IonQ shipped a 256-qubit machine and the paper saying you need 19,397
The same company published a fault-tolerant resource estimate for breaking bitcoin's curve in 25.7 days, on hardware its own roadmap puts in 2028.

IonQ did two things on September 8. It unveiled Superion 256, a 256-qubit trapped-ion machine now taking orders for 2027 delivery. And it published the first fully compiled, end-to-end fault-tolerant resource estimate for running Shor's algorithm against secp256k1, the elliptic curve bitcoin uses.
The answer in that paper is 19,397 physical qubits, 1,457 logical qubits, 39 million Toffoli gates, and 25.7 days per attempt.
So the machine IonQ announced is about one seventy-sixth of the machine IonQ says the attack needs, and the company's own note says the estimate "aligns with the scale of systems on IonQ's publicly stated hardware roadmap (~2028 timeframe)." Decrypt made the necessary point that a 256-qubit computer does not break 256-bit security, because the two numbers count different things. Correct, and probably too gentle about how odd the day was. A hardware vendor published its product launch and its own countdown clock in the same news cycle, then sells post-quantum cryptography and key distribution to the people reading both.
We are not accusing IonQ of anything. It flagged the shift itself. "In 2025, I flagged that the Q-Day time horizon was shifting materially earlier - from the 2030s to the 2020s," chairman and chief executive Niccolo de Masi said. The research is more careful than most vendor material, with a provable lower bound on success probability rather than a heuristic, and IonQ ran responsible disclosure on it. On a resource estimate. For a public curve. That is either admirable or the most elaborate courtesy in computing, and we cannot decide.
Now the part the coverage keeps missing, which is what 25.7 days actually means for a coin.
IonQ says the exposure "relates to authentication and integrity rather than to confidentiality," and that a signature compromise "is exploitable going forward rather than retroactively." Bitcoin does not have a harvest-now-decrypt-later problem. It has a public-key-already-exposed problem. To steal with Shor you need a target's public key, and then you need the coins to sit still for the better part of a month while you grind.
A pending transaction sits in the mempool for minutes. Nobody is stealing that.
What you can steal, given 26 days, is anything sitting at an address whose public key is already visible on chain and has not moved in years. Pay-to-public-key outputs from 2009 and 2010 (bitcoin's first year paid to keys, not hashes). Reused addresses. Wallets whose owner is dead or has lost the keys. Which is to say the quantum threat to bitcoin is, in the first instance, a threat to the coins nobody is watching, including Satoshi's.
Our read is that this reframes the migration debate rather than accelerating it. The Ethereum Foundation has set a December 2029 deadline for quantum-resistant transactions, validators and storage, and Galaxy put up to $5 million behind bitcoin quantum-security work in July. Those are schedules for protecting live users, and live users are probably the easy case, because a modern wallet exposes its public key only at spend time. The hard case is the coins sitting in old exposed-key outputs that no soft fork can migrate, because nobody can sign for them.
So we would expect the first serious bitcoin quantum policy fight to be about what to do with those coins — freeze, sunset, or leave them as a bounty — rather than about signature schemes, and we would expect it to reach a public BIP discussion before the end of 2027 (the arguments are already circulating, they just have no deadline yet). A credible demonstration of Shor at even trivial scale on a fault-tolerant machine would pull that forward by a year.
One more IonQ number, because it is the one that decides everything else. The company says moving from laser control to semiconductor control cuts cost per qubit by more than 300 times across its roadmap, with the SkyWater design cycle compressed from nine months to two. Qubit counts are likely a function of manufacturing more than of physics now, and manufacturing is the thing IonQ just bought.
What is your bitcoin's public key doing right now?
