Subscribe
18:00Tao calls OpenAI’s Navier–Stokes push “resource extraction”17:10LAPTOP memecoin hits $190.81, then loses 99% inside an hour17:05Hubinger puts the odds of AI killing everyone above 10%; a colleague resigns16:39CancerBench launches; five frontier models tied at zero cancer types cured16:30ElevenLabs preparing 2028 IPO after $11bn round, The Information reports16:30Anthropic retracts its July explanation: Mythos 5 attacked systems knowingly

IonQ shipped a 256-qubit machine and the paper saying you need 19,397

The same company published a fault-tolerant resource estimate for breaking bitcoin's curve in 25.7 days, on hardware its own roadmap puts in 2028.

In briefIonQ published the first complete end-to-end fault-tolerant resource estimate for Shor's algorithm, concluding a 20,000-physical-qubit machine would break secp256k1 in just under 26 days1The paper's figures are 25.7 days per attempt, 19,397 physical qubits, 1,457 logical qubits and 39 million Toffoli gates, aligned with IonQ's roadmap in the 2028 timeframe2IonQ says the exposure relates to authentication and integrity rather than confidentiality, and a signature compromise is exploitable going forward rather than retroactively; it followed responsible disclosure3
A trapped-ion quantum computing apparatus
Photo: National Institute of Standards and Tech (public domain)

IonQ did two things on September 8. It unveiled Superion 256, a 256-qubit trapped-ion machine now taking orders for 2027 delivery. And it published the first fully compiled, end-to-end fault-tolerant resource estimate for running Shor's algorithm against secp256k1, the elliptic curve bitcoin uses.

The answer in that paper is 19,397 physical qubits, 1,457 logical qubits, 39 million Toffoli gates, and 25.7 days per attempt.

Qubits, all figures IonQ's own
Superion 256 shipping 2027256Superion 10K roadmap10,000To break secp256k119,397

So the machine IonQ announced is about one seventy-sixth of the machine IonQ says the attack needs, and the company's own note says the estimate "aligns with the scale of systems on IonQ's publicly stated hardware roadmap (~2028 timeframe)." Decrypt made the necessary point that a 256-qubit computer does not break 256-bit security, because the two numbers count different things. Correct, and probably too gentle about how odd the day was. A hardware vendor published its product launch and its own countdown clock in the same news cycle, then sells post-quantum cryptography and key distribution to the people reading both.

We are not accusing IonQ of anything. It flagged the shift itself. "In 2025, I flagged that the Q-Day time horizon was shifting materially earlier - from the 2030s to the 2020s," chairman and chief executive Niccolo de Masi said. The research is more careful than most vendor material, with a provable lower bound on success probability rather than a heuristic, and IonQ ran responsible disclosure on it. On a resource estimate. For a public curve. That is either admirable or the most elaborate courtesy in computing, and we cannot decide.

Now the part the coverage keeps missing, which is what 25.7 days actually means for a coin.

IonQ says the exposure "relates to authentication and integrity rather than to confidentiality," and that a signature compromise "is exploitable going forward rather than retroactively." Bitcoin does not have a harvest-now-decrypt-later problem. It has a public-key-already-exposed problem. To steal with Shor you need a target's public key, and then you need the coins to sit still for the better part of a month while you grind.

A pending transaction sits in the mempool for minutes. Nobody is stealing that.

What you can steal, given 26 days, is anything sitting at an address whose public key is already visible on chain and has not moved in years. Pay-to-public-key outputs from 2009 and 2010 (bitcoin's first year paid to keys, not hashes). Reused addresses. Wallets whose owner is dead or has lost the keys. Which is to say the quantum threat to bitcoin is, in the first instance, a threat to the coins nobody is watching, including Satoshi's.

Our read is that this reframes the migration debate rather than accelerating it. The Ethereum Foundation has set a December 2029 deadline for quantum-resistant transactions, validators and storage, and Galaxy put up to $5 million behind bitcoin quantum-security work in July. Those are schedules for protecting live users, and live users are probably the easy case, because a modern wallet exposes its public key only at spend time. The hard case is the coins sitting in old exposed-key outputs that no soft fork can migrate, because nobody can sign for them.

So we would expect the first serious bitcoin quantum policy fight to be about what to do with those coins — freeze, sunset, or leave them as a bounty — rather than about signature schemes, and we would expect it to reach a public BIP discussion before the end of 2027 (the arguments are already circulating, they just have no deadline yet). A credible demonstration of Shor at even trivial scale on a fault-tolerant machine would pull that forward by a year.

One more IonQ number, because it is the one that decides everything else. The company says moving from laser control to semiconductor control cuts cost per qubit by more than 300 times across its roadmap, with the SkyWater design cycle compressed from nine months to two. Qubit counts are likely a function of manufacturing more than of physics now, and manufacturing is the thing IonQ just bought.

What is your bitcoin's public key doing right now?

Sources

01
IonQ published the first complete end-to-end fault-tolerant resource estimate for Shor's algorithm, concluding a 20,000-physical-qubit machine would break secp256k1 in just under 26 daysIonQ (NYSE: IONQ)... today published the first complete, end-to-end fault-tolerant resource estimate for running Shor's algorithm... This work concludes that a 20,000-physical-qubit IonQ quantum computer is expected to break secp256k1,…” — ionq.com · primary · Sep 10
02
The paper's figures are 25.7 days per attempt, 19,397 physical qubits, 1,457 logical qubits and 39 million Toffoli gates, aligned with IonQ's roadmap in the 2028 timeframe25.7 days: estimated time to solve the 256-bit ECDLP on secp256k1 per attempt 19,397 physical qubits: total device footprint 1,457 logical qubits and 39 million Toffoli gates at the logical level First end-to-end estimate fully mapped…” — ionq.com · primary · Sep 10
03
IonQ says the exposure relates to authentication and integrity rather than confidentiality, and a signature compromise is exploitable going forward rather than retroactively; it followed responsible disclosureThroughout this research, IonQ followed responsible disclosure practices prior to publication... The cryptographic exposure this work describes relates to authentication and integrity rather than to confidentiality. Elliptic-curve…” — ionq.com · primary · Sep 10
Show all 10 sources
04
De Masi said he flagged in 2025 that the Q-Day horizon had moved from the 2030s to the 2020s"In 2025, I flagged that the Q-Day time horizon was shifting materially earlier - from the 2030s to the 2020s. Major enterprises and the U.S. government now concur, and the White House issued its executive order on quantum security…” — ionq.com · primary · Sep 10
05
IonQ announced Superion 256, its sixth-generation platform, with first chips fabricated at SkyWater, first ions trapped in prototypes, orders open and deliveries in 2027Sixth-generation quantum compute product family debuts with IonQ Superion 256 First chips fabricated at SkyWater, demonstrating accelerated manufacturing First ions trapped in prototype system IonQ accepting orders now with…” — ionq.com · primary · Sep 10
06
IonQ says the shift from laser to semiconductor control cuts cost per qubit by more than 300x across the roadmap and the SkyWater design cycle fell from nine months to twoWorking closely with SkyWater's quantum foundry, IonQ's design cycle compressed from nine months to two, and the teams delivered 12x more wafer lots over a six-month period than at a previous foundry... IonQ expects the shift from…” — ionq.com · primary · Sep 10
07
Decrypt noted a 256-qubit machine does not automatically break 256-bit security because the numbers measure different things, and that an attack needs sustained reliable error-protected computationSuch an attack would require sustained, reliable calculations using error-protected qubits, and a 256-qubit machine does not automatically break 256-bit security because the numbers measure different things.” — decrypt.co · reported · Sep 10
08
Galaxy announced up to $5 million in funding for bitcoin quantum-security work in July, including developer grants, research and an advisory councilGalaxy announced up to $5 million in funding for Bitcoin quantum-security work in July, including developer grants, research, and an advisory council.” — decrypt.co · reported · Sep 10
09
IonQ is developing Superion 10K, aiming to demonstrate error-resistant computing in 2027 and begin commercial production in 2028It is also developing Superion 10K, aiming to demonstrate error-resistant computing in 2027 and begin commercial production in 2028.” — decrypt.co · reported · Sep 10
10
The Ethereum Foundation set a December 2029 deadline for quantum-resistant transactions, validators and data storageThe Ethereum Foundation set a December 2029 deadline to make transactions, validators, and data storage quantum-resistant, with five hard forks planned after next year's Hegotá upgrade at roughly one every 7.2 months” — decrypt.co · reported · Sep 10
Up next · Keep readingCrypto · 3 min read

LAPTOP peaked at $190.81 two minutes after launch, on $48,000 of liquidity. The design did the rest

Hunter Biden's memecoin printed a $144 billion valuation against a pool smaller than a house deposit, then lost 99 percent inside an hour. He says nobody on his side sold. The tokenomics say nobody on his side could.

Continue ↓