Skip to content

Security1 publisher2 min readPublished

A new IACR estimate sizes the secp256k1 break at 1,450 logical qubits and 40 million Toffoli gates

The algorithm-level numbers are the part of the estimate that can be recompiled onto any fault-tolerant machine, and the headline 25.7 days on 19,397 physical qubits belongs to the trapped-ion architecture its own authors proposed.

The Watch · Security desk

Photograph accompanying A new IACR estimate sizes the secp256k1 break at 1,450 logical qubits and 40 million Toffoli gates
Photo: postquantum.com

What happened

  • An IACR ePrint report, listed in a news item dated 10 September 2026, is credited to at least 13 authors, with the notice truncating the list.
  • It targets the 256-bit elliptic curve discrete logarithm problem on secp256k1, the curve used by blockchain technologies such as Bitcoin, using Shor's algorithm.
  • Compiled to the authors' trapped-ion architecture, that circuit runs in approximately 25.7 days on 19,397 physical qubits with an estimated 63% success probability.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint The logical circuit size can be recompiled onto other error-correction schemes, but the 25.7-day runtime is tied to the Walking Cat Architecture its own authors proposed, so it cannot be lifted onto a different hardware roadmap.
  • cost A 63% per-run success rate means an attacker budgets about 1.59 attempts, or roughly 41 days of a large machine reserved for one key, before expecting a result.
  • exposure The exposed population is keys on this curve whose public halves must stay valid longer than it takes anyone to field about 19,400 physical qubits with the paper's cat-state features.
  • decision Holders of long-lived secp256k1 keys can now schedule migration against two published numbers, a logical qubit count and a Toffoli count, and stop treating the timing as unquantified.

Divide the two qubit counts. About 1,450 logical qubits compile down to 19,397 physical ones, roughly 13.4 physical per logical [10]. That ratio carries the runtime claim, and it comes from the architecture the same group designed, described in the abstract as "our recently proposed Walking Cat Architecture" and offered here as a proof-of-concept optimization [6].

The algorithm-level figures are the durable part. The authors took the circuits from Schrottenloher's recent work and optimized them to about 1,450 qubits and 40 million Toffoli gates [7][3]. Anyone can recompile those onto a different error-correction scheme. The 19,397 and the 25.7 days assume this paper's machinery: non-overlapping cat-based measurements run in parallel, the logical CliNR protocol for Clifford operations, a more efficient loss correction protocol, recycled CliNR ancilla qubits, and reusable cat-state resources provisioned to the circuit's peak measurement parallelism [9].

Now the pace. 25.7 days is 2,220,480 seconds, so 40 million Toffoli gates in that window averages about 18 per second, roughly 56 milliseconds apiece [11]. That average rests on a fast CCZ magic-state factory and a depth-one CCZ state injection, which the paper credits with cutting CCZ gate execution time by a factor of 31 [8].

The 63% is an estimated end-to-end success probability [5]. At that rate an attacker averages about 1.59 runs, near 41 days of machine time held for a single key [12]. The rigorous claim sits lower in the stack: a lower bound on the logical-level success probability holding with confidence at least 1 minus 2^-128, with a heuristic estimate alongside it [4].

Nothing an attacker can run today changes. The abstract sets no date for hardware and states only that a trapped-ion computer based on the architecture "would be able to solve" the ECDLP on secp256k1 in approximately 25.7 days [13]. What a planner can track is the physical qubit count in trapped-ion devices, and the physical-to-logical ratio in the next group's estimate, because 13.4 is aggressive: a ratio ten times worse puts the same 1,450-logical-qubit circuit near 194,000 physical qubits [14].

What to watch

  • An independent group compiling the same 1,450-qubit circuit and publishing its own physical-to-logical ratio.
  • Peer review of the factor-31 CCZ magic-state factory and the loss correction protocol the runtime depends on.
  • Any trapped-ion hardware roadmap that names a date for 19,397 physical qubits with cat-state measurement support.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories