Research / Q-Day

Resource estimates and Q-Day

Q-Day is the informal name for the first moment a cryptographically relevant quantum computer can break production ECC. The date is a range. The direction of the resource estimates is not.

Google, 2026

In March 2026, Google Quantum AI published Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities, with a companion responsible-disclosure blog post and a paper on ePrint 2026/625. Under standard superconducting assumptions they give two Shor circuits for ECDLP-256:

  • ≤ 1,200 logical qubits and ≤ 90 million Toffoli gates
  • ≤ 1,450 logical qubits and ≤ 70 million Toffoli gates

Compiled to a planar surface-code machine at 10⁻³ physical error rate, they estimate those circuits run in minutes with fewer than 500,000 physical qubits — roughly an order of magnitude below earlier public single-instance estimates. They also distinguish fast-clock machines (superconducting, photonic) that could attack in-flight mempool transactions from slower architectures.

Project Eleven

Project Eleven has treated Q-Day as an engineering problem, not a thought experiment. In April 2026 their Q-Day Prize produced a 15-bit elliptic-curve break on publicly accessible ~70-qubit hardware — still nowhere near 256-bit keys, but a live demonstration of the attack class. In July 2026 they published an unaudited prototype for proving Bitcoin ownership after Q-Day using a post-quantum ZK proof over BIP-32 derivation, in case a migration window closes with coins still sitting on ECC addresses.

How to read the timeline

Public Q-Day ranges still cluster in the early 2030s, with tails in both directions. Hardware may slip. Algorithms have been getting cheaper. LPs do not need a precise year to notice that a 10-year fund with a 2024–2026 vintage is long a cryptographic assumption whose published cost is falling.

vc.fail does not assign a Q-Day date to any fund. It only asks whether the public book has started to leave ECC.