Bitcoin’s “26-Day Quantum Attack” Is an Estimate, Not a Hack.
IonQ has put a number on a future cryptographic threat. The machine needed to carry it out does not exist today.

“Bitcoin could be cracked in 26 days” is the kind of claim that races across a feed. The missing words are doing most of the work: on a future machine, under a particular set of assumptions, per attempt.
On September 8, IonQ published a detailed resource estimate for solving the mathematical problem behind 256-bit elliptic-curve signatures on secp256k1, the curve used by Bitcoin. Its model calls for 19,397 and estimates 25.7 days per attempt.[1]
What the number actually describes
This is a calculation of the resources a sufficiently capable fault-tolerant quantum computer would need. It is not a report of a stolen private key. IonQ explicitly says no wallet, key, network or live system was touched, and that no machine capable of running the attack exists today.[1]
The distinction is crucial. An engineering estimate can make a threat more concrete without making it a present-day event. And “per attempt” is not the same thing as a guaranteed result within a deadline.

Why a hypothetical result still matters
Security changes take planning. NIST finalized its first three post-quantum cryptography standards in 2024, giving organizations tools for moving away from vulnerable forms of public-key cryptography. That does not mean a Bitcoin migration is automatic or already complete.[2]
The useful question is therefore not whether to panic at a countdown. It is whether the hardware assumptions stand up to scrutiny and whether systems can adapt before the threat becomes practical. For now, the headline is a more detailed model of a future risk. The correction is just as important: an estimate is not a hack.