Can quantum computers break Bitcoin?

Short answer: not today, and not with anything on a public roadmap. Long answer: the interesting one.

You'll be able to estimate how many qubits, and how long, it takes to break a Bitcoin key on a fast or a slow machine.

The answer in four lines

Racing one Bitcoin spend, breaking its key inside the ten-minute confirmation window, was costed at about 1.9 billion physical qubits in 2022 and under half a million in 2026: the same attack, estimated twice. Today's biggest superconducting chip, IBM's Condor, has 1,121 noisy ones, and a noisy qubit is not a fraction of a corrected one until error rates are low enough. Mining is effectively safe forever. The real story is a migration problem whose deadline keeps moving closer.

Plain

What a quantum computer could steal

Your bitcoin is protected by a padlock (your public key) whose combination (your private key) is easy to check and absurdly hard to reverse. Every classical computer on Earth working together couldn't reverse it before the sun burns out. Shor's algorithm, the famous quantum one, reverses exactly this kind of padlock efficiently. So in principle: yes, a big enough quantum computer forges your signature and spends your coins.

The catch is "big enough." Running Shor's algorithm on a Bitcoin key isn't a bigger version of anything today's machines do; it's the difference between a paper airplane and a cargo jet. The machine must run flawlessly for many minutes to hours, which requires error correction (the thing AI is helping fix, the subject of this whole site), which multiplies the hardware thousands of times over.

One more wrinkle: a padlock can only be picked if the attacker can see it. Most Bitcoin addresses keep the padlock hidden behind a hash until the moment you spend. Coins at fresh, unused addresses show attackers nothing useful, but roughly a quarter to a third of all bitcoin, including Satoshi-era coins, sits with its padlock in plain view, and Taproot adoption keeps adding more.

Working

The three attack surfaces, ranked by real risk

TargetQuantum toolVerdict
Signatures (ECDSA/Schnorr, 256-bit)Shor: exponential advantageReal threat, eventually. The only one that matters.
Exposed-key coins (~25–30% of supply, est.)Shor, at leisureFirst victims. Attackable whenever hardware arrives; no time pressure.
Mining (SHA-256)Grover: quadratic onlyEffectively safe. √ speedup loses to ASICs + error-correction overhead.

The 10-minute window. Spending from a hashed address reveals your public key while the transaction waits (~10 minutes) to confirm. An attacker would need to run Shor's algorithm inside that window to race you, which is why serious resource estimates ask not just "can it be done" but "can it be done in an hour." That requirement multiplies the machine size, though a 2026 result cut it sharply by precomputing half the algorithm before your transaction appears (see the calculator below, and the 2026 update in the Formal section).

Why mining shrugs. Grover cuts the exponent in half (today's ~2⁷⁸ hashes of work per block become ~2³⁹ quantum steps), which sounds fatal until you price it: each quantum "hash" runs through error-corrected logic millions of times slower than an ASIC's nanosecond hash, and the speedup can't be parallelized the way mining farms trivially are. This is the same wall-clock honesty as our Grover audit: quadratic speedups die in the overhead.

The calculator: what would it take?

Drag the sliders. The model is the one the Formal tier works in: surface-code error correction, logical error target 10⁻¹², and your choice of circuit generation: the 2017 textbook (Roetteler et al.) or the 2026 state of the art.

Shor-vs-Bitcoin resource estimator



Circuit:

Toy model, order-of-magnitude only: distance-d surface code (2d² qubits/logical), ×3 routing/factory overhead, Toffoli gates executed serially at 1 μs × d per logical cycle. Circuit generations: 2017 textbook = Roetteler et al. (2,330 logical qubits, 1.26×10¹¹ Toffolis); 2026 state of the art = arXiv 2603.28846-class (~1,200 logical, ~7×10⁷ Toffolis). Caveats: serial execution runs ~30× slower than Webber's parallelized 2022 design at the same scale, and this plain accounting lands ~8× above the 2026 paper's compact layout (~500K qubits); read outputs as the conservative end. Real machines differ; the orders of magnitude don't.

Formal

The resource estimates, with receipts

Shor's algorithm for the elliptic-curve discrete logarithm on a 256-bit prime-field curve: 2,330 logical qubits and ≈1.26×10¹¹ Toffoli gates (Roetteler, Naehrig, Svore & Lauter, arXiv:1706.06752, computed for NIST P-256; Bitcoin's secp256k1 is the same size and comparable cost). Later circuit work cuts the Toffoli count substantially (Litinski, arXiv:2306.08585, ~5×10⁷ Toffolis via active-volume architecture and state-reuse tricks; windowed-arithmetic lines of work cut counts further), which moves the estimates down, not away.

This page asserts those counts; it does not derive how Shor's algorithm reaches them. The mechanism (the quantum Fourier transform, phase estimation, and the period-finding step that turns "factor N" into "find a period") is worked through from scratch on The Machinery. Want the one-sentence version of why any of it works before the full derivation? Start with phase kickback, the single mechanism this whole circuit runs on, repeated.

Under surface-code assumptions with physical error ~10⁻³, Webber et al. (AVS Quantum Science 2022) get: break a key in one day ≈ 13M physical qubits; in one hour ≈ 317M; inside the 10-minute confirmation window ≈ . Compare: frontier chips today are O(10³) physical qubits with logical demonstrations at small code distance. Against those 2022 numbers, the gap to the one-day machine was ~4 orders of magnitude of scale plus sustained below-threshold operation; and to the 10-minute racing attack, ~6 orders. Those were the numbers. Then 2026 happened.

The 2026 update. A Google Quantum AI / Ethereum Foundation / Stanford team (Babbush, Zalcman, Gidney et al., arXiv:2603.28846, Mar 2026) re-costed the attack with state-of-the-art circuits: <1,200 logical qubits and <90M Toffolis, , breaking a key in minutes, on the same 10⁻³ surface-code assumptions. Worse for the threat model: the first half of Shor's algorithm depends only on public curve parameters, so an attacker can precompute it and finish in once your transaction appears (12 minutes on the paper's second circuit), against blocks that arrive about every ten minutes. The paper puts the chance of winning that race at just under 41% under idealised assumptions, so it is a coin-flip-sized threat to a single spend, not a certainty. That moves the racing attack from "1.9 billion qubits" to "half a million," and the gap from today's largest superconducting chip to about2.6 orders of magnitude, not 6.2 (the figures are computed in the chart below). The two-axis compounding in note (iv) below isn't hypothetical; it happened between 2022 and 2026.

2022 estimate Webber et al. 1.9 billion 2026 estimate Babbush et al. under 500 thousand IBM Condor, 2023 largest superconducting chip 1,121 Google Willow, 2024 runs below threshold 105 10² 10⁴ 10⁶ 10⁸ physical qubits (logarithmic: each tick to the right is 100×)

← swipe the diagram to see all of it →

The same attack got 3,800× cheaper in four years. Webber et al. (AVS Quantum Science, 2022) costed the racing attack at 1.9 billion physical qubits. In March 2026 Babbush, Zalcman, Gidney et al. (Google Quantum AI, the Ethereum Foundation and Stanford; arXiv:2603.28846) re-costed it at under half a million, partly because the first half of Shor’s algorithm can be precomputed before your transaction appears. Against IBM’s 1,121-qubit Condor that is at most 2.6 orders of magnitude away, not the 6.2 of 2022; against Google’s 105-qubit Willow, the only machine here that runs error correction below threshold, it is at most 3.7. The axis is logarithmic, so the short yellow bars are much further from the others than they look. The full numbers, with caveats ▸
Cain et al., 2026 as few as, slower 10,000 Cain et al., 2026 for P-256, in days 26,000 Caltech array, 2025 trapped, not computing 6,100 10² 10⁴ 10⁶ 10⁸ physical qubits (logarithmic: each tick to the right is 100×)

← swipe the diagram to see all of it →

A slower machine needs far fewer qubits, but it cannot race your transaction. Cain et al. (arXiv:2603.28627) count reconfigurable neutral atoms, whose cycles take milliseconds, not microseconds: as few as 10,000 atoms can run Shor’s algorithm, and 26,000 could solve a P-256 discrete logarithm in a few days. Days is fine for a key that sits exposed on the chain, and useless against the ten-minute confirmation window. The largest array on record holds 6,100 trapped atoms, only 4.3× short of the higher figure, but trapping atoms is not computing with them: the paper reports computation on arrays of hundreds.

Notes the headlines skip: (i) the T/Toffoli count, not qubit count, sets runtime; magic-state throughput is the real budget (the same economics as magic-state distillation); (ii) exposed-key coins remove the time limit entirely, so the racing-attack numbers are an upper bound on difficulty, not the threat model for the 25–30% of supply with exposed keys; (iii) "harvest now, decrypt later" does not apply to signatures the way it does to encrypted traffic, since there is nothing to record today except already-public keys, which is exactly why exposed keys are the whole early game; (iv) improvements arrive on two axes at once, hardware error rates and algorithmic Toffoli counts, so tracking one axis understates the trend. That compounding is the loop this site exists to cover.

Check yourself

The 2022 estimate for a racing attack was 1.9 billion physical qubits. The 2026 estimate is about 500,000. What mostly closed that gap?

Both estimates are careful and neither is wrong. The collapse came from the algorithm side (active-volume architectures, windowed arithmetic and far lower Toffoli counts) plus the observation in arXiv:2603.28846 that the first half of Shor’s algorithm can be precomputed from public curve parameters, before your transaction exists. The lesson: a correctly-cited number can go stale by three orders of magnitude in four years. This page carried the older number once; it was fixed in editing, before the corrections log started counting.

So when should anyone start to worry?

The answer is a range rather than a date: expert surveys cluster around "a cryptographically relevant machine is plausible in the 2030s, not the 2020s", and Google planning its own post-quantum migration for 2029 tells you how seriously the people building these machines take the timeline. Bitcoin's real exposure isn't a surprise attack; it's that migrating a decentralized system takes a decade of arguing, and the clock on that has already started. What happens to exposed coins nobody migrates (burn, freeze, or free-for-all) may end up the most contentious debate in Bitcoin's history.

Google's 2029 migration date — tracked on The Ledger →

Go deeper

Error correction, Plain

Why quantum computers need babysitting at all.

Read →

The math floor

Surface codes, decoders, and the Grover audit this page leans on.

Read →

🏁 The Race

Who's closest to machines that matter. The table is still empty, and the page says why.

Scoreboard →
Next in this trackPost-quantum, on the wire: seven live toolsProve itThe Solver's Path: the main questJudge a claimDid they do what they said? The Ledger