The Qubit Gap: 96 Logical Qubits Exist. ~1,150 Break Bitcoin.
Where quantum hardware stands today, what it takes to break Bitcoin/Ethereum signatures, and which roadmaps cross that line.
⚡ At a Glance
Verified logical qubits, the world record (QuEra, Nature, Jan 2026)
Logical qubits in the leanest known ECDSA-breaking circuit (ecdsa.fail frontier)
When major roadmaps (IonQ, Infleqtion, IBM, Oratomic) cross the threshold
The bottom line: the gap is a single order of magnitude (~12x), it is closing on every front at once (qubit counts, error rates, error-correction codes, and the attack circuits themselves), and no major chain's migration is on track to finish before the first roadmap crossings.
📏 The Gap
Logical (error-corrected) qubits are the only count that matters for Shor's algorithm. Log scale: each tick is 10x the last.
logical qubits (log scale)
| Attack | Logical Qubits | Physical Qubits (est.) | Status |
|---|---|---|---|
| ECDSA-256 (Bitcoin/Ethereum) | 1,098 min → 1,152 (ecdsa.fail) → 1,200-1,450 (Google) | <500,000 (superconducting, Google) / ~10,000-26,000 (neutral atom, Oratomic) | 🔴 Approaching fast |
| RSA-2048 | 4,000-6,190 | <100,000 (qLDPC) to 8M (surface code) | 🟡 Timeline compressed |
| SHA-256 mining (Grover's) | >8,000 | Tens of millions | 🟢 Lower priority |
*Quantinuum's 94 is postselected; QuEra's 96 is the verified error-corrected record. Both use low code distance, while attack circuits need distance ≥25, so quality must scale too, not just count (a16z, Dec 2025).
🗓️ The Timeline: Roadmaps vs. the Threshold
Logical-qubit roadmaps vs. the ~1,100-1,425 attack threshold
- 96 logical verified (QuEra world record)
- Quantinuum 94 beyond break-even
- ecdsa.fail frontier hits 1,152 logical qubits
- QuEra targets 100 logical / 10,000 physical
- PsiQuantum 1M+ photonic-qubit sites (2027-28)
- 🔴 US DOE target (first fault-tolerant QC)
- IonQ 1,600 logical (accelerated roadmap)
- 🔴 Google's own migration deadline ("Q-Day possible")
- IBM Starling (200 logical)
- Quantinuum Apollo (fully fault-tolerant)
- Infleqtion (1,000 logical)
- IonQ 8,000 logical
- Oratomic + Monarch (thousands of logical qubits "by end of decade")
- IBM Blue Jay (2,000 logical, above every ECDSA threshold)
How to read it: solid demonstrations sit at 2026; everything after is a company target. Roadmaps slip, but five independent efforts on three different hardware platforms cross the red band in a 2028-2031 window, and both Google and the US DOE have put official deadlines inside it.
🎯 The Three Benchmarks That Set the Bar
Three independent 2026 results define what it takes to steal a Bitcoin/Ethereum key. All three slashed prior estimates, and the bar keeps falling.
1. Google Quantum AI whitepaper (superconducting, Mar 30, 2026)
- 1,425 logical qubits x 2.1M Toffoli gates (benchmark circuit); 1,200-1,450 across designs
- <500,000 physical qubits; derives a key in ~9 minutes, inside Bitcoin's confirmation window (~18-23 min full attack), validated by a zero-knowledge proof
- A ~20x reduction vs. prior estimates. Google set itself a 2029 migration deadline
- Whitepaper →
2. Oratomic (neutral atom; paper Mar 31, 2026, company scaling since)
- Shor's algorithm at cryptographic scale with ~10,000-26,000 physical atomic qubits in ~10 days, using high-rate qLDPC codes on reconfigurable atom arrays: roughly 100x below prior estimates for the platform (Cain et al., arXiv:2603.28627)
- High-rate codes need as few as 3-4 physical qubits per logical qubit (vs. hundreds for surface codes); movable atoms provide the long-range connectivity these codes require
- The company, not just the paper: Pasadena-based Caltech/Harvard spin-out (CEO Dolev Bluvstein; co-founders include Manuel Endres and John Preskill). Raised a $300M Series A (July 2026) co-led by ARCH, Spark Capital, and Khosla Ventures; Vinod Khosla called it his firm's largest initial investment yet, likening it to OpenAI
- Skipping NISQ entirely to build fault-tolerant machines directly; core components demonstrated, including 6,000+ atom arrays. Partnership with Monarch Quantum (Apr 2026) targets thousands of error-corrected logical qubits by the end of the decade
- oratomic.com →
3. ecdsa.fail (open challenge, live leaderboard, by Eigen Labs)
- Public arena where researchers and AI agents shrink the secp256k1 Shor circuit, scored by qubits x Toffoli gates (lower is better)
- Current frontier: 1,152 logical qubits x 1.32M Toffolis, which is 49.2% ahead of Google's benchmark circuit
- Not a live exploit: it tracks the algorithmic floor falling in real time, in public. The hardware bar drops even when no new hardware ships
- ecdsa.fail →
🖥️ Hardware Today
The players that matter most for the crypto timeline. Logical qubits shown as now / roadmap target.
| Company | Tech | Physical | Logical (now / target) | Target |
|---|---|---|---|---|
| QuEra | Neutral atom | 448 (demo) | 96 / 100 | 2026-27 |
| Quantinuum | Trapped ion | 98 (Helios) | 94* / fully fault-tolerant (Apollo) | 2030 |
| Infleqtion | Neutral atom | 1,600 | 12 / 1,000 | 2030 |
| IonQ | Trapped ion | 256 (6th-gen) | 0 / 1,600 → 8,000 | 2028 / 2030 |
| IBM | Superconducting | 156 (Heron) | 1-2 / 200 → 2,000 | 2029 / 2033 |
| Superconducting | 105 (Willow) | below-threshold / useful FT machine | 2029 | |
| Oratomic | Neutral atom | building (6,000+ atom arrays demonstrated by founders) | 0 / thousands (with Monarch) | ~2030 |
| PsiQuantum | Photonic | building | 0 / 100+ (1M+ physical) | 2027-28 |
| Atom Computing | Neutral atom | 1,180 | none yet / 50 (Magne) | late 2026 |
| USTC (China) | Superconducting | 107 | below-threshold / scaling | TBD |
| Microsoft | Topological | Majorana 1 | R&D (first readout, Feb 2026) | "years not decades" |
*Postselected, beyond break-even. D-Wave (annealing) is excluded: annealing cannot run Shor's algorithm.
💥 What This Means for Crypto
- 1~6.9M BTC (~$470B) sits in addresses with already-exposed public keys (P2PK, reused, Taproot) that no future upgrade can protect. Includes Satoshi's ~1M BTC, exposed since 2009.
- 2Harvest Now, Decrypt Later is already happening. The Federal Reserve confirmed adversaries are recording blockchain data today for future decryption. Harvested data cannot be un-harvested.
- 3Every spend is a window. Google's whitepaper estimates ~41% theft probability for an on-spend attack during the ~10-minute mempool window.
- 4The defenses aren't deployed. Bitcoin: BIP-360 merged into the BIP repository (Feb 2026), BTQ testnet live, but no mainnet date. Ethereum: base-layer fix targeted ~2029; accounts, contracts, bridges, and L2s must still migrate on top.
- 5The migration is the slow part. Bitcoin's ~190M UTXOs at ~7 TPS is roughly a year of blocks doing nothing but migrating. The deadlines above are the schedule it has to beat.
Already protected: Quantum Resistant Ledger (QRL) has been quantum-safe since 2018 using XMSS signatures. See QRL 2.0 (Zond) and QRL FAQs.
What should you do?
- Never reuse addresses: each spend permanently exposes your public key.
- Track the fixes: BIP-360 (Bitcoin), Glamsterdam/Hegota (Ethereum).
- Consider quantum-resistant alternatives like QRL / QRL 2.0.
- Stay informed via the Quantum News page.
⚠️ Caveats
- Code distance is the hidden gap. Today's records (QuEra's 96 at distance 4) are far below the distance ≥25 needed to run Shor's end-to-end. Count and quality must scale, but records doubled in about a year, and both are scaling.
- Roadmaps slip. Every target above is a company projection. The picture is the convergence, not any single date.
- Conservative views exist (Adam Back: 20-40 years) but are increasingly outliers; expert consensus now clusters on 2030-2035, with official targets (DOE 2028, Google 2029) inside this decade.
📖 Mini Glossary
| Term | Meaning |
|---|---|
| Physical qubit | The actual hardware qubit. Error-prone (~1-in-100 to 1-in-10,000 per operation). |
| Logical qubit | One reliable qubit built from many physical qubits via error correction. The unit Shor's algorithm needs. |
| Code distance | How strong the error correction is. Records today: distance 4. Attacks need: ≥25. |
| qLDPC codes | New error-correction family cutting physical-qubit overhead ~10x (or to 3-4:1, per Oratomic) vs. surface codes. |
| CRQC | Cryptographically Relevant Quantum Computer: one that can run Shor's on real keys. None exist yet. |
| Q-Day | The day a CRQC breaks deployed public-key crypto. Google: possible by 2029. |
| HNDL | Harvest Now, Decrypt Later: record encrypted/public-key data today, crack it later. Confirmed ongoing. |
Sources
Google Quantum AI whitepaper (Mar 2026)·Cain et al. / Oratomic, arXiv:2603.28627·oratomic.com·ecdsa.fail (Eigen Labs)·Kim et al., ePrint 2026/106·Chevignard et al., ePrint 2026/280 (EUROCRYPT 2026)·Roetteler et al. 2017·QuEra, Nature (Jan 2026)·IBM roadmap·IonQ roadmap·Quantinuum roadmap·a16z analysis·Full coverage: Quantum News
Last Updated: July 14, 2026