Ionq

IonQ estimates 19,397 physical qubits and 25.7 days to run Shor on secp256k1

On September 8, 2026, IonQ published a resource estimate for solving the discrete logarithm problem of the 256‑bit elliptic curve secp256k1 using Shor’s algorithmShor’s Algorithm / Shor's Algorithm / Shor AlgorithmA quantum algorithm for efficiently factoring large integers on a quantum computer. It is widely known for its implications for the security of public-key cryptography.QI NoteNo efficient classical algorithm for integer factorization is known, and this algorithm is regarded as a representative example demonstrating quantum advantage. Its impact on schemes such as RSA is theoretically significant, but decrypting practical cryptographic keys would require large-scale, high-fidelity quantum computation. on a fault‑tolerant quantum computer. The company estimates 19,397 physical qubitsPhysical Qubit / Physical QubitIndividual qubits that are physically created and manipulated on a quantum processor. They are also used to form logical qubits.QI NoteA large number of physical qubits does not by itself indicate practical computational capability. Error rates, connectivity, and the number of physical qubits required per logical qubit are also important. and a runtime of 25.7 days per attempt, but this is not a demonstration of cryptographic breaking on a physical device.

✍️ Quantum Index Analysis
We explain the technical and business implications behind the announcement and evaluation points that are not obvious from the numbers or headlines alone. Read our analysis ↓

Summary

This study targets secp256k1, the elliptic curve used by Bitcoin and others, and maps Shor’s algorithm onto a specific fault‑tolerant quantum computer design to produce a concrete resource estimate. It is based on IonQ’s Walking Cat architectureWalking Catアーキテクチャ / Walking Cat ArchitectureA fault-tolerant quantum computing architecture for trapped-ion quantum computers proposed by researchers including IonQ. It performs logical operations by leveraging quantum LDPC codes and cat states.QI NoteIt should be considered as a system-level design that includes not only the number of physical qubits but also the chosen error-correcting code, the number of logical qubits, logical gate speeds, and other aspects. At present it is an architecture based on proposals and simulations, and is not the name of a completed, operational device., published in April 2026, and assumes trapped‑ion hardware combined with quantum LDPC codes. The estimated computation scale is 19,397 physical qubits, 1,457 logical qubitsLogical Qubit / Logical QubitA unit of information treated as a single qubit protected from errors by using multiple physical qubits and quantum error correction.QI NoteSimply having “created a logical qubit” does not necessarily mean fault-tolerant quantum computing (FTQC) has been achieved. One should verify logical error rates, operational/gate performance, and scalability., and 39 million Toffoli gates at the logical level. The runtime for a single attempt is estimated at 25.7 days, and the authors report having derived a provable lower bound on the overall success probability of the computation. A notable aspect is that the evaluation integrates not only logical gate counts but also the algorithm, compiler, hardware configuration, and quantum error correction量子誤り訂正 / Quantum Error Correction / QECA technique that distributes information across multiple physical qubits and detects and corrects errors without directly disturbing the quantum state.QI NoteSimply implementing it does not automatically provide practical fault tolerance. What matters is whether the logical error rate is improved relative to the physical error rate. down to the basic error‑correction operations. However, specific numerical values for the success probability and detailed circuits have not been publicly released. IonQ positions a system with the relevant capabilities on its roadmap around 2028. This publication is a design and resource study based on that projected scale and does not indicate that any operational digital assets or cryptographic platforms have actually been compromised.

Key points

  • The target is the elliptic curve discrete logarithm problem for the 256‑bit curve secp256k1.
  • Estimated required resources: 19,397 physical qubits, 1,457 logical qubits, and 39 million Toffoli gates.
  • Estimated runtime per attempt is 25.7 days, and a provable lower bound on the overall success probability is provided.
  • The evaluation assumes the Walking Cat architecture using trapped ions and quantum LDPC codes, and includes error‑correction circuits in the assessment.
  • This is a design and resource estimate based on IonQ’s roadmap target around 2028, not an on‑device cryptographic break.

Technical and business implications

On the technical side, the significance lies in concretizing the computational resources required not only for logical operations needed for cryptanalysis but also for a specific trapped‑ion configuration and the basic operations of quantum error correction. This serves as an example of a design methodology that jointly optimizes algorithm and hardware for fault‑tolerant quantum computing. From a business and security perspective, the work provides data to inform migration to post‑quantum cryptography for systems that rely on elliptic‑curve signatures—such as code signing, certificate hierarchies, device IDs, and long‑term trust anchors. However, whether the estimated performance can be reproduced on actual hardware remains unconfirmed, and the publication does not imply that existing systems can be immediately broken. IonQ has stated that SLH‑DSA and ML‑DSA are not affected by the kind of results presented here.

What to watch next

First, attention will focus on how concretely IonQ can realize a system on the order of ~20,000 physical qubits and whether the assumed error‑correction operations can be run on actual hardware. Next, it will be important to validate, under real‑device conditions, the 25.7‑day runtime and the claimed overall success probability. The verifiability of the non‑public circuits and whether comparative evaluations with other approaches are published will also be key factors in assessing the credibility of this resource estimate.

✍️ Quantum Index Analysis

This announcement does not mean secp256k1 used by Bitcoin and others has been broken by quantum computers today. The relevant evaluation is that Shor’s algorithmShor’s Algorithm / Shor's Algorithm / Shor AlgorithmA quantum algorithm for efficiently factoring large integers on a quantum computer. It is widely known for its implications for the security of public-key cryptography.QI NoteNo efficient classical algorithm for integer factorization is known, and this algorithm is regarded as a representative example demonstrating quantum advantage. Its impact on schemes such as RSA is theoretically significant, but decrypting practical cryptographic keys would require large-scale, high-fidelity quantum computation. has been concretized by IonQ down to its proposed fault‑tolerant “Walking Cat” architecture, and that the necessary computational resources have been estimated.

The “Cat” in Walking Cat refers to cat states used for logical measurements and is distinct from the cat qubitCat Qubit / Cat Qubit / Schrödinger Cat QubitA qubit designed to use "cat states"—superpositions of distinct quantum states—to make certain types of errors less likely.QI NoteIt may reduce the overhead required for error correction, but not all errors are automatically suppressed. Attention should also be paid to the remaining error rates. developed by Alice & Bob. IonQ assumes a configuration that combines trapped‑ion transport capability with quantum LDPC codes and uses these auxiliary cat states where needed. Therefore, the figures—19,397 physical qubitsPhysical Qubit / Physical QubitIndividual qubits that are physically created and manipulated on a quantum processor. They are also used to form logical qubits.QI NoteA large number of physical qubits does not by itself indicate practical computational capability. Error rates, connectivity, and the number of physical qubits required per logical qubit are also important. and 25.7 days—are estimates contingent on this particular hardware design and assumed error‑correction performance.

Reaching roughly 20,000 physical qubits would not by itself enable immediate cryptographic breaks. To assess actual threat levels, it is crucial to determine whether 1,457 logical qubitsLogical Qubit / Logical QubitA unit of information treated as a single qubit protected from errors by using multiple physical qubits and quantum error correction.QI NoteSimply having “created a logical qubit” does not necessarily mean fault-tolerant quantum computing (FTQC) has been achieved. One should verify logical error rates, operational/gate performance, and scalability. can be maintained at the required logical error rates and whether a computation involving about 39 million Toffoli gates can be completed reliably over an extended period. Going forward, the extent to which error‑correction performance and overall success probability can be reproduced on hardware, and whether the resource estimates are independently verified, will be the main criteria for judgment.

NETWORKExplore IonQ’s industry network →

Related articles

Source

Read the original announcement

If you found this article useful, please consider sharing it.
𝕏 Share this article

Similar Posts