In truth, this vagueness is the real answer, and it's more useful than a falsely precise one. If you came here for a countdown, you won’t find it. The takeaway is that the range is wide, the low end is close enough to plan around, and the exact year is less important than it seems. This piece is about the timing question specifically. For what Q-Day is and why it's a concern, start with What is Q-Day? article.
The short answer, with numbers
One of the most systematic current readings comes from the Global Risk Institute, which surveys quantum computing experts from academia and industry each year. Its 2025 report asked 26 experts to put odds on a quantum computer capable of breaking RSA-2048 within a day, at points from five years out to thirty. This benchmark is the report's working measure and a common proxy for a cryptographically relevant machine. It’s not a direct forecast for Bitcoin's curve, which may need somewhat different resources.
Because respondents picked wide probability bands, the report averages the low and high ends of their answers into two figures: a 28% to 49% chance within 10 years, and 51% to 70% within 15. Those are lower- and upper-bound aggregates, not a single expert panel estimate or a confidence interval. It was the survey's most aggressive 10-year result yet, though the report cautions that a shifting panel and wide response ranges make year-to-year comparison difficult.

The forecast is a rising probability band, not a single year.
These numbers should be read carefully. About a 1-in-4 to 1-in-2 chance inside a decade is not a prediction that Q-Day arrives in 2035. It reflects genuine disagreement among experts, and that disagreement is the finding itself. The survey's averaged 5-year probability is only 5% to 15%, so almost no one on the panel expects a capable machine that soon. Opinion splits hardest over the 10- and 15-year horizons. What the experts share is a sense that the risk is tangible and growing, even if they can't pin the year it materializes.
Why the forecasts disagree
A Q-Day estimate is a forecast about hardware that doesn't exist yet, so it depends on guessing two things at once: how fast the machines improve and how much easier the attack itself gets. Both are moving, and experts weigh them differently.
On the hardware side, the question is when a computer can run a fault-tolerant computation large enough to complete the attack, across the many reliable logical qubits it demands. The leading programmable gate machines today run in the hundreds to low thousands of physical qubits, with error rates far too high, so getting from there to a fault-tolerant machine is a different kind of problem, not a bigger version of the same one. No one can say confidently how many years that jump will take.
On the algorithm side, the resource requirements keep falling. The number of qubits researchers think the attack needs has dropped sharply in the past few years. A cheaper attack pulls the date earlier, but only if the hardware shows up to run it. Those two curves moving at different speeds are largely why the estimates scatter.

Why the estimates scatter: cheaper attacks pull the date in, slow hardware pushes it out.
The deadline that isn't a prediction
The most common mistake is reading an official migration deadline as a Q-Day forecast. They’re not the same thing.
Governments have set staged migration deadlines, mostly running from 2030 to 2035, with the highest-priority systems moved first and the rest finished last. The exact dates vary by jurisdiction, and they mix binding directives with indicative goals, but the shape is consistent: priority systems by the early 2030s, extensive completion by around 2035. These are risk-management targets for getting the work done. When a code-breaking machine appears is a separate, still very open question.
Treating 2035 as the answer to ‘when is Q-Day’ mistakes a deadline for a forecast. The deadline is set early on purpose, so the necessary work on the solution finishes with time to spare, not to name when the threat arrives.
What could move the date
Two kinds of news would shift the estimate: one earlier, one later.
Pulling it earlier takes a jump in qubit quality, a demonstration of error correction at scale, or another cut in the resource estimate for the attack. Google's 2026 paper estimated that a fast elliptic-curve attack could run on fewer than 500,000 physical qubits in a superconducting design, a nearly 20x reduction from a 2023 estimate of about 9 million in a photonic architecture.
The hardware assumptions differ, so it isn't a like-for-like comparison, though it shows how sharply attack estimates can fall. Cuts like that can raise the probability experts put on earlier timelines, but they don't by themselves say when the hardware will exist.
What pushes it later is the engineering proving harder than hoped. Scaling from today's devices to hundreds of thousands or millions of high-quality physical qubits under full fault-tolerant control, or to tens of thousands under more aggressive and unproven designs, is an unsolved problem, and unsolved problems have a way of taking longer than the optimists expect. A smaller qubit count on paper is not the same as a working machine, and no resource estimate names a delivery date.
The signals worth watching are concrete: growth in reliable logical qubits and logical circuit depth, new end-to-end resource estimates, and whether fault-tolerant systems scale beyond today's small demonstrations. Those move the forecast. Press headlines mostly don’t.
Why the exact year is the wrong question
If you’re holding crypto, the precise date is less useful to you than it seems.
Firstly, migration takes years. Swapping the signature scheme a chain depends on is a slow, coordinated upgrade, and it has to be completed before a capable machine exists. If a migration eats most of the available lead time, a threat that looks comfortably distant can leave little margin.
Secondly, exposure is already accumulating, in a related but different sense. A public key that stays visible on-chain can be catalogued now and attacked later, once a machine exists to derive its private key. That's a similar ‘collect now, exploit later’ timing problem, but it isn't ‘harvest now, decrypt later’: no ciphertext is being harvested, and the later step is private-key recovery and signature forgery, not decryption per se.
How much protection a holder has before spending depends on the chain and address type. The planning point holds either way: the important horizon is the earlier end of the range, because early planning is generally less costly than a rushed migration, and missing the window could mean complete loss for exposed funds.
So the question to ask isn’t ‘when is Q-Day?’ It's whether the chains you rely on will have migrated before the earliest plausible machine. You can easily see where they stand today in the L1 Quantum Vulnerability Index.
So, when?
The short version of this answer is a range, and the odds aren’t spread evenly across it. In the Global Risk Institute's aggregation, the odds of a capable machine cross 50% at the 15-year mark and sit at 28% to 49% within 10, against an RSA-2048 benchmark. The survey also leaves a material tail past the mid-2040s if fault-tolerant hardware scales slowly. No authoritative source assigns Q-Day a reliable year, and any single-year answer is better treated as a planning scenario than a firm date.
Plan for the early end, watch the hardware and resource-estimate signals instead of the headlines, and treat any government deadline as a backstop for your own preparation, as opposed to a prediction of the threat. The date is unknowable, but the direction isn’t.
FAQ
When is Q-Day?
There's no fixed date. In the Global Risk Institute's 2025 survey, aggregated expert opinion put a quantum computer capable of breaking RSA-2048 at a 28% to 49% chance within 10 years and 51% to 70% within 15, figures that stand in as a proxy for the wider threat, not a Bitcoin-specific forecast. The survey shows meaningful risk across the 2030s and 2040s, with a smaller 5-year tail and residual risk beyond 2045.
Could Q-Day come sooner than expected?
Yes. Better circuits, lower error-correction overhead, or a hardware breakthrough could move the threshold forward. Google's 2026 estimate put a fast elliptic-curve attack at fewer than 500,000 physical qubits in a superconducting design, a nearly 20x reduction from a 2023 photonic estimate of about 9 million. The hardware assumptions differ, so it isn't a like-for-like comparison, but it shows how sharply attack estimates can fall. It's also why resource estimates have to be revisited often, and why it's worth planning for the early end of the range.
Is Q-Day 2035?
No. 2035 is when several government migration deadlines land, the date by which agencies aim to complete the transition to post-quantum cryptography, with priority systems targeted earlier in the 2030s. It's a risk-management target, not a prediction of when a code-breaking computer arrives. Those deadlines are set ahead of the expected threat on purpose, so the work is done before it lands.
Has Q-Day been delayed?
Not in any measurable sense, because it was never scheduled. Forecasts shift year to year as hardware and algorithms progress. The 2025 expert survey put more weight on the ten-year horizon than earlier editions, but a changing respondent pool and broad answer bands mean that's a soft signal, not a precise acceleration.
What should I do before Q-Day?
Focus on the migration, not the date. Check whether the chains you hold are moving to post-quantum signatures. Pay attention to where a chain and address type keep the public key hidden until you spend, and avoid address reuse to reduce long-term exposure (a temporary risk-reduction step, not genuine post-quantum security). Treat the earliest plausible date as your planning horizon, since waiting for the forecasts to sharpen could leave too little of a migration margin.
qLABS Editorial. Sources are linked inline. See the L1 Quantum Vulnerability Index for our full methodology and conflict-of-interest disclosure.

