Google's March 2026 estimate for a fast attack on an exposed secp256k1 public key calls for fewer than 500,000 superconducting physical qubits, and assumes it will finish in minutes. Meanwhile, an Oratomic and Caltech preprint runs the same attack on neutral atoms and needs far fewer qubits, about 10,000 to 26,000, but takes days to years. Each number below comes with the assumptions that produced it.
Together, those two 2026 studies are a snapshot of where the field stands, and no more than that. We know that the span runs from about 10,000 to fewer than 500,000 physical qubits, at runtimes anywhere from minutes to years, on machines nobody has built, and neither end is a floor or a ceiling. Change the hardware assumptions, and the figures land well outside the range.
It also helps to be precise about the word "break." The attack recovers one private key from a public key the attacker can get hold of. It doesn't touch Bitcoin's proof-of-work or rewrite past blocks, but defeats the authorization on certain outputs, so a fraudulent spend enters the ledger as a valid transaction. Some outputs expose their public key the moment they're funded; others only when the coins are spent, which is what decides how much is exposed today.

The same attack, priced three ways. Fewer qubits, slower machine.
Logical qubits and physical qubits
Most qubit estimates come in two forms, and mixing them up causes most of the confusion here. Some papers report only the logical side, which is part of why the headline numbers vary so much.
Logical qubits are the error-corrected kind, the ones an algorithm needs to do real work. Google's March 2026 paper compiled two circuits for the 256-bit elliptic-curve discrete logarithm problem that Bitcoin's secp256k1 curve rests on. One uses fewer than 1,200 logical qubits and 90 million Toffoli gates. The other uses fewer than 1,450 logical qubits and 70 million gates, trading qubits for speed.
Physical qubits are the hardware you build. Today's qubits are noisy, so many of them go into protecting each logical one, and how many it takes depends on the code, the hardware error model, target reliability, connectivity, and runtime. Under the surface-code approach Google models, the ratio runs into the hundreds. This is how those circuits add up to fewer than 500,000 physical qubits on a superconducting machine, with the work finishing in minutes. Higher-rate codes bring that ratio down a long way, which is where the much smaller neutral-atom figures come from.
The two numbers describe different layers of one model, and neither is a mathematical floor. The 1,200 and 1,450 are the widths of Google's two circuit designs, and a July 2026 preprint brought the logical width down to 835 by accepting a much larger gate count. The sub-500,000 figure is Google's mapping of those circuits onto a particular fault-tolerant architecture.

One attack, two kinds of qubit.
What the estimate assumes
Resource estimates aren't measurements. They're what-ifs with specific inputs, and Google's assumes a physical error rate near one in a thousand, surface-code error correction, microsecond correction rounds, and a superconducting machine that amounts to a scaled-up version of what it has already built.
Change those inputs and the number moves. A better error rate shrinks the error-correction overhead, and every logical qubit gets cheaper to hold. A different hardware family changes the arithmetic altogether, which is why a qubit count from a neutral-atom machine and one from a superconducting machine can't be treated as equivalent.
Runtime is part of the price as well. The minutes-scale result assumes a machine that can run fault-tolerant operations and real-time error decoding for the entire computation, and manufacture the "magic states" those operations burn through fast enough to keep up. Time and qubits trade against each other, which is what Google's two circuit variants show. One spends more qubits to finish sooner, the other spends fewer and takes longer. Quote a qubit count without its runtime, and you've quoted half the number.
Why the numbers keep falling
These figures have dropped fast, and not because someone built a machine that could run the attack.
Google describes its result as close to a 20-fold reduction against Litinski's 2023 photonic estimate of about 9 million physical qubits. That compares two specific architectures. It doesn't show a single universal requirement falling from 9 million to 500,000, and other 2023 work landed far lower on different hardware. What improved (and fast) were the algorithms and the error-correction design. Plenty of new hardware arrived in those years, though none of it is what brought the estimate down.
The same pattern shows up next door. In May 2025, Google Quantum AI's Craig Gidney estimated that RSA-2048 could be factored with fewer than a million physical qubits in under a week. That's about 20 times fewer qubits than the 2019 Gidney and Ekerå figure, traded for a longer runtime, from eight hours to several days.
The trend is the true signal. An estimate that moves this far in three years isn't a fixed target.
The other numbers you'll see
Two other numbers circulate, and neither answers the Bitcoin question cleanly.
The first comes from Iceberg Quantum's early-2026 architecture, which factors RSA-2048 with fewer than 100,000 physical qubits using quantum low-density parity-check codes, at a runtime of about a month. RSA-2048 isn't secp256k1. It's a different problem on a different architecture, and the runtime isn't in the same range. Quoting it as Bitcoin's number is quoting the wrong paper.
The second number is about the right curve family, and it's smaller still. The Oratomic and Caltech preprint runs Google's two ECC-256 compilations on a neutral-atom design and puts the cost at about 10,000 to 26,000 physical qubits, depending on how much parallelism you pay for. The trade-off is time. Runtimes across their architectures vary by two orders of magnitude, with the fastest needing as few as 10 days, and that fast end assumes magic-state factories running in parallel at a scale nobody has built yet.
So, the sub-100,000 headlines aren't all wrong. It’s just that they're describing a different machine running a much slower attack.
How far today's hardware truly is
No current machine comes close to what any of these estimates assume, even where the raw qubit counts look comparable.
Caltech has demonstrated a 6,100-qubit neutral-atom array, and the largest superconducting processors sit around a thousand. Set 6,100 against the neutral-atom estimate of 10,000 to 26,000, and the hardware looks close. But looks can be deceiving.
That experiment showed a large coherent array with individual atom addressing and precise movement. Array-wide entanglement and error correction at that scale are milestones Caltech itself described as still ahead, and the array held no logical qubits at all.
The true distance is between noisy machines and fault-tolerant ones. The two aren't the same kind of machine, and no qubit count captures it.
What would have to change
Closing that distance takes more than adding qubits.
Error rates have to keep falling. Fault tolerance starts working once the physical rate drops below a threshold, and Google has already shown below-threshold surface-code memory on a small system. Holding that across a thousand logical qubits at once is a different order of problem.
Error correction has to scale too. Running these designs means keeping on the order of a thousand logical qubits alive, and producing magic states and decoding errors fast enough to keep up. Google's circuits need 70 to 90 million Toffoli gates, and the narrower 835-qubit construction pays for its smaller width with a gate count in the billions. No single physical qubit has to stay coherent for the whole run, since that's what error correction is for. The machine does have to correct faster than it fails for the entire computation.
Both fronts have moved quickly, yet neither is solved at the scale and reliability this attack needs.
Reading these numbers in context
A resource estimate answers a narrow question of what this attack would cost if you already had the machine. It says nothing about when the machine arrives.
Google separately warned that unscientific and unsubstantiated resource estimates can themselves function as an attack on confidence in a system. Treat these figures as a bar that keeps moving, since none of them is a countdown.
For the timing question, our What Is Q-Day piece covers where the forecasts land. For which coins are exposed and what to do about them, start with our guide Is Bitcoin Quantum Safe?. You can also see where Bitcoin sits among the chains we score on the qLVI.
FAQ
How many qubits does it take to break Bitcoin?
There's no single figure. Google's March 2026 estimate calls for fewer than 500,000 superconducting physical qubits, with the attack finishing in minutes. An Oratomic and Caltech neutral-atom preprint estimates about 10,000 to 26,000 physical qubits at far longer runtimes. Google's circuits use 1,200 to 1,450 logical qubits, and a July 2026 preprint brought the logical width down to 835.
Is that logical qubits or physical qubits?
Both, and they measure different things. Logical qubits are error-corrected, and they're what the algorithm needs: 1,200 to 1,450 in Google's circuits and 835 in a July 2026 preprint. Physical qubits are the raw hardware, and the count depends on the code, the hardware error model, target reliability, connectivity, and runtime. A full-machine figure is more than a simple physical-per-logical ratio.
Does 100,000 qubits break Bitcoin?
Not as it's usually quoted. One widely circulated sub-100,000 figure comes from Iceberg Quantum's 2026 architecture for factoring RSA-2048, which models about 94,000 physical qubits for a one-month run, a different problem on different hardware. Separately, a neutral-atom preprint does estimate about 10,000 to 26,000 physical qubits for ECC-256, at much longer runtimes than Google's.
How many qubits do quantum computers have today?
Raw counts vary by platform. Caltech has demonstrated a coherent array of 6,100 neutral-atom qubits, and IBM's Condor holds 1,121 superconducting ones. Neither is a cryptographically capable machine. The Caltech array hasn't implemented entanglement or error correction at that scale, and current systems fall short of both the logical width and the error rates it would take.
Will the number keep dropping?
Probably, though not at the same pace. Published estimates have fallen repeatedly as algorithms and error correction improve, and they can also rise when researchers adopt stricter hardware assumptions. None of them predicts when a capable machine will exist.
qLABS Editorial. Sources are linked inline. See the L1 Quantum Vulnerability Index for our full methodology and conflict-of-interest disclosure.


%20copy-600x290.jpg)