IonQ published the first fully compiled blueprint showing a 20,000-physical-qubit machine could break Bitcoin's secp256k1 encryption in 26 days, sharpening the fault-tolerant quantum race.
IonQ published the first fully compiled blueprint showing a 20,000-physical-qubit machine could break Bitcoin's secp256k1 encryption in 26 days, sharpening the fault-tolerant quantum race.

A 20,000-physical-qubit IonQ computer could solve the discrete logarithm problem behind Bitcoin's secp256k1 encryption in under 26 days, per the first fully compiled fault-tolerant resource estimate the company released.
"Major enterprises and the U.S. government now concur, and the White House issued its executive order on quantum security earlier this summer," Niccolo de Masi, chairman and chief executive officer at IonQ, said.
The estimate, built on the Walking Cat architecture IonQ published in April, compiles every operation down to the error-correction primitives the machine runs. It requires 19,397 physical qubits, 1,457 logical qubits and 39 million Toffoli gates to solve the elliptic-curve discrete logarithm problem on secp256k1, the curve securing Bitcoin and other blockchain networks. IonQ said the footprint matches systems on its public roadmap targeting the 2028 timeframe, and it remains on track to deliver a fully fault-tolerant 10,000-physical-qubit machine in 2027.
The result reframes the race against IBM, Google and Quantinuum, all of which are chasing fault-tolerant machines, and pressures the cryptography industry to accelerate migration off elliptic-curve signatures. IonQ, which trades on the NYSE under IONQ, said the same full-stack method extends to chemistry, materials and defense applications on its roadmap.
A Capability Milestone, Not Just a Security Finding
The paper is the first to estimate a utility-scale algorithm's cost without approximating away the parts that dominate a real machine's runtime, according to IonQ. Earlier work on optimized point-addition circuits for elliptic-curve cryptocurrencies produced logical-layer figures; what is new is the architecture-specific accounting on a high-rate error-corrected trapped-ion machine rather than a surface code. IonQ said it proved, rather than assumed, a lower bound on the probability the full computation succeeds.
The reduction is steep: computations that once demanded millions of physical qubits now fit on a 20,000-qubit machine, according to Martin Roetteler, vice president of quantum applications R&D at IonQ. That compression, achieved by optimizing the algorithm, compiler, hardware architecture and error-correction layer in tandem, is what maps the result to commercial workloads beyond cryptography.
The company framed the result as a capability milestone first and a security finding second. The cryptographic exposure touches authentication and integrity rather than confidentiality: elliptic-curve signatures underpin code signing, certificate hierarchies, device identity and long-lived roots of trust. Unlike an attack on encrypted data, a signature compromise is exploitable going forward rather than retroactively against traffic recorded today.
IonQ followed responsible disclosure, sharing advance copies with U.S. government and industry partners before publication. The mitigation is standardized and available now: both the Stateless Hash-Based Digital Signature Algorithm and ML-DSA are unaffected by this class of result.
The Competitive Stakes
IonQ's estimate lands as IBM, Google and Quantinuum push their own fault-tolerant roadmaps, and it gives the company a concrete number to defend its full-stack approach. The company reached 99.99% two-qubit gate fidelity in 2025, a world record, and counts Amazon Web Services, AstraZeneca and NVIDIA among customers that reported a 20x performance increase over earlier quantum systems.
De Masi said the Q-Day time horizon has shifted from the 2030s to the 2020s, a view he flagged in 2025 and that the White House's executive order on quantum security this summer now reflects. For investors, the paper is a marker in a sector where fault-tolerance has long been a distant promise: IonQ's dated target of reaching the relevant scale by 2028 gives it a timeline to measure against IBM's and Google's own fault-tolerance roadmaps. The company did not disclose a stock reaction to the announcement.
This article is for informational purposes only and does not constitute investment advice.