Quantum computers remain orders of magnitude away from breaking ECC; cryptocurrencies face no immediate risk but will eventually need quantum-resistant encryption.
Regulation & Gov ·
Recent theoretical advances in quantum computing have substantially reduced the hardware requirements needed to break Elliptic Curve Cryptography, but practical implementation remains far beyond current capabilities. A 2026 paper outlined new circuit designs that would theoretically allow breaking ECC—which secures Bitcoin, Ethereum, TLS, and HTTPS—on a superconducting quantum computer with roughly 1,200 logical qubits executing approximately 90 million Toffoli gates. However, existing quantum computers have achieved only around 10^5 usable qubits versus the approximately 500,000 physical qubits required, representing a gap of roughly 10x in the last decade despite theoretical requirements dropping around 600x in four years.
The core challenge lies in error correction. Physical qubits must be bundled into logical qubits through error-correction codes, with current distance-5 codes requiring roughly 49 physical qubits to reliably store one logical qubit. Two-qubit fidelity has improved substantially—from roughly 90% in 2005 to above 99.9% today—yet this progress cannot be extrapolated to predict when sufficient error-corrected qubits will exist in a single machine.
Timelines remain deeply uncertain. Estimates range from 10% probability by 2030 to 50% by 2032, while NIST and NSA target 2035 for deprecating vulnerable cryptography. Cryptocurrencies and internet protocols face no immediate risk, though systems with exposed public addresses will eventually require migration to quantum-resistant encryption schemes as the hardware gap gradually narrows.