Google Research published new resource estimates for how much quantum computing power it would take to break the elliptic-curve cryptography that secures Bitcoin and other cryptocurrencies. A whitepaper released alongside the post, co-authored with researchers from the Ethereum Foundation and Stanford University, describes two circuit designs for solving the underlying math problem: one uses fewer than 1,200 logical qubits and fewer than 90 million Toffoli gates, the other fewer than 1,450 logical qubits and fewer than 70 million Toffoli gates.
Translated into physical, error-corrected hardware, Google says either circuit could run in a few minutes using fewer than 500,000 physical qubits — roughly 20 times fewer than the qubit count the same team estimated in 2019. That is a resource estimate, not a forecast. The paper calculates what a quantum computer would need to carry out the attack; it does not calculate when a computer of that size will exist, and no hardware built today comes close to that scale.
A separate 2029 deadline
Google has also set a 2029 target for moving its own systems to post-quantum cryptography, a timeline the company published separately and pointed back to in the cryptocurrency post. That date describes when Google wants its own infrastructure switched over, in step with NIST guidance calling for vulnerable systems to be phased out after 2030. It says nothing about when a quantum computer capable of breaking Bitcoin might actually be built, and the two figures answer different questions.
An estimate published without the attack
Rather than release the circuits themselves, Google’s team published a zero-knowledge proof that lets outside researchers verify the resource estimate without obtaining a blueprint for carrying out the attack. The paper argues that the lower resource estimate is reason for cryptocurrencies built on elliptic-curve keys to accelerate, not delay, a move to quantum-resistant algorithms.
An earlier version of this article said Google’s study calculated a timeline for when quantum computers will be powerful enough to break Bitcoin’s encryption. Google’s paper is a resource estimate, not a timeline, and does not predict when such hardware will exist; the article also conflated that estimate with Google’s separate 2029 timeline for migrating its own systems to post-quantum cryptography. The article has been rewritten from Google’s research post and whitepaper directly, and now sources them rather than the outlet that originally relayed the story to us.
