In 2019, Google's Sycamore processor used
One holy grail of quantum computation is a direct attack on public-key cryptography: factoring for RSA, and elliptic-curve discrete logarithms for ECC. That task requires a different level of machine. Running Shor-style algorithms against real cryptosystems needs long, structured, fault-tolerant computation. In practice, that means logical qubits with very low failure rates, often discussed at the level of
This is why Google's sequence of error-correction results matters. In 2023, a larger distance-
In parallel with rapid experimental progress, theory and architecture work have compressed the apparent hardware demand for realistic cryptosystems. In 2026, Google Quantum AI, the Ethereum Foundation, Stanford, and collaborators estimated the resources needed to attack
These developments raise the question this article tries to answer:
How far is realistic quantum computation from the resources needed for a cryptocurrency attack?
The rest of the article treats that question as a gap analysis: demonstrated hardware on one side,
1. What is exposed in the crypto stack?
Crypto is no longer only a payment experiment. It is a large attempt to coordinate ownership, governance, settlement, and financial infrastructure without relying on a single central operator. That ambition rests on cryptography at several layers. User accounts need signatures. Validators need signatures. Bridges and custodians need threshold keys. DAOs need multisig policies. Rollups and privacy systems need proof systems. Tokenized real-world assets add another layer of administrative keys, oracle keys, and legal wrappers around the same cryptographic substrate.
The main quantum-sensitive surface is elliptic-curve public-key cryptography. Bitcoin has long used ECDSA over
Shor's algorithm targets the elliptic-curve discrete logarithm problem behind these schemes. Once a public key is visible, a sufficiently large fault-tolerant quantum computer can, in principle, derive the corresponding private key. That is the attack path. Hash functions sit in a different category. SHA-256, Keccak, Poseidon, and related primitives mainly face Grover-style quadratic speedups, which change security margins without creating the same immediate signature-forgery route.
Table 1 summarizes where quantum-sensitive cryptography appears across the crypto stack.
Table 1. Quantum exposure across crypto components
2. Shor attacks are now a resource-estimation problem
Shor's algorithm is the canonical quantum algorithm for public-key cryptanalysis because it gives a polynomial-time route to problems that support modern public-key cryptography. In the cryptocurrency setting, the relevant version attacks the elliptic-curve discrete logarithm problem. For a signature system such as ECDSA or Schnorr over
The operational detail is public-key visibility. A quantum attack begins to matter when the target public key is available and the machine can finish the computation before the attacker loses the opportunity to use the recovered private key.
There are two useful attack windows:
This distinction matters because resource estimates depend on architecture. A slow-clock machine may still threaten at-rest keys. An on-spend attack needs fast logical operations, enough parallelism, and a system that can complete the full private-key recovery inside the live transaction window.
As algorithms, compilation methods, error-correcting codes, and architecture assumptions improve, the estimated resources for realistic cryptographic attacks have moved downward. In 2026, two estimates became especially useful for this article: the Google team's
Babbush et al. from the Google-led team made the
Cain et al. from Oratomic give a different marker for the neutral-atom path. Their architecture uses high-rate codes, reconfigurable atomic arrays, and optimized logical instructions. They estimate that cryptographically relevant Shor computations could run with as few as
Table 2. Two resource estimates to watch
Neither estimate is a prediction that an attack is imminent. They are scale markers. They turn the question from "can Shor break ECC in theory?" into a comparison among logical qubits, logical error rates, non-Clifford gates, runtime, and migration speed.
3. Measuring the gap
To make the gap less abstract, we read it in two ways. First, we compare the public experimental record with cryptographic resource estimates: physical qubits, logical qubits, error rates, and timelines. Then we look at the neutral-atom roadmap, because it gives one of the clearest public paths from QEC testbeds toward fault-tolerant logical machines.
3.1 Hardware progress versus cryptographic requirements
Raw qubit count is a weak proxy for cryptographic risk. A useful attack machine needs encoded logical qubits, low logical memory error, reliable logical gates, enough non-Clifford resources, fast decoding, and enough parallelism to meet the relevant attack window.
Figure 1 is our working map of that gap. Panel A tracks the physical scale of superconducting, trapped-ion, and neutral-atom systems. Panel B compares demonstrated logical-qubit counts with the

Figure 1. Quantum hardware milestones and cryptographic resource estimates. The four panels compare physical scale, demonstrated logical scale, reported error-rate milestones, and cryptographic resource estimates.
The figure makes the main point visually: the gap has become quantitative. It is smaller than it looked a decade ago, yet it is still multi-dimensional. A real attack machine needs the right logical scale, logical error rate, non-Clifford throughput, and runtime together.
3.2 The neutral-atom roadmap
Recently, QuEra, a major neutral-atom quantum computing company, released an updated roadmap that translates neutral-atom progress into explicit fault-tolerant targets. It moves from Aquila and Gemini into planned Libra and Next Gen systems, with MegaQuOp and GigaQuOp labels tied to logical operation budgets [16,17].

Figure 2. QuEra's neutral-atom roadmap. The roadmap moves from Aquila and Gemini into planned fault-tolerant systems: Libra as a MegaQuOp-class machine in 2028 and a next-generation GigaQuOp-class system in 2028/29. These are roadmap targets rather than achieved benchmarks.
The numbers matter. Gemini is described as a QEC testbed with
Libra would still sit below the
The reason neutral atoms deserve attention is architectural. Reconfigurable atom arrays can move qubits and create nonlocal interactions, which makes high-rate QEC and qLDPC-style constructions more plausible than in a fixed nearest-neighbor layout. Cain et al. use that flexibility in their Shor architecture [15]. Zhao et al. push the idea further in theory and simulation, with ultra-high-rate codes for reconfigurable atom arrays [18].
4. Three milestones that would make the risk concrete
The following milestones are our reading of what would change the risk model. Based on current hardware development and the resource estimates above, we anticipate that these experimental steps will matter more than another raw-qubit-count announcement. Each one connects a theoretical requirement for fault tolerance to an experimental capability that a cryptographic attack would need.
4.1 A memory logical qubit below
A Shor-scale computation has to keep quantum information alive through a long circuit. If a logical qubit fails too often while acting as memory, the computation fails before the expensive arithmetic finishes.
Threshold theorems explain why quantum error correction can scale. Under suitable noise assumptions, increasing the code size can suppress logical error rates if the physical error rate is below a threshold [19]. The assumptions carry weight. Noise should be local or weakly correlated, leakage needs control, crosstalk needs control, measurement errors need decoding, and the classical decoder must keep up with the device.
This is why correlated errors matter. A code can look healthy under a simple independent-error model and then hit an error floor in hardware. Google's below-threshold experiment is a good example of both progress and caution. It reported a distance-
The repetition-code part of the same experiment is narrower but still important. A repetition code cannot correct the full set of quantum errors, so it is not a complete logical qubit. Even so, rare correlated events appeared at roughly once per hour or
The surface-code memory error rate is still above
This is also where the roadmap pressure becomes concrete. QuEra's Libra target is a logical error rate near
4.2 High-rate neutral-atom QEC that goes below threshold
So far, the clearest below-threshold experimental evidence comes from surface-code-style scaling: increase the code distance, then observe the logical error rate go down. That is the experimental signature that matters. It is different from simply reporting more logical qubits. Several points in Fig. 1 panel B show encoded or logical-qubit demonstrations, while below-threshold scaling with increasing code distance has only appeared in a smaller subset of experiments.
This distinction is exactly why high-rate QEC is a separate milestone. Surface-code overhead is large. A low encoding rate means many physical qubits per logical qubit, which pushes a thousand-logical-qubit machine toward enormous physical scale. High-rate codes promise better space efficiency, and the experiment has to prove that this efficiency can coexist with scalable error suppression.
Neutral atoms are interesting here because reconfiguration changes the geometry problem. Atom movement and long-range operations can support codes that are awkward on static nearest-neighbor chips. This is why the Oratomic and QuEra papers are worth tracking together: one estimates an attack-scale architecture, the other explores ultra-high-rate QEC codes for the same hardware family [15,18].
Table 3. High-rate QEC signals for neutral atoms
The milestone is an experiment: high encoding rate plus below-threshold behavior on a neutral-atom processor. The field needs to see logical error decrease as code size increases while the encoding rate stays high. That would show that better encoding efficiency and scalable error suppression can coexist. If that happens, the physical-qubit overhead in attack estimates changes quickly.
4.3 A non-Clifford resource below
Reliable memory is only one piece of universal quantum computation. Clifford operations and stabilizer circuits have a special structure: the Gottesman-Knill theorem says they can be simulated efficiently on classical computers [20]. A machine that only does Clifford-style fault tolerance is scientifically useful for QEC experiments, but it cannot run general Shor arithmetic.
Universal fault-tolerant quantum computation needs a non-Clifford resource. The common route is Clifford+
Recent work on magic state cultivation makes this bottleneck more concrete. Gidney, Shutty, and Jones proposed growing a single
This is why cryptographic resource estimates count Toffoli gates, T gates, or magic-state throughput. Babbush et al.'s
The milestone is a logical
Table 4. Milestones for a cryptographically relevant machine
5. Q-Day as a dashboard
A better question than "which year does crypto collapse?" is whether the migration clock is slower than the hardware and resource-estimate clock.
Today's evidence says practical attacks are still out of reach. The strongest public results show quantum advantage on benchmark tasks, early below-threshold QEC behavior, and roadmaps toward fault-tolerant neutral-atom machines. The resource estimates for ECC attacks are also specific enough to monitor. That combination deserves attention without panic.
The first memory logical qubit below
For crypto systems, the rational response is boring and necessary: inventory exposed public keys, reduce key reuse, design post-quantum migration paths, and test account-abstraction or signature-upgrade mechanisms before pressure arrives. NIST has already finalized the first post-quantum cryptography standards, which gives the broader security community a migration anchor even though blockchains have their own consensus, wallet, and state-transition constraints [24].
A useful quantum computer can change crypto's risk model before anyone agrees that Q-Day has arrived. It only has to make private-key recovery economically plausible for exposed keys before the ecosystem has finished migrating.
References
[1] F. Arute et al., "Quantum supremacy using a programmable superconducting processor," Nature 574, 505-510 (2019). https://www.nature.com/articles/s41586-019-1666-5
[2] Google Quantum AI, "Suppressing quantum errors by scaling a surface code logical qubit," Nature 614, 676-681 (2023). https://arxiv.org/abs/2207.06431
[3] R. Acharya et al., "Quantum error correction below the surface code threshold" (arXiv, 2024). https://arxiv.org/abs/2408.13687
[4] Google Quantum AI, "Meet Willow, our state-of-the-art quantum chip" (2024). https://blog.google/technology/research/google-willow-quantum-chip/
[5] A. Morvan et al., "Observation of constructive interference at the edge of quantum ergodicity," Nature (2025). https://www.nature.com/articles/s41586-025-09526-6
[6] R. Babbush et al., "Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities: Resource Estimates and Mitigations" (arXiv, 2026). https://arxiv.org/abs/2603.28846
[7] Bitcoin BIP-0340, "Schnorr signatures for secp256k1." https://github.com/bitcoin/bips/blob/master/bip-0340.mediawiki
[8] Bitcoin BIP-0341, "Taproot: SegWit version 1 spending rules." https://github.com/bitcoin/bips/blob/master/bip-0341.mediawiki
[9] Ethereum developer docs, "Accounts." https://ethereum.org/en/developers/docs/accounts/
[10] G. Wood, "Ethereum: A Secure Decentralised Generalised Transaction Ledger," Ethereum Yellow Paper. https://ethereum.github.io/yellowpaper/paper.pdf
[11] Ethereum consensus specs, "Phase 0: Beacon Chain." https://github.com/ethereum/consensus-specs/blob/dev/specs/phase0/beacon-chain.md
[12] Ethereum EIP-4844, "Shard Blob Transactions." https://eips.ethereum.org/EIPS/eip-4844
[13] Zcash Protocol Specification. https://zips.z.cash/protocol/protocol.pdf
[14] E. Ben-Sasson, I. Bentov, Y. Horesh, and M. Riabzev, "Scalable, transparent, and post-quantum secure computational integrity" (IACR ePrint 2018/046, 2018). https://eprint.iacr.org/2018/046
[15] M. Cain et al., "Shor's algorithm is possible with as few as 10,000 reconfigurable atomic qubits" (arXiv, 2026). https://arxiv.org/abs/2603.28627
[16] QuEra, "Our quantum roadmap" (accessed 2026-06-30). https://www.quera.com/our-quantum-roadmap
[17] Quantum Computing Report, "QuEra Updates Neutral-Atom Quantum Roadmap with 2028 Fault-Tolerant Launch on Amazon Braket" (2026). https://quantumcomputingreport.com/quera-updates-neutral-atom-quantum-roadmap-with-2028-fault-tolerant-launch-on-amazon-braket/
[18] C. Zhao et al., "Towards Ultra-High-Rate Quantum Error Correction with Reconfigurable Atom Arrays" (arXiv, 2026). https://arxiv.org/abs/2604.16209
[19] D. Aharonov and M. Ben-Or, "Fault-Tolerant Quantum Computation With Constant Error Rate" (arXiv, 1999). https://arxiv.org/abs/quant-ph/9906129
[20] S. Aaronson and D. Gottesman, "Improved Simulation of Stabilizer Circuits," Physical Review A 70, 052328 (2004). https://arxiv.org/abs/quant-ph/0406196
[21] S. Bravyi and A. Kitaev, "Universal Quantum Computation with ideal Clifford gates and noisy ancillas," Physical Review A 71, 022316 (2005). https://arxiv.org/abs/quant-ph/0403025
[22] C. Gidney, N. Shutty, and C. Jones, "Magic state cultivation: growing T states as cheap as CNOT gates" (arXiv, 2024). https://arxiv.org/abs/2409.17595
[23] E. Rosenfeld, C. Gidney, G. Roberts, et al., "Magic state cultivation on a superconducting quantum processor" (arXiv, 2025). https://arxiv.org/abs/2512.13908
[24] NIST, "NIST Releases First 3 Finalized Post-Quantum Encryption Standards" (2024). https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards