Short answer: not today, and not with anything on a public roadmap. Long answer: the interesting one.
You'll be able to estimate how many qubits, and how long, it takes to break a Bitcoin key on a fast or a slow machine.
Racing one Bitcoin spend, breaking its key inside the ten-minute confirmation window, was costed at about 1.9 billion physical qubits in 2022 and under half a million in 2026: the same attack, estimated twice. Today's biggest superconducting chip, IBM's Condor, has 1,121 noisy ones, and a noisy qubit is not a fraction of a corrected one until error rates are low enough. Mining is effectively safe forever. The real story is a migration problem whose deadline keeps moving closer.
Your bitcoin is protected by a padlock (your public key) whose combination (your private key) is easy to check and absurdly hard to reverse. Every classical computer on Earth working together couldn't reverse it before the sun burns out. Shor's algorithm, the famous quantum one, reverses exactly this kind of padlock efficiently. So in principle: yes, a big enough quantum computer forges your signature and spends your coins.
The catch is "big enough." Running Shor's algorithm on a Bitcoin key isn't a bigger version of anything today's machines do; it's the difference between a paper airplane and a cargo jet. The machine must run flawlessly for many minutes to hours, which requires error correction (the thing AI is helping fix, the subject of this whole site), which multiplies the hardware thousands of times over.
One more wrinkle: a padlock can only be picked if the attacker can see it. Most Bitcoin addresses keep the padlock hidden behind a hash until the moment you spend. Coins at fresh, unused addresses show attackers nothing useful, but roughly a quarter to a third of all bitcoin, including Satoshi-era coins, sits with its padlock in plain view, and Taproot adoption keeps adding more.
Working| Target | Quantum tool | Verdict |
|---|---|---|
| Signatures (ECDSA/Schnorr, 256-bit) | Shor: exponential advantage | Real threat, eventually. The only one that matters. |
| Exposed-key coins (~25–30% of supply, est.) | Shor, at leisure | First victims. Attackable whenever hardware arrives; no time pressure. |
| Mining (SHA-256) | Grover: quadratic only | Effectively safe. √ speedup loses to ASICs + error-correction overhead. |
The 10-minute window. Spending from a hashed address reveals your public key while the transaction waits (~10 minutes) to confirm. An attacker would need to run Shor's algorithm inside that window to race you, which is why serious resource estimates ask not just "can it be done" but "can it be done in an hour." That requirement multiplies the machine size, though a 2026 result cut it sharply by precomputing half the algorithm before your transaction appears (see the calculator below, and the 2026 update in the Formal section).
Why mining shrugs. Grover cuts the exponent in half (today's ~2⁷⁸ hashes of work per block become ~2³⁹ quantum steps), which sounds fatal until you price it: each quantum "hash" runs through error-corrected logic millions of times slower than an ASIC's nanosecond hash, and the speedup can't be parallelized the way mining farms trivially are. This is the same wall-clock honesty as our Grover audit: quadratic speedups die in the overhead.
Drag the sliders. The model is the one the Formal tier works in: surface-code error correction, logical error target 10⁻¹², and your choice of circuit generation: the 2017 textbook (Roetteler et al.) or the 2026 state of the art.
Circuit:
Toy model, order-of-magnitude only: distance-d surface code (2d² qubits/logical), ×3 routing/factory overhead, Toffoli gates executed serially at 1 μs × d per logical cycle. Circuit generations: 2017 textbook = Roetteler et al. (2,330 logical qubits, 1.26×10¹¹ Toffolis); 2026 state of the art = arXiv 2603.28846-class (~1,200 logical, ~7×10⁷ Toffolis). Caveats: serial execution runs ~30× slower than Webber's parallelized 2022 design at the same scale, and this plain accounting lands ~8× above the 2026 paper's compact layout (~500K qubits); read outputs as the conservative end. Real machines differ; the orders of magnitude don't.
Shor's algorithm for the elliptic-curve discrete logarithm on a 256-bit prime-field curve: 2,330 logical qubits and ≈1.26×10¹¹ Toffoli gates (Roetteler, Naehrig, Svore & Lauter, arXiv:1706.06752, computed for NIST P-256; Bitcoin's secp256k1 is the same size and comparable cost). Later circuit work cuts the Toffoli count substantially (Litinski, arXiv:2306.08585, ~5×10⁷ Toffolis via active-volume architecture and state-reuse tricks; windowed-arithmetic lines of work cut counts further), which moves the estimates down, not away.
This page asserts those counts; it does not derive how Shor's algorithm reaches them. The mechanism (the quantum Fourier transform, phase estimation, and the period-finding step that turns "factor N" into "find a period") is worked through from scratch on The Machinery. Want the one-sentence version of why any of it works before the full derivation? Start with phase kickback, the single mechanism this whole circuit runs on, repeated.
Under surface-code assumptions with physical error ~10⁻³, Webber et al. (AVS Quantum Science 2022) get: break a key in one day ≈ 13M physical qubits; in one hour ≈ 317M; inside the 10-minute confirmation window ≈ 1.9B. Compare: frontier chips today are O(10³) physical qubits with logical demonstrations at small code distance. Against those 2022 numbers, the gap to the one-day machine was ~4 orders of magnitude of scale plus sustained below-threshold operation; and to the 10-minute racing attack, ~6 orders. Those were the numbers. Then 2026 happened.
The 2026 update. A Google Quantum AI / Ethereum Foundation / Stanford team (Babbush, Zalcman, Gidney et al., arXiv:2603.28846, Mar 2026) re-costed the attack with state-of-the-art circuits: <1,200 logical qubits and <90M Toffolis, under half a million physical qubits, breaking a key in minutes, on the same 10⁻³ surface-code assumptions. Worse for the threat model: the first half of Shor's algorithm depends only on public curve parameters, so an attacker can precompute it and finish in ≈9 minutes once your transaction appears (12 minutes on the paper's second circuit), against blocks that arrive about every ten minutes. The paper puts the chance of winning that race at just under 41% under idealised assumptions, so it is a coin-flip-sized threat to a single spend, not a certainty. That moves the racing attack from "1.9 billion qubits" to "half a million," and the gap from today's largest superconducting chip to about2.6 orders of magnitude, not 6.2 (the figures are computed in the chart below). The two-axis compounding in note (iv) below isn't hypothetical; it happened between 2022 and 2026.
← swipe the diagram to see all of it →
← swipe the diagram to see all of it →
Notes the headlines skip: (i) the T/Toffoli count, not qubit count, sets runtime; magic-state throughput is the real budget (the same economics as magic-state distillation); (ii) exposed-key coins remove the time limit entirely, so the racing-attack numbers are an upper bound on difficulty, not the threat model for the 25–30% of supply with exposed keys; (iii) "harvest now, decrypt later" does not apply to signatures the way it does to encrypted traffic, since there is nothing to record today except already-public keys, which is exactly why exposed keys are the whole early game; (iv) improvements arrive on two axes at once, hardware error rates and algorithmic Toffoli counts, so tracking one axis understates the trend. That compounding is the loop this site exists to cover.
Check yourself
The 2022 estimate for a racing attack was 1.9 billion physical qubits. The 2026 estimate is about 500,000. What mostly closed that gap?
Both estimates are careful and neither is wrong. The collapse came from the algorithm side (active-volume architectures, windowed arithmetic and far lower Toffoli counts) plus the observation in arXiv:2603.28846 that the first half of Shor’s algorithm can be precomputed from public curve parameters, before your transaction exists. The lesson: a correctly-cited number can go stale by three orders of magnitude in four years. This page carried the older number once; it was fixed in editing, before the corrections log started counting.
The answer is a range rather than a date: expert surveys cluster around "a cryptographically relevant machine is plausible in the 2030s, not the 2020s", and Google planning its own post-quantum migration for 2029 tells you how seriously the people building these machines take the timeline. Bitcoin's real exposure isn't a surprise attack; it's that migrating a decentralized system takes a decade of arguing, and the clock on that has already started. What happens to exposed coins nobody migrates (burn, freeze, or free-for-all) may end up the most contentious debate in Bitcoin's history.
Who's closest to machines that matter. The table is still empty, and the page says why.
Scoreboard →