Skip to content

Build1 publisher3 min readPublished

IonQ's secp256k1 estimate spends 13 physical qubits on every logical one

The 26-day figure is a runtime rather than a date, and it works out to one logical Toffoli every 57.6 milliseconds on trapped-ion hardware whose scale IonQ's roadmap does not reach until 2028. No error rates are published to check it.

The Engineer · Build desk

Illustration accompanying IonQ's secp256k1 estimate spends 13 physical qubits on every logical one

What happened

  • IonQ researchers published what they describe as the first complete, end-to-end resource estimate for running Shor's algorithm against a real hardware architecture rather than an abstraction.
  • The job is costed at 1,457 logical qubits and roughly 39 million logical Toffoli gates, running on approximately 19,397 physical qubits and finishing the secp256k1 break in under 26 days.
  • IonQ's public roadmap targets a fully fault-tolerant system of 10,000 physical qubits by 2027, and machines at the scale the estimate requires by 2028.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • decision Teams that want a date to plan against will take 2028, which is a vendor manufacturing target rather than an output of the resource estimate, so the migration deadline inherits delivery risk from a company selling quantum hardware.
  • constraint Without a published physical error rate or gate time, nobody outside IonQ can re-derive the 26 days for a different qubit technology, so the figure does not port onto superconducting or neutral-atom roadmaps.
  • contradiction IonQ's own first fully fault-tolerant machine lands at roughly half the physical qubits this attack calls for, so the milestone most likely to be reported as a breakthrough is a smaller, earlier machine than the one that actually runs the attack.
  • exposure Every system settling value with secp256k1 signatures now has a costed worst case instead of a vague one, and the cost is low enough that key lifetime becomes the number worth arguing about, more than qubit count.

Divide 19,397 physical qubits by 1,457 logical ones and you get 13.3 physical qubits per logical qubit [16]. That ratio is where the news is. A 13-to-1 overhead is the signature of a high-rate code doing the heavy lifting, which is consistent with the optimised Walking Cat architecture the estimate targets: trapped-ion hardware, quantum low-density parity-check codes [6]. IonQ says every operation was mapped down to the error-correction primitives the hardware actually uses, which is what makes a success probability computable rather than assumed [8]. Good engineering, and the harder claim of the two. But the write-up on dev.to reports counts and runtime without the physical error rate, the code distance, or the physical gate time [19]. Those are the numbers that decide whether 13.3 to 1 hits a usable logical error rate. The headline 20,000 is 19,397 rounded up [2][5].

The runtime has the same shape. Twenty-six days is 2,246,400 seconds, and 39 million logical Toffoli gates in that window is about 17 per second, or 57.6 ms each [17]. Every error-correction cycle underneath one logical Toffoli has to fit inside that 57.6 ms. With no physical clock rate in the write-up, there is no way to tell whether that budget is comfortable or whether it is the constraint that set the 26 days [19].

The date attached to all this comes from a product roadmap [9] that targets systems of this scale by 2028; the resource estimate itself sets no date. Anyone anchoring a migration deadline to it is anchoring it to one company's manufacturing schedule, and that company also builds post-quantum cryptography and quantum key distribution hardware [20]. The pull-in is still worth taking seriously: the write-up says earlier expectations sat in the 2030s [11] and attributes the change to compounding progress across algorithms, compilers and hardware design [12]. If that is the mechanism, the crossing date is not any single vendor's to set, which cuts both ways on the 2028 number.

For planning, the estimate answers one question, which is what one key on one architecture costs. It does not say what the second key costs, and secp256k1 is the 256-bit curve behind Bitcoin and other chains [4], so whether 26 days per key is alarming depends on how many keys an attacker needs and how long yours stay worth forging. The write-up notes that no digital assets were harmed in the research [13], a sentence you only write when readers might reasonably wonder. It also reports that the study stresses rigorous stress-testing of the algorithms meant to replace current standards [14]. For anyone actually running a migration, that line carries more work than the qubit count does.

What to watch

  • Publication of the assumed physical two-qubit error rate and gate time, which would let the 26-day runtime be checked against non-trapped-ion hardware.
  • Whether the 2027 milestone of a fully fault-tolerant 10,000 physical qubit system ships, since the 2028 attack-scale date sits on top of it.
  • An independent resource estimate for the same curve that reproduces the 13-to-1 physical-to-logical ratio without qLDPC-specific assumptions.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories