Three Papers, Twelve Months: Quantum Computers Are Rewriting Cryptography's Survival Timeline

Three Papers, Twelve Months: Quantum Computers Are Rewriting Cryptography's Survival Timeline

中文 EN

Three Papers, Twelve Months: Quantum Computers Are Rewriting Cryptography's Survival Timeline

Between May 2025 and March 2026, three papers compressed the estimated quantum resources needed to break RSA-2048 and Bitcoin's elliptic curve cryptography from tens of millions of qubits down to the hundred-thousand range. This isn't incremental improvement — it's an order-of-magnitude leap. Since Peter Shor published his factoring algorithm in 1994, the cryptography community has never experienced such a dramatic threat reassessment in so short a time.

Yet reality is equally hard to ignore: the most advanced quantum processor today has just 156 qubits, still three to four orders of magnitude short of the hundred-thousand to million qubits needed for cryptographic attacks. The chasm between theoretical breakthroughs and engineering reality is the crux of this entire debate.

This article starts from these three breakthrough papers and systematically examines the technical reality of quantum threats, specific risks to cryptocurrency, the deployment progress of post-quantum cryptography, and the legitimate arguments of skeptics. Both sides have defensible positions — and the real threat may be more nuanced than either side is willing to admit.


Three Papers That Rewrote the Rules

The Gidney Paper: A 20x Compression (May 2025)

Google Quantum AI researcher Craig Gidney estimated in 2019 that breaking RSA-2048 would require approximately 20 million noisy qubits and 8 hours of computation. In May 2025, he overturned his own numbers: through approximate residue arithmetic, low-overhead logical qubit storage, and more efficient quantum state preparation, the required qubits dropped to under one million — a full 20x reduction. [arXiv:2505.15917]

The technical prerequisites of this paper: the quantum computer must run continuously for five days, with a surface code cycle time of 1 microsecond and gate error rates no higher than 0.1%. None of these conditions can be met today, but they at least define an engineering roadmap far clearer than before.

The Iceberg Pinnacle Architecture: Another 10x Reduction (February 2026)

Sydney startup Iceberg Quantum published the Pinnacle architecture paper in February 2026, proposing the use of quantum LDPC codes (qLDPC codes) instead of traditional surface codes, further reducing the physical qubit requirement for breaking RSA-2048 to under 100,000 — another 10x reduction from Gidney's million-qubit estimate. [arXiv:2602.11457]

Critical caveat: Pinnacle's results are entirely simulation-based, not experimentally validated. Its architecture requires non-local connectivity, real-time qLDPC decoding, and fault-tolerant stability lasting months — none of which have been demonstrated in any experiment. This paper shows the theoretical limits of possibility, not a near-term engineering blueprint.

The Google ECDLP-256 White Paper: Taking Aim at Bitcoin (March 2026)

On March 31, 2026, Google Quantum AI, in collaboration with Ethereum Foundation researchers and Stanford University, published a 57-page white paper specifically targeting Bitcoin's secp256k1 elliptic curve. The paper proposes two optimized quantum circuits: the first requires fewer than 1,200 logical qubits plus 90 million Toffoli gates; the second requires fewer than 1,450 logical qubits plus 70 million Toffoli gates. Converted to physical qubits, the requirement drops from the previous estimate of approximately 9 million to under 500,000 — yet another roughly 20x reduction. [Google Quantum AI White Paper]

The Quantum Insider's comment on the day of publication was incisive: "Together, these three papers represent the most significant rewrite of quantum threat assessment since Shor's algorithm in 1994."


Hardware Reality: 156 Qubits vs. Hundreds of Thousands to Millions

The theoretical resource compression is impressive, but turn to actual hardware and the picture changes dramatically.

As of early 2026, the world's most advanced quantum processors are:

  • Google Willow (December 2024): 105 superconducting qubits, coherence time (T1) of approximately 100 microseconds, first demonstration of below-threshold quantum error correction — error rates decreasing exponentially as qubit count increases.
  • IBM Heron r2/r3: 156 qubits, representing the highest publicly available qubit count. IBM's roadmap shows the Kookaburra multi-chip system (three chips totaling 4,158 qubits) for 2026, targeting a fault-tolerant quantum computer by 2029.

Placing these numbers alongside the resources needed for cryptographic attacks:

MetricCurrent BestRequired for RSA-2048Required for ECDLP-256
Physical qubits~156100,000 - 1,000,000~500,000
Coherence time~100 microsecondsDays of continuous operationMinutes
Gate error rateStill above threshold< 0.1%< 0.1%

The gap is three to four orders of magnitude. Even if IBM's Kookaburra achieves approximately 4,000 qubits on schedule in 2026, that's still more than 25x short of the 100,000 mark. And qubit scaling isn't linear — cooling systems, control electronics, wiring, crosstalk suppression — each introduces exponential engineering challenges at scale.

Quantum error correction (QEC) is another critical bottleneck. Real-time QEC requires classical electronics to process millions of error signals per second and feed back corrections within approximately 1 microsecond. Data throughput may reach hundreds of TB per second — comparable to the load of a global video streaming platform. Currently, there are only approximately 1,800-2,200 QEC specialists worldwide, with an estimated 5,000-16,000 needed by 2030. [Riverlane]


"Harvest Now, Decrypt Later": A Threat Already Underway

Before quantum computers actually break any cryptography, one attack mode is already in progress: Harvest Now, Decrypt Later (HNDL).

The logic of HNDL is straightforward: adversaries intercept and store encrypted communications now, waiting for quantum computers to mature before decrypting. For data that must remain confidential for ten years or more — government secrets, financial transaction records, medical data, intellectual property — this isn't a hypothetical threat but an established reality.

The US Department of Homeland Security (DHS), UK National Cyber Security Centre (NCSC), EU Agency for Cybersecurity (ENISA), and Australian Cyber Security Centre (ACSC) have all issued guidance premised on "adversaries are actively harvesting encrypted data." Citi's January 2026 report explicitly characterizes HNDL as "an already active threat." The US Federal Reserve has published a dedicated assessment of HNDL risks to distributed ledger networks. [Federal Reserve FEDS Working Paper]

China, Russia, and other nation-state actors are most frequently identified as likely HNDL operators. This means a harsh reality: even if quantum computers are a decade away from breaking cryptography, certain data transmitted today will still have enormous intelligence value when decrypted ten years hence.

On the HNDL threat, the cryptographic community has a rare consensus: this is the only quantum threat vector requiring immediate action. The encryption layer of post-quantum cryptography (PQC) — as opposed to digital signatures — should be deployed right now.


Bitcoin's $440 Billion Vulnerability

The quantum threat path to Bitcoin is specific and well-defined: Shor's algorithm can solve the Elliptic Curve Discrete Logarithm Problem (ECDLP), deriving private keys from public keys. Bitcoin's ECDSA with the secp256k1 curve is a direct target of this attack.

Exposed Address Types

Not all Bitcoin addresses are equally vulnerable. The critical distinction is whether the public key has been exposed on-chain:

  • P2PK (Pay-to-Public-Key): The public key is written directly on-chain, permanently exposed. This is the format from early Bitcoin (2009-2010), including Satoshi's mining addresses.
  • P2PKH (reused addresses): The public key is exposed after the first spend. If the address has never been reused, the public key remains protected by hashing.
  • P2TR (Taproot): Exposure risk exists in certain scenarios.

According to analysis by ARK Invest and Unchained, approximately 6.9 million BTC (roughly 35% of total supply) sits in theoretically vulnerable address types. About 1.7 million are in P2PK addresses (most believed to be permanently lost), and approximately 5.2 million are in addresses that can be migrated but require holder action. On the other hand, roughly 65% of Bitcoin is already in address types where the public key has never been revealed — for these coins, quantum risk is limited to "short-range scenarios" requiring quantum computation speeds far beyond current or even theoretical estimates. [CoinShares; Ledger Donjon]

Satoshi's Immovable Coins

Among all quantum vulnerability discussions, Satoshi's Bitcoin is the most dramatic case. Approximately 1 million BTC (worth roughly $76 billion) sits in P2PK format with public keys directly exposed on the blockchain. Satoshi hasn't moved these coins in over 15 years — forced migration of dormant wallets is impossible.

Google's white paper suggests a sufficiently capable quantum computer could crack these wallets in as little as 9 minutes. This has sparked a profound philosophical debate in the community: should Satoshi's coins be frozen? CoinDesk's February 2026 headline directly named the dilemma: "To Freeze or Not to Freeze: Satoshi and the $440 Billion in Quantum-Threatened Bitcoin." [CoinDesk, February 22, 2026]

Advocates like Charles Edwards push for deploying BIP-360 (Pay-to-Merkle-Root) in 2026 and suggest penalties for coins not migrated by 2028. Opponents argue that forced migration or freezing violates Bitcoin's core principle of permissionlessness.

BIP-360: Bitcoin's Quantum Defense Line

BIP-360 proposes a new output type — Pay-to-Merkle-Root (P2MR) — removing public key visibility from the chain. In March 2026, BTQ Technologies published the first working BIP-360 implementation (v0.3.0) on testnet, including full P2MR consensus, SegWit v2 outputs, 5 Dilithium post-quantum signature opcodes, and end-to-end CLI wallet tooling. [bip360.org; Bitcoin Magazine]

However, even if BIP-360 is accepted and deployed by the community, it cannot solve the dormant wallet problem. Addresses that are lost or whose holders are inactive — including Satoshi's million coins — will remain permanently exposed to quantum attack.


Ethereum and Other Blockchains' Quantum Roadmaps

Ethereum: Vitalik Buterin's Four-Layer Defense

Vitalik Buterin published Ethereum's quantum resistance roadmap in February 2026, identifying four vulnerable areas:

  1. Validator signatures: Currently using BLS signatures, needing to switch to hash-based signatures.
  2. Data storage: Currently using KZG commitments, needing quantum-safe alternatives.
  3. User accounts: EIP-8141 proposes native account abstraction supporting multiple signature methods.
  4. Zero-knowledge proofs: Quantum-safe alternatives needed.

Cost is a key concern: current ECDSA verification requires approximately 3,000 gas, while post-quantum alternatives require approximately 200,000 gas — a 67x cost increase. The Ethereum Foundation has established a post-quantum team and offers $1 million in bounties for strengthening quantum-resistant cryptography. At least one proposal is being considered for inclusion in a late-2026 upgrade. [CoinDesk, February 26, 2026]

Progress on Other Chains

  • QRL (Quantum Resistant Ledger): Launched in 2018 as the first public chain using hash-based XMSS signatures. Project Zond (Q4 2025) adds SPHINCS+ smart contracts.
  • Algorand: Completed its first Falcon-1024 mainnet transaction on November 3, 2025.
  • Solana: Replaced Ed25519 with CRYSTALS-Dilithium on public testnet in December 2025.
  • XRP Ledger: Enabled CRYSTALS-Dilithium quantum-resistant transaction testing in December 2025.
  • Circle's Arc: Expected to launch mainnet in 2026 with quantum resistance as a design requirement.

Post-Quantum Cryptography: Standards Are Ready, Deployment Has Begun

NIST Standards (Finalized August 2024)

The US National Institute of Standards and Technology (NIST) officially released the first three post-quantum cryptographic standards on August 13, 2024:

  • FIPS 203 (ML-KEM): Module-lattice-based key encapsulation mechanism, formerly CRYSTALS-Kyber. The primary standard for encryption and key exchange.
  • FIPS 204 (ML-DSA): Module-lattice-based digital signature algorithm, formerly CRYSTALS-Dilithium. The primary standard for digital signatures.
  • FIPS 205 (SLH-DSA): Stateless hash-based digital signature algorithm, formerly SPHINCS+. An alternative signature standard.

NSA CNSA 2.0 Framework

NSA's CNSA 2.0 sets clear timelines: from January 1, 2027, all new national security system acquisitions must comply with CNSA 2.0; full mandatory implementation by December 31, 2031; infrastructure migration complete by 2035. The FBI, NIST, and CISA have designated 2026 as the "Year of Quantum Security."

Tech Giants Already Deploying

Post-quantum cryptography is no longer confined to standards documents — it's already running on your devices:

  • Apple PQ3 (March 2024, iOS 17.4+): iMessage adopts a hybrid EC + PQ design with post-quantum rekeying every 50 epochs, achieving Level 3 security.
  • Signal PQXDH: The first messaging app to deploy post-quantum security at scale, Level 2 security.
  • Chrome 131+ (November 2024): TLS 1.3 defaults to X25519MLKEM768 hybrid key exchange. Firefox 132+ and Microsoft Edge 131+ followed suit.
  • Google: Set 2029 as the hard deadline for post-quantum migration across all products. ML-DSA already integrated into Google Cloud and Android 17.
  • Cloudflare: Accelerated its PQC deadline to 2029 in April 2026.

The Cost of Migration

This migration isn't cheap. Industry estimates put the total cost of enterprise-grade cybersecurity rebuilding at approximately $15 billion. Cryptographic deprecation is expected to begin in 2030, with full disallowance projected for 2035. Todd Moore, Thales's Global VP of Encryption, put it bluntly: "Quantum readiness won't be optional in 2026 — it will become policy." [Thales]


The Skeptics' Position: Why Some Cryptographers Aren't Worried

Presenting this debate fairly means taking the skeptics' arguments seriously — because they're not without merit.

The Papers Are Theoretical Estimates, Not Experimental Demonstrations

All three "breakthrough" papers are theoretical resource estimates, not experimental validations. Gidney's paper assumes 1-microsecond surface code cycles, 0.1% gate error rates, and five days of continuous operation — none achievable today. Iceberg's Pinnacle is entirely simulation-based. History shows that theoretical quantum speedups frequently encounter unexpected obstacles in practice. Quantum decoherence, crosstalk, manufacturing defects, thermal noise — all these problems worsen dramatically at scale.

Markets Aren't Pricing In Quantum Threats

Real Vision CEO Raoul Pal's argument is concise and forceful: "If quantum computing were about to destroy everything, the market would already know." Bitcoin prices and crypto markets show no quantum threat discount. Insurance markets and bond yields don't reflect imminent cryptographic breach. No major enterprise security incident has been attributed to quantum computing. [Raoul Pal]

The Attack Incentive Structure Doesn't Hold

Pal further points out an often-overlooked argument: a successful quantum attack would immediately destroy the value of the stolen assets. A comprehensive cryptographic break would trigger economic chaos, harming the attacker themselves. Nation-state actors with quantum capabilities are more likely to use them covertly (via HNDL) than to publicly demonstrate them.

The Historical Pattern of Quantum Hype

The phrase "quantum computing is 5-10 years away" has been repeated for over 20 years. Previous breakthroughs (D-Wave, Google Sycamore 2019) were followed by reality corrections. Publicly traded quantum companies face pressure to demonstrate short-term revenue, and hype serves fundraising. Grayscale's 2026 Digital Asset Outlook directly called quantum computing a "red herring" for crypto markets. [Grayscale]

65% of Bitcoin Is Already Safe

CoinShares' analysis points out that 65% of Bitcoin's supply is held in address types where the public key has never been revealed. The 35% vulnerable portion includes approximately 1.7 million BTC believed to be permanently lost. Active Bitcoin holders can migrate to quantum-safe addresses before a CRQC appears.


The Governance Problem: "Bitcoin's Quantum Problem Is Governance, Not Engineering"

On April 7, 2026, Grayscale made what may be the most profound observation of the entire debate: "Bitcoin's quantum problem is governance, not engineering." [CoinDesk, April 7, 2026]

Technical solutions already exist. BIP-360 has a working implementation. NIST standards are finalized. ML-KEM, ML-DSA, and SLH-DSA are all rigorously vetted algorithms. The question isn't "can we upgrade" but "can a decentralized community reach consensus to upgrade."

Bitcoin's consensus mechanism is designed to resist rapid change. Any protocol-level upgrade requires broad community support, miner cooperation, and node operator updates. SegWit's activation took years. Taproot's deployment journey was similarly protracted. A quantum-resistance upgrade — particularly one involving forced migration or freezing dormant addresses — would trigger political controversy far more intense than SegWit.

Ethereum is in a somewhat better position, as its governance model allows faster protocol changes and Vitalik Buterin's roadmap has clearly indicated the direction. But a 67x gas cost increase means this isn't simply a matter of "swap the signature algorithm" — it will affect the entire network's economic model.

Enterprise migration is equally difficult. The estimated $15 billion cost, the lack of crypto-agility, and the fact that most systems were never designed with the possibility of replacing cryptographic primitives all make migration slow and expensive. IAM Director Haider Iqbal's warning deserves attention: "Organizations that haven't started planning for a post-quantum world are already behind."


AI as the Unpredictable Accelerator

On April 7, 2026 — during the research period for this article — the Oratomic team published an alarming development: AI played an "instrumental" role in their quantum algorithm development. The researchers stated explicitly: "Without a doubt, we used AI to accelerate this development."

This paper directly prompted Cloudflare to accelerate its PQC deadline to 2029. Cloudflare researchers' reaction was disarmingly candid: "This is a real shock" and "In my opinion, the world isn't ready yet." Time magazine ran the headline: "AI Helped Produce a Quantum Breakthrough. The World 'Isn't Ready.'" [Time, April 7, 2026]

The convergence of AI and quantum computing represents a genuine wildcard. If AI can continuously accelerate quantum algorithm improvements — further compressing the required quantum resources — then the "still a decade away" estimates based on current hardware gaps may expire faster than expected. This isn't cause for panic, but it is reason to attach wider error bars to all timeline predictions.


What Developers Should Do Now: Pragmatic Migration Advice

Based on current threat assessments and standards maturity, here are tiered action recommendations:

Immediate Action (2026)

  • Inventory quantum-vulnerable systems: NSM-10 requires US federal agencies to submit annual inventories of quantum-vulnerable systems. Even if you're not a federal agency, this is a reasonable starting point.
  • Prioritize encryption layer migration (defend against HNDL): For systems protecting long-lived secrets, deploy ML-KEM hybrid key exchange immediately. TLS 1.3's X25519MLKEM768 is enabled by default in major browsers.
  • Ensure crypto-agility: Future systems should be designed to swap cryptographic primitives without major refactoring.

Medium-Term Planning (2026-2029)

  • Digital signature migration: Begin testing ML-DSA integration. Google has already deployed it in Android 17 — a directional indicator.
  • Cryptocurrency holders: Migrate assets to address types where public keys aren't exposed. Avoid address reuse. Follow the progress of quantum-resistance proposals like BIP-360.
  • Financial institutions: Follow the G7 Cyber Expert Group's January 2026 coordinated PQC roadmap. Citi's report estimates a single-day quantum attack on the top five US banks could cause $2-3.3 trillion in indirect damage — a figure worth including in risk assessments.

Long-Term Preparation (2029-2035)

  • Full CNSA 2.0 compliance: NSA's timeline mandates full enforcement by 2031 and infrastructure migration by 2035.
  • Monitor hardware progress: Both IBM and Google target 2029 for fault-tolerant quantum computers. Whether these milestones are achieved will be key signals for recalibrating threat assessments.

Timeline Assessment: Not Panic, but Not Wait-and-See Either

Back to the core question: when will quantum computers actually break current cryptography?

Citi's January 2026 report offers a set of probability estimates: a 19-34% chance Q-Day arrives before 2034; over 60% probability before 2044. The Global Risk Institute's 2025 survey showed 39% of experts believe a CRQC (Cryptographically Relevant Quantum Computer) will emerge within ten years — the highest ten-year estimate in the survey's seven-year history.

But probability is not certainty. The most prudent assessment is layered:

Now (2026): No quantum computer can break any current cryptography. But HNDL attacks mean long-lived secrets are already at risk.

Danger Zone (2029-2035): If hardware roadmaps from Google, IBM, and others materialize, cryptographically relevant quantum computers may appear in this window. Unmigrated systems will face genuine vulnerability.

High-Probability Zone (Beyond 2035): By then, any system not migrated to PQC faces serious risk.

The true significance of these three papers isn't that they prove quantum threats are imminent — they don't. Their significance is that they've moved the breaking threshold from "theoretically possible but engineering-wise unreachable" to "still engineering-hard but no longer fantasy." From 20 million qubits to 100,000, the gap shrank from four orders of magnitude to three. The rate of change in this direction is the signal truly worth watching.

Grayscale's observation may be the best summary: the threat is real, technical solutions exist, but for decentralized systems, the greatest obstacle isn't engineering — it's governance. Whether consensus can be reached and migration completed before quantum computers arrive will determine the outcome of this race.

For developers and organizations, this means one thing: panic isn't necessary, but the cost of waiting is growing exponentially with time. The best time to start planning post-quantum migration was the day the standards were finalized — August 13, 2024. The second-best time is now.