Skip to content
QubitWire
SECURITY · SECURITY

Bitcoin’s “26-Day Quantum Attack” Is an Estimate, Not a Hack.

IonQ has put a number on a future cryptographic threat. The machine needed to carry it out does not exist today.

Source Published Sources checked
My reading list
Gold-coloured physical token bearing the Bitcoin symbol.
A physical Bitcoin-themed token, used as an illustration. IonQ’s publication is a resource estimate; no wallet was attacked.Photo: Physical bitcoin statistic coin.JPG · AntanaCoins · CC BY-SA 3.0

“Bitcoin could be cracked in 26 days” is the kind of claim that races across a feed. The missing words are doing most of the work: on a future machine, under a particular set of assumptions, per attempt.

On September 8, IonQ published a detailed resource estimate for solving the mathematical problem behind 256-bit elliptic-curve signatures on secp256k1, the curve used by Bitcoin. Its model calls for 19,397 and estimates 25.7 days per attempt.[1]

What the number actually describes

This is a calculation of the resources a sufficiently capable fault-tolerant quantum computer would need. It is not a report of a stolen private key. IonQ explicitly says no wallet, key, network or live system was touched, and that no machine capable of running the attack exists today.[1]

The distinction is crucial. An engineering estimate can make a threat more concrete without making it a present-day event. And “per attempt” is not the same thing as a guaranteed result within a deadline.

Ledger Nano S hardware wallet in an archive product photograph.
A Ledger Nano S hardware wallet in a 2019 archive photograph. The image is illustrative and does not imply this product was tested, breached or endorsed.Photo: Ledger Nano S - Hard Wallet - Cold Storage for Cryptocurrency 01.jpg · Motokoka · CC BY-SA 4.0

Why a hypothetical result still matters

Security changes take planning. NIST finalized its first three post-quantum cryptography standards in 2024, giving organizations tools for moving away from vulnerable forms of public-key cryptography. That does not mean a Bitcoin migration is automatic or already complete.[2]

The useful question is therefore not whether to panic at a countdown. It is whether the hardware assumptions stand up to scrutiny and whether systems can adapt before the threat becomes practical. For now, the headline is a more detailed model of a future risk. The correction is just as important: an estimate is not a hack.

READ NEXT

Continue exploring

All Security stories
  1. Related reading

    IETF Publishes Hybrid ML-KEM Key Agreement for TLS 1.3

    RFC 10024 specifies three combinations of ML-KEM and elliptic-curve key agreement at Proposed Standard maturity.

    Source date
THE QUANTUM BRIEFING

A clearer signal.
Straight to your inbox.

A little perspective on a fast-moving field.

Read a briefing preview →

Selected quantum coverage, once a week. Read a preview before joining.