No quantum computer can break the encryption that protects your bank, your messages, or your crypto wallet today. What has changed is the estimate of how big a quantum computer would need to be. Google researcher Craig Gidney’s 2025 paper cut the requirement for breaking RSA-2048 from 20 million noisy qubits to under one million, and a Google white paper in March 2026 reported that elliptic curve encryption, which Bitcoin uses, could fall to fewer than 500,000. In response, NIST, the US National Security Agency, the European Union, and Google have set migration deadlines that run from 2029 to 2035.
This article explains what quantum computers can and cannot break, how far hardware is from those estimates, which deadlines apply, and what it means for crypto holders. It is not financial, legal, or security advice.
Can Quantum Computers Break Encryption Today?
No. The Quantum Insider’s April 2026 overview notes that breaking RSA-2048 would take roughly one million physical qubits running fault-tolerant error correction. A September 2026 preprint from Georgia Tech researchers states that current fault-tolerant systems achieve only dozens of logical qubits. A logical qubit is an error-corrected qubit built from many fragile physical ones, and the attacks described below need hundreds or thousands of them.
The threat is real but sits in the future. The reason to act now is that migrating encryption takes years, and some data has to stay secret for decades.
What Quantum Computers Can and Cannot Break
Public Key Encryption
RSA, elliptic curve cryptography, and Diffie-Hellman key exchange are the vulnerable group. They rely on math problems that Shor’s algorithm solves exponentially faster than any known classical method, according to The Quantum Insider. These systems protect online banking, e-commerce, VPNs, software updates, and blockchain signatures. When people talk about “Q-Day,” they mean the day a quantum computer can run Shor’s algorithm at that scale.
Symmetric Encryption
AES and similar ciphers are far less affected. Grover’s algorithm gives only a quadratic speedup against them. The Quantum Insider explains that AES-128 would offer roughly the security of a 64-bit key against a quantum attacker, while AES-256 keeps roughly 128-bit security, which it calls strong by current standards. Doubling the key length is enough, so symmetric encryption does not need to be replaced.
Why the Estimates Keep Falling
RSA-2048
Gidney’s paper, posted on May 21, 2025, estimates that RSA-2048 could be factored with fewer than one million noisy qubits in under a week. The paper compares this with a 2019 estimate of 20 million qubits and eight hours. The calculation assumes a 0.1 percent gate error rate, a one-microsecond surface code cycle, and a square grid of qubits with nearest-neighbor connections. The savings come from approximate residue arithmetic, a way of storing idle qubits called yoked surface codes, and magic state cultivation.
Those assumptions describe hardware that does not exist yet. The paper lowers the bar but does not claim anyone can clear it.
Elliptic Curve Cryptography
On March 30, 2026, Google Quantum AI released a white paper on attacking 256-bit elliptic curve cryptography. As reported by The Quantum Insider, it estimates fewer than 1,200 logical qubits and fewer than 500,000 physical qubits, with the attack finishing in minutes on a sufficiently advanced machine. The researchers said quantum attacks are not yet feasible and described the improvement as roughly an order of magnitude. Instead of publishing the attack details, they used zero-knowledge proofs so others could verify the claim without receiving the technique.
A preprint posted on September 15, 2026 to the IACR Cryptology ePrint Archive, by Sunghyeon Jo and Gye Jin Lee of Georgia Tech and QED Audit, cut the logical qubit requirement further. Tech Times reported that it reduces the coefficient from 3n to 5n/2, which comes to roughly 640 logical qubits for P-256 plus lower-order terms, and that it lowers the gate count from cubic to near-quadratic. It has not been peer-reviewed.
Claims to Treat With Caution
Not every low estimate is credible. QDayIsComing.com, a site that itself argues for an early Q-Day, reports that papers from a group called the Advanced Quantum Technologies Institute in October 2025 and March 2026 claimed RSA and elliptic curve encryption could fall to fewer than 5,000 qubits, and that independent researchers contested the method. Gidney’s paper is the one the cryptography community has broadly accepted. A headline with a very small qubit count deserves a check on who wrote it and whether anyone outside the group has verified it.
How Far Is Hardware From Those Numbers?
IBM’s published roadmap gives a sense of scale. IBM plans a machine called Starling at its Poughkeepsie, New York facility. It is meant to run circuits of 100 million gates on 200 logical qubits, with demonstrations in 2028 and 2029 and full capability in 2029. An interim processor called Kookaburra is planned for 2026.
Two cautions apply. The roadmap is IBM’s plan, not a delivered product. And 200 logical qubits is well below the roughly 1,200 that Google’s elliptic curve paper estimates, though the two use different architectures and are not directly comparable. The gap between today’s dozens of logical qubits and the thousands needed is the main reason serious researchers say Q-Day has not arrived.
Timeline predictions vary widely. The Quantum Insider’s April 2026 summary lists quantum company estimates of 10 to 15 years, academic estimates of 15 to 25 years, and government planning assumptions around 2040 to 2045. Ethereum Foundation researcher Justin Drake has estimated at least a 10 percent chance of private key recovery by 2032, as quoted by The Quantum Insider in July 2026. The range of expert opinion is wide.
The Deadlines Already Set
NIST
NIST approved its first three post-quantum standards on August 13, 2024. FIPS 203 covers ML-KEM for key exchange, FIPS 204 covers ML-DSA for digital signatures, and FIPS 205 covers SLH-DSA, a hash-based signature scheme. In March 2025 it selected HQC as an additional key exchange algorithm, and Falcon is in development as another signature scheme. NIST IR 8547 states that NIST will deprecate and ultimately remove quantum-vulnerable algorithms from its standards by 2035. The Quantum Insider’s May 2026 summary adds that RSA-2048 and P-256 are slated for deprecation by 2030.
NSA and the European Union
The NSA’s CNSA 2.0 suite sets a staged schedule for national security systems, according to The Quantum Insider. New systems must support quantum-resistant cryptography by 2027, with software and firmware signing moving exclusively to CNSA 2.0 from January 1, 2027, and full quantum resistance required across national security systems by 2035. It specifies ML-KEM-1024 and ML-DSA-87. The EU roadmap asks member states to publish national strategies and begin inventories by the end of 2026, move critical infrastructure by the end of 2030, and finish medium-risk uses by the end of 2035.
Google announced in March 2026 that it would complete its own post-quantum migration by 2029, earlier than NIST’s 2035 removal date, citing advances in quantum hardware, error correction, and updated estimates of how quickly a machine could break today’s standards. The Quantum Insider reported that Google is prioritizing digital signatures over encryption in transit, and that it plans to ship ML-DSA in Android 17. Google did not tie the date to a specific milestone.
Harvest Now, Decrypt Later
The urgency comes from a specific attack. Adversaries can collect encrypted traffic today and store it until a quantum computer can decrypt it. The Quantum Insider describes this as a risk for data with long-term sensitivity, such as government secrets, medical records, and intellectual property. A file that must stay confidential until 2045 is already exposed if it is captured in 2026 and decrypted in 2040.
What It Means for Bitcoin and Crypto
Blockchains depend on elliptic curve signatures, so the March 2026 Google paper drew attention across the industry. It describes two attack types. An on-spend attack targets a transaction while it is waiting to be confirmed. An at-rest attack targets wallets whose public keys are already visible on the chain. The paper notes that Bitcoin’s proof-of-work mining is not directly vulnerable to the same class of algorithm.
The Quantum Insider’s July 2026 report, citing the Google paper, puts about 6.9 million bitcoin, roughly one third of the supply, in addresses with already-exposed public keys. About 1.7 million of those sit in early pay-to-public-key addresses.
Bitcoin developers have two proposals under discussion. BIP-360, published in February 2026 by Hunter Beast, Ethan Heilman, and Isabel Foxen Duke, introduces an output type called Pay-to-Merkle-Root that keeps public keys off the chain until coins are spent. Cointelegraph notes it does not upgrade existing coins automatically and does not add post-quantum signatures. BIP-361, proposed in April 2026 by Jameson Lopp and five co-authors, lays out a three-phase plan to phase out vulnerable address types, and it drew strong criticism from people who called it confiscatory. Neither source reviewed for this article reported either proposal as activated. Security researcher Conor Deegan has flagged Ethereum’s KZG trusted setup, Zcash’s Sapling protocol, and Litecoin’s MimbleWimble as other designs with elliptic curve parameters built in.
This section describes technical risk, not a prediction of any asset’s price.
What You Can Do Now
Individuals have little to do beyond keeping devices, browsers, and wallet software updated, since the main migration happens in the software they use. Organizations have more work. NIST advises applying its standards now, and the EU timeline starts with inventories, which means listing where RSA and elliptic curve cryptography are used. For crypto holders, the exposed-key problem is tied to older address types whose public keys are already visible on the chain, so following Bitcoin’s BIP discussions and your wallet provider’s upgrade notes is the practical step.
Frequently Asked Questions
When will quantum computers break encryption?
Nobody knows. Google has set 2029 as its own migration deadline, while The Quantum Insider’s April 2026 summary lists government planning assumptions of roughly 2040 to 2045. No machine today has the hundreds or thousands of logical qubits that the attacks require.
Is Bitcoin safe from quantum computers?
Not permanently. Bitcoin’s mining is not directly vulnerable, but its signatures are. About 6.9 million BTC sit in addresses with exposed public keys, according to the Google paper as reported in July 2026. Developers have proposed BIP-360 and BIP-361, though neither is active.
Is AES-256 quantum-safe?
Largely yes. Grover’s algorithm weakens symmetric encryption only quadratically, leaving AES-256 with roughly 128-bit security against a quantum attacker, according to The Quantum Insider. RSA and elliptic curve cryptography are the algorithms that need replacing.
What is harvest now, decrypt later?
It is the practice of recording encrypted data today so a future quantum computer can decrypt it. It matters most for information that must stay secret for 10 to 20 years or more.
References and Sources
NIST, “Post-Quantum Cryptography”: https://csrc.nist.gov/projects/post-quantum-cryptography
Craig Gidney, arXiv, “How to factor 2048 bit RSA integers with less than a million noisy qubits”: https://arxiv.org/abs/2505.15917
IBM Quantum, “IBM lays out clear path to fault-tolerant quantum computing”: https://www.ibm.com/quantum/blog/large-scale-ftqc
The Quantum Insider, “How Quantum Computing Affects Cryptography”: https://thequantuminsider.com/2026/04/06/how-quantum-computing-affects-cryptography/
The Quantum Insider, “Google Shortens Timeline for Quantum-Safe Encryption Transition”: https://thequantuminsider.com/2026/03/25/google-shortens-timeline-for-quantum-safe-encryption-transition/
The Quantum Insider, “Google Suggests Quantum Attacks on Cryptocurrency Encryption May Require Fewer Resources”: https://thequantuminsider.com/2026/03/31/google-suggests-quantum-attacks-on-cryptocurrency-encryption-may-require-fewer-resources/
The Quantum Insider, “Quantum Security Deadlines are Here, What Happens Next?”: https://thequantuminsider.com/2026/05/08/post-quantum-migration-timelines-government-industry-impact/
The Quantum Insider, “The Growing Quantum Security Challenge Facing Bitcoin and Digital Assets”: https://thequantuminsider.com/2026/07/29/growing-quantum-security-challenge-bitcoin-digital-assets/
Tech Times, “Elliptic Curve Encryption’s Quantum Attack Cost Falls on Two Fronts in Georgia Tech Paper”: https://www.techtimes.com/articles/327545/20260915/elliptic-curve-encryptions-quantum-attack-cost-falls-two-fronts-georgia-tech-paper.htm
Cointelegraph, “Bitcoin’s Quantum Defense Plan: What BIP-360 Actually Changes”: https://cointelegraph.com/features/bitcoin-s-quantum-upgrade-path-what-bip-360-changes-and-what-it-does-not
QDayIsComing.com, “Three Papers in Three Months: Why Q-Day May Now Be 2029, Not 2035”: https://qdayiscoming.com/articles/three-papers-q-day-2029
