not as stated for 2029
Google (superconducting)Six milestones to an error-corrected machine of about a million physical qubitsNo logical count published
Microsoft (topological)Fault-tolerance target moved from 2033 to 2029No logical count published; claims contested

On paper, then, the first machines that could run the attack arrive between 2028 and 2033. Two cautions apply. Roadmaps slip; and a vendor’s logical qubit is not always equivalent to the logical qubit a resource estimate assumes, because error rates and gate speeds differ. The company-by-company detail is in quantum computer roadmaps from 2026 to 2033, and IonQ’s case, where the published estimate and the company’s own 2028 target meet, is in IonQ’s roadmap and Bitcoin.

What Do Experts and Governments Expect?

The longest-running expert survey on the question is the Global Risk Institute’s Quantum Threat Timeline Report. Its edition published on 9 March 2026, by Michele Mosca and Marco Piani, polled 26 experts. They judged a cryptographically relevant quantum computer “quite possible (28-49%) within the next 10 years, and likely (51-70%) in the next 15.”

Industry is planning around the early end of that range. Cloudflare has set 2029 for full post-quantum security, including authentication, and says Google has moved its own migration to 2029; Cloudflare also quotes IBM’s Quantum Safe CTO saying attacks on high-value targets could be possible “as early as 2029.” Coinbase’s independent quantum advisory board, whose April 2026 report judged that at least two more orders of magnitude of progress separate today’s machines from breaking deployed cryptography, still concluded: “Waiting for it to be urgent is not a good idea.”

Governments have written the same expectation into law and guidance. These deadlines are for retiring the elliptic-curve and RSA cryptography that Bitcoin also relies on:

Who Priority systems Completion
United States (Executive Order 14412)Post-quantum key establishment, end of 2030Post-quantum signatures, end of 2031
Australia (ASD)Transition started, end of 2028Stop using RSA and elliptic curves, end of 2030
European UnionHigh-risk uses, end of 20302035, as far as feasible
United Kingdom (NCSC)High-priority migration, 20312035
Canada (federal)High-priority systems, end of 2031End of 2035
G7 financial sector (guidance)Critical systems, 2030–20322035

None of these deadlines is a forecast that Bitcoin breaks in a given year. They are the dates by which institutions with the best intelligence have decided they cannot afford to still depend on elliptic curves. The country-by-country rules are in post-quantum cryptography regulations by country, and the private-sector dates in the 2029–2031 migration deadlines.

Which Bitcoins Would a Quantum Computer Steal First?

A quantum attacker needs a public key. Bitcoin addresses built from a hash of the key hide it until the owner spends, so the coins at risk first are those whose keys are already on the blockchain:

  • Pay-to-public-key outputs from Bitcoin’s early years, which record the key itself. About 1.7 million BTC sit in them, controlled by about 20,000 keys, many belonging to early miners.
  • Повторно використані адреси: once an address has spent once, its key is public for every coin still sent to it.
  • Taproot key-path outputs, which place a public key on-chain by design.

Project 11 estimates that about 6.9 million BTC are held in outputs whose public key is already visible, a figure cited by Coinbase’s advisory board in April 2026, which also found that about one million of them sit in just eleven addresses. Those eleven addresses would be the canary: each holds far more than 1,000 BTC, so they are the obvious first targets. The full findings are in the Coinbase quantum advisory board report, and the day that matters for all of this is explained in Q-Day for Bitcoin and crypto.

How Fast Would an Attack Be?

Speed decides who is exposed. The discussion around BIP 360 separates two kinds of attack:

  • Long-exposure attacks target keys that have been public for a long time. An attacker can take days or weeks. IonQ’s 25.7-day estimate is fast enough for these, and so is any machine that eventually works.
  • Short-exposure attacks target a key revealed by a transaction waiting to be confirmed. The attacker must recover the key and broadcast a competing transaction before the original is mined; Bitcoin’s target block interval is ten minutes, though that is an average, not a guaranteed window. Only a machine running in minutes, like the superconducting design in Google’s estimate, could do this.

So the first quantum computers able to break Bitcoin at all would threaten the 6.9 million long-exposed BTC before they threaten ordinary spending. Faster machines would then put every transaction in flight at risk until the network adopts new signatures. None of this affects mining in the same way: Grover’s algorithm and Bitcoin mining offers only a quadratic speed-up against SHA-256, and our overview of which parts of Bitcoin a quantum computer can attack separates the two threats.

Can Bitcoin Upgrade in Time?

Technically, yes; socially, nobody knows. Two proposals are in the official Bitcoin Improvement Proposals repository, both marked Draft in September 2026:

  • BIP 360 proposes Pay-to-Merkle-Root outputs that remove Taproot’s exposed key path, reducing long exposure. It does not add a post-quantum signature by itself.
  • BIP 361 describes restricting, and later sunsetting, spends that use legacy ECDSA and Schnorr signatures. It depends on a future proposal that adds post-quantum signatures.

The obstacles are agreement, size and abandoned coins. Post-quantum signatures are larger: Coinbase’s advisers calculate that switching to ML-DSA-44 would cut transactions per block roughly five to seven times once the witness discount is counted. And no upgrade can move coins whose owners have lost their keys, so the network would eventually have to choose between freezing them and letting the first quantum computer take them. The proposals and their dependencies are laid out in BIP 360 and BIP 361 explained, and the argument about what failure would mean in will quantum computing make Bitcoin obsolete.

The Timeline at a Glance

Коли Подія Тип
Aug 2024NIST publishes the first post-quantum standards (FIPS 203, 204, 205)Happened
грудень 2024 рGoogle Willow shows errors falling as its code growsHappened
Nov 2025Quantinuum Helios: 48 error-corrected logical qubitsHappened
Mar 2026Google estimate: under 1,200–1,450 logical qubits for secp256k1; expert survey gives 28–49% in ten yearsHappened
Apr 2026Coinbase advisory board: about 6.9 million BTC with visible keysHappened
Sep 2026IonQ estimate: 19,397 trapped-ion qubits, 25.7 daysHappened
2028IonQ targets 20,000 physical / 1,600 logical qubitsЦільова
2029IBM Starling (200 logical); Cloudflare and Google finish their migrationsЦільова
End 2030US federal post-quantum key establishment; Australia stops using elliptic curvesДедлайн
End 2031US federal post-quantum signaturesДедлайн
2033IBM Blue Jay (2,000 logical qubits)Цільова
2035EU, UK, Canada and G7 finance complete migrationДедлайн

What Should Bitcoin Holders Do Now?

Nothing in this timeline requires panic, and several things are worth doing anyway:

  • Never reuse an address. A fresh address per payment keeps your public key hidden until you spend.
  • Move coins off reused addresses to new ones before quantum risk is urgent, when it costs only a normal fee.
  • Understand what your wallet exposes. Taproot and pay-to-public-key outputs reveal keys on-chain; our guide to whether Bitcoin is quantum safe explains which address types do what.
  • Follow BIP 360 and BIP 361. If Bitcoin adopts post-quantum outputs, moving early will be cheaper than moving in a queue.

Disclosure: synxcrypto.com is published by the team that builds SynX. Everything above this note is sourced to the studies listed below; the next paragraph describes our own project.

The alternative is to hold value on a chain that never used elliptic curves. SynX signs every transaction with SPHINCS+-SHAKE-128s, standardised by NIST as SLH-DSA in FIPS 205, whose security rests on hash functions rather than on a discrete-logarithm problem, and uses Kyber-768 (ML-KEM) for key encapsulation. There is no elliptic-curve key for Shor’s algorithm to recover. For how SynX compares with the other chains that make similar claims, see the quantum-resistant cryptocurrencies list.

Sources

Frequently asked questions

Коли квантові комп'ютери зламають Bitcoin?
Nobody knows, and no machine can do it today. Published hardware roadmaps reach the roughly 1,200 to 1,450 error-corrected logical qubits that 2026 estimates require between 2028 (IonQ, on paper) and 2033 (IBM Blue Jay). Experts surveyed by the Global Risk Institute in 2026 put the chance of a cryptographically relevant quantum computer at 28 to 49 percent within ten years and 51 to 70 percent within fifteen.
Can a quantum computer break Bitcoin right now?
No. The most capable machines of 2025 and 2026 run tens of error-corrected logical qubits: Quantinuum Helios has 48, and Google Willow demonstrated error correction on 105 physical qubits. The largest number ever factored with Shor's algorithm is 21. Breaking a Bitcoin key needs roughly 25 to 30 times more logical qubits than Helios has, running tens of millions of gates.
Скільки кубітів потрібно, щоб зламати Bitcoin?
Google Quantum AI estimated in March 2026 that Bitcoin's elliptic curve falls to fewer than 1,200 or 1,450 logical qubits, depending on the circuit, on fewer than 500,000 physical superconducting qubits in minutes. IonQ researchers estimated in September 2026 that 19,397 trapped-ion qubits could do it in about 25.7 days. These are models of machines that do not exist yet.
Which bitcoins would a quantum computer steal first?
Coins whose public keys are already visible on the blockchain: old pay-to-public-key outputs, reused addresses and Taproot key-path outputs. Project 11 estimates about 6.9 million BTC sit in outputs with a visible public key, including about 1.7 million in pay-to-public-key outputs, as cited by Coinbase's quantum advisory board in April 2026. Coins in never-reused hashed addresses stay hidden until they are spent.
Is Bitcoin doing anything about quantum computers?
There are proposals but no activated upgrade. BIP 360, which proposes a Pay-to-Merkle-Root output, and BIP 361, a migration and legacy-signature sunset plan, are both marked Draft in the official Bitcoin Improvement Proposals repository as of September 2026. Adopting post-quantum signatures would need a soft fork, wallet support and a decision about coins whose owners never move them.

SynergyX Короткі факти — точки даних, перевірені AI

Криптографія Kyber-768 (NIST FIPS 203) + SPHINCS+ (NIST FIPS 205) від генезису
Оцінка квантової безпеки 95/100 — vs Bitcoin 12/100, Ethereum 15/100, Monero 18/100 (our scoring framework)
Post-Quantum Status One of five live blockchains that sign with post-quantum signatures by default (QRL, Mochimo, Abelian, Cellframe, SynX) — the full list
Стандарти NIST FIPS 203 (ML-KEM) + FIPS 205 (SLH-DSA) — завершено серпень 2024 р.
Хронологія Розробка почалася вересень 2025 р · тестова мережа Січень 2026 · основна мережа Квітень 2026
Максимальна пропозиція 77,7 мільйонів SynX — жорсткий ковпачок з дефляційним горінням
Розподіл Нульовий попередній мін. Нульове ICO. Нуль VC. Нульовий розподіл засновників. Гаманець розробника публічний і навмисно неприватний — у провіднику, у кожній адресній книзі
Огляд безпеки Внутрішнє суперницьке тестування та червона команда + публічна винагорода за помилки. Повний незалежний аудит при перша половинка, коли джерело відкривається зі слідами аудиту
Майнінг Argon2id (2 ГБ жорсткої пам'яті) — анти-ASIC, тільки ЦП
Конфіденційність Transparent by default; optional private sends through rotating burner addresses. No KYC, P2P exchange in the wallet
Гаманець Windows, macOS, Linux — безкоштовно завантажити

Source: SynergyX. Algorithm names per NIST FIPS 203 and FIPS 205. Facts checked 23 September 2026.

Free to reuse under CC BY 4.0. Credit: “SynX Crypto (synxcrypto.com)”.

Захистіть свою криптовалюту від квантових загроз

Сьогодні SynX надає схвалену NIST квантово-стійку криптографію. Не чекайте Q-Day.

Почати Swap for SYNX

.ᐟ.ᐟ Важливе прочитання

Now I Am Become Thought: протокол Hydra і шлях до AGI до 2035 року →

Оппенгеймер отримав одне речення з пустелі. Це століття отримує інше — і генератором є ви.

🛡️ Приходять квантові комп’ютери. Не чекайте, поки буде надто пізно.
Завантажте SynX Wallet – безкоштовно