Security1 publisher3 min readPublished
IonQ's compiled secp256k1 break needs twice the qubits of its 2027 machine
IonQ's September 8 paper puts one secp256k1 key at just under 26 days on 20,000 physical qubits. The company's roadmap reaches 10,000 fault-tolerant qubits in 2027 and names no year for the larger machine.
The Watch · Security desk

What happened
- IonQ published on September 8, 2026 what it calls the first complete, end-to-end fault-tolerant resource estimate for running Shor's algorithm.
- The paper concludes a 20,000-physical-qubit IonQ machine would break secp256k1, the 256-bit elliptic curve behind Bitcoin, in just under 26 days.
- Chris Ballance, IonQ's president of quantum computing, said no deployed digital asset or crypto platform was affected during the research.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- capability Crypto-inventory and PQC migration plans now have a specific per-key runtime and qubit count to cost against, attached to a named architecture rather than a decade range.
- constraint At about 14 keys a year on a single machine, the published economics point at selected high-value keys, not at mass compromise of a signature scheme.
- decision Anyone setting a migration deadline can anchor it to IonQ's own roadmap gap: the estimate needs double the qubits of the system the company says arrives in 2027.
"Fully compiled" carries the weight here. IonQ says its researchers costed the algorithm without approximating away the layers that usually dominate a real machine's runtime, and Chris Ballance, IonQ's president of quantum computing, said the team "compiled every operation down to the actual error-correction primitives our architecture runs" [4]. The curve was picked for its exposure to scrutiny: IonQ says secp256k1 is one of the most scrutinized cryptography standards in production today [17].
The estimate covers the elliptic curve discrete logarithm problem on an optimized version of IonQ's Walking Cat architecture, which the company published in April 2026 as a full-stack fault-tolerant blueprint built on trapped ions and quantum LDPC codes [3].
The 26 days is one key on one machine [2]. Run that machine continuously and it clears about 14 keys a year, 365 divided by 26 [13]. The announcement gives no figure for splitting the computation across machines, so on the numbers published the first owner of such a system picks a small set of targets.
The estimate calls for 20,000 physical qubits [2]. Niccolo de Masi, IonQ's chairman and CEO, said the company is on track for a fully fault tolerant 10,000 physical qubit system in 2027, with further advances in labs, manufacturing and deployments in 2028 [7]. That is half the machine the estimate requires [14]. The announcement names 2027 and 2028 and no year for a 20,000-qubit system [15]. Martin Roetteler, IonQ's VP of quantum applications R&D, said "A computation that once demanded millions of physical qubits now fits on a 20,000-qubit IonQ machine on our roadmap" [11]. Those last three words attach the claim to a machine the roadmap has not yet dated.
IonQ also sells the mitigation. De Masi's statement lists software, post-quantum cryptography and quantum key distribution hardware, and says IonQ is "uniquely positioned to help secure our nation and allies against the cyber risks our adversaries will pose in the quantum era" [8]. He said "In 2025, I flagged that the Q-Day time horizon was shifting materially earlier - from the 2030s to the 2020s" [9]. The technical framing in the same release is narrower: IonQ says the result is a capability milestone first and a security finding second [10].
This is a resource estimate. It is not a demonstrated attack. Ballance said "no deployed digital asset nor crypto platform was affected during IonQ's research" [6]. What operators get is a named architecture, a named qubit count and a per-key runtime they can argue against in a budget meeting, published by the company that builds the machine. The announcement credits IonQ's own research team and does not mention independent replication or peer review [16].
What to watch
- An independent resource estimate for secp256k1 on the Walking Cat architecture, from a group that does not also sell PQC and QKD.
- Whether the fully fault-tolerant 10,000-physical-qubit system arrives in 2027 as de Masi stated, and at what error rates.
- A published figure for spreading the computation across multiple machines, which would move the 14-keys-a-year ceiling.