QRLHUB

The Qubit Gap: 96 Logical Qubits Exist. ~1,150 Break Bitcoin.

Where quantum hardware stands today, what it takes to break Bitcoin/Ethereum signatures, and which roadmaps cross that line.

⚡ At a Glance

96

Verified logical qubits, the world record (QuEra, Nature, Jan 2026)

~1,152

Logical qubits in the leanest known ECDSA-breaking circuit (ecdsa.fail frontier)

2028-30

When major roadmaps (IonQ, Infleqtion, IBM, Oratomic) cross the threshold

The bottom line: the gap is a single order of magnitude (~12x), it is closing on every front at once (qubit counts, error rates, error-correction codes, and the attack circuits themselves), and no major chain's migration is on track to finish before the first roadmap crossings.

📏 The Gap

Logical (error-corrected) qubits are the only count that matters for Shor's algorithm. Log scale: each tick is 10x the last.

1101001k10kIBM1-2Infleqtion12Quantinuum94*QuEra96 ← world record← 12x gap →BREAKS BITCOIN (~1,100-1,425)~2-hour attack (6,500)

logical qubits (log scale)

AttackLogical QubitsPhysical Qubits (est.)Status
ECDSA-256 (Bitcoin/Ethereum)1,098 min → 1,152 (ecdsa.fail) → 1,200-1,450 (Google)<500,000 (superconducting, Google) / ~10,000-26,000 (neutral atom, Oratomic)🔴 Approaching fast
RSA-20484,000-6,190<100,000 (qLDPC) to 8M (surface code)🟡 Timeline compressed
SHA-256 mining (Grover's)>8,000Tens of millions🟢 Lower priority

*Quantinuum's 94 is postselected; QuEra's 96 is the verified error-corrected record. Both use low code distance, while attack circuits need distance ≥25, so quality must scale too, not just count (a16z, Dec 2025).

🗓️ The Timeline: Roadmaps vs. the Threshold

Logical-qubit roadmaps vs. the ~1,100-1,425 attack threshold

2026
  • 96 logical verified (QuEra world record)
  • Quantinuum 94 beyond break-even
  • ecdsa.fail frontier hits 1,152 logical qubits
2027
  • QuEra targets 100 logical / 10,000 physical
  • PsiQuantum 1M+ photonic-qubit sites (2027-28)
2028
  • 🔴 US DOE target (first fault-tolerant QC)
  • IonQ 1,600 logical (accelerated roadmap)
2029
  • 🔴 Google's own migration deadline ("Q-Day possible")
  • IBM Starling (200 logical)
2030
  • Quantinuum Apollo (fully fault-tolerant)
  • Infleqtion (1,000 logical)
  • IonQ 8,000 logical
  • Oratomic + Monarch (thousands of logical qubits "by end of decade")
2033
  • IBM Blue Jay (2,000 logical, above every ECDSA threshold)

How to read it: solid demonstrations sit at 2026; everything after is a company target. Roadmaps slip, but five independent efforts on three different hardware platforms cross the red band in a 2028-2031 window, and both Google and the US DOE have put official deadlines inside it.

🎯 The Three Benchmarks That Set the Bar

Three independent 2026 results define what it takes to steal a Bitcoin/Ethereum key. All three slashed prior estimates, and the bar keeps falling.

1. Google Quantum AI whitepaper (superconducting, Mar 30, 2026)

  • 1,425 logical qubits x 2.1M Toffoli gates (benchmark circuit); 1,200-1,450 across designs
  • <500,000 physical qubits; derives a key in ~9 minutes, inside Bitcoin's confirmation window (~18-23 min full attack), validated by a zero-knowledge proof
  • A ~20x reduction vs. prior estimates. Google set itself a 2029 migration deadline
  • Whitepaper →

2. Oratomic (neutral atom; paper Mar 31, 2026, company scaling since)

  • Shor's algorithm at cryptographic scale with ~10,000-26,000 physical atomic qubits in ~10 days, using high-rate qLDPC codes on reconfigurable atom arrays: roughly 100x below prior estimates for the platform (Cain et al., arXiv:2603.28627)
  • High-rate codes need as few as 3-4 physical qubits per logical qubit (vs. hundreds for surface codes); movable atoms provide the long-range connectivity these codes require
  • The company, not just the paper: Pasadena-based Caltech/Harvard spin-out (CEO Dolev Bluvstein; co-founders include Manuel Endres and John Preskill). Raised a $300M Series A (July 2026) co-led by ARCH, Spark Capital, and Khosla Ventures; Vinod Khosla called it his firm's largest initial investment yet, likening it to OpenAI
  • Skipping NISQ entirely to build fault-tolerant machines directly; core components demonstrated, including 6,000+ atom arrays. Partnership with Monarch Quantum (Apr 2026) targets thousands of error-corrected logical qubits by the end of the decade
  • oratomic.com →

3. ecdsa.fail (open challenge, live leaderboard, by Eigen Labs)

  • Public arena where researchers and AI agents shrink the secp256k1 Shor circuit, scored by qubits x Toffoli gates (lower is better)
  • Current frontier: 1,152 logical qubits x 1.32M Toffolis, which is 49.2% ahead of Google's benchmark circuit
  • Not a live exploit: it tracks the algorithmic floor falling in real time, in public. The hardware bar drops even when no new hardware ships
  • ecdsa.fail →

🖥️ Hardware Today

The players that matter most for the crypto timeline. Logical qubits shown as now / roadmap target.

CompanyTechPhysicalLogical (now / target)Target
QuEraNeutral atom448 (demo)96 / 1002026-27
QuantinuumTrapped ion98 (Helios)94* / fully fault-tolerant (Apollo)2030
InfleqtionNeutral atom1,60012 / 1,0002030
IonQTrapped ion256 (6th-gen)0 / 1,600 → 8,0002028 / 2030
IBMSuperconducting156 (Heron)1-2 / 200 → 2,0002029 / 2033
GoogleSuperconducting105 (Willow)below-threshold / useful FT machine2029
OratomicNeutral atombuilding (6,000+ atom arrays demonstrated by founders)0 / thousands (with Monarch)~2030
PsiQuantumPhotonicbuilding0 / 100+ (1M+ physical)2027-28
Atom ComputingNeutral atom1,180none yet / 50 (Magne)late 2026
USTC (China)Superconducting107below-threshold / scalingTBD
MicrosoftTopologicalMajorana 1R&D (first readout, Feb 2026)"years not decades"

*Postselected, beyond break-even. D-Wave (annealing) is excluded: annealing cannot run Shor's algorithm.

💥 What This Means for Crypto

  1. 1~6.9M BTC (~$470B) sits in addresses with already-exposed public keys (P2PK, reused, Taproot) that no future upgrade can protect. Includes Satoshi's ~1M BTC, exposed since 2009.
  2. 2Harvest Now, Decrypt Later is already happening. The Federal Reserve confirmed adversaries are recording blockchain data today for future decryption. Harvested data cannot be un-harvested.
  3. 3Every spend is a window. Google's whitepaper estimates ~41% theft probability for an on-spend attack during the ~10-minute mempool window.
  4. 4The defenses aren't deployed. Bitcoin: BIP-360 merged into the BIP repository (Feb 2026), BTQ testnet live, but no mainnet date. Ethereum: base-layer fix targeted ~2029; accounts, contracts, bridges, and L2s must still migrate on top.
  5. 5The migration is the slow part. Bitcoin's ~190M UTXOs at ~7 TPS is roughly a year of blocks doing nothing but migrating. The deadlines above are the schedule it has to beat.

Already protected: Quantum Resistant Ledger (QRL) has been quantum-safe since 2018 using XMSS signatures. See QRL 2.0 (Zond) and QRL FAQs.

What should you do?

  • Never reuse addresses: each spend permanently exposes your public key.
  • Track the fixes: BIP-360 (Bitcoin), Glamsterdam/Hegota (Ethereum).
  • Consider quantum-resistant alternatives like QRL / QRL 2.0.
  • Stay informed via the Quantum News page.

⚠️ Caveats

  • Code distance is the hidden gap. Today's records (QuEra's 96 at distance 4) are far below the distance ≥25 needed to run Shor's end-to-end. Count and quality must scale, but records doubled in about a year, and both are scaling.
  • Roadmaps slip. Every target above is a company projection. The picture is the convergence, not any single date.
  • Conservative views exist (Adam Back: 20-40 years) but are increasingly outliers; expert consensus now clusters on 2030-2035, with official targets (DOE 2028, Google 2029) inside this decade.

📖 Mini Glossary

TermMeaning
Physical qubitThe actual hardware qubit. Error-prone (~1-in-100 to 1-in-10,000 per operation).
Logical qubitOne reliable qubit built from many physical qubits via error correction. The unit Shor's algorithm needs.
Code distanceHow strong the error correction is. Records today: distance 4. Attacks need: ≥25.
qLDPC codesNew error-correction family cutting physical-qubit overhead ~10x (or to 3-4:1, per Oratomic) vs. surface codes.
CRQCCryptographically Relevant Quantum Computer: one that can run Shor's on real keys. None exist yet.
Q-DayThe day a CRQC breaks deployed public-key crypto. Google: possible by 2029.
HNDLHarvest Now, Decrypt Later: record encrypted/public-key data today, crack it later. Confirmed ongoing.