Key Takeaways: The theoretical qubit threshold to break ECDSA signatures has fallen from 2,330 to 813 in nine years, and Circle says the industry is running out of time.
Key Takeaways: The theoretical qubit threshold to break ECDSA signatures has fallen from 2,330 to 813 in nine years, and Circle says the industry is running out of time.

Circle publicly warned that quantum computing progress is narrowing the gap to breaking blockchain security, as the theoretical threshold to crack ECDSA signatures dropped from 2,330 logical qubits in 2017 to 813 in August 2026.
"We are now firmly in the quantum advantage era," said Jay Gambetta, Director of IBM Research and IBM Fellow, after IBM and University of Chicago researchers demonstrated a computation using 70 logical qubits that leading classical methods could not practically reproduce.
Google's Willow processor has reached 105 logical qubits, while QuEra projects surpassing 1,000 logical qubits by 2029 — a level that would exceed the 813-qubit threshold needed to break ECDSA signatures. Google's March 2026 whitepaper estimated that cracking ECDLP-256, the elliptic curve math securing most blockchain wallets, could require fewer than 500,000 physical qubits, a roughly 20-fold reduction from the tens of millions previously estimated.
The narrowing gap pressures Bitcoin, Ethereum, and stablecoin issuers like Circle to accelerate post-quantum cryptographic upgrades. NIST has finalized FIPS 203 and FIPS 204 standards, and Google has set a 2029 internal deadline for its own migration, but Bitcoin's governance process has historically taken years to approve fundamental protocol changes.
The ECDSA break threshold has fallen from 2,330 logical qubits in 2017 to 813 in August 2026, according to updated resource estimates. Google's Willow processor, announced in December 2024, demonstrated below-threshold quantum error correction with 105 physical qubits. IBM and University of Chicago researchers pushed further in July 2026, operating 70 logical qubits with effective error rates 10 times lower than the underlying physical error rates.
QuEra's projection of surpassing 1,000 logical qubits by 2029 would place quantum hardware above the 813-qubit threshold needed to break ECDSA signatures. Google's March 2026 whitepaper further compressed the timeline, estimating that fewer than 500,000 physical qubits could break ECDLP-256 — a roughly 20-fold reduction from the tens of millions previously thought necessary. Microsoft has also accelerated its roadmap, targeting a scalable quantum machine by 2029.
Bitcoin runs two distinct cryptographic systems. SHA-256 covers mining and proof-of-work, which faces no meaningful quantum threat on any near-term horizon. The exposure sits with ECDSA and Schnorr signatures, which authorize wallet transactions, because those are built on elliptic curve math that Shor's algorithm can attack.
Elliptic curve keys are considerably smaller than RSA keys at equivalent security levels, meaning a lower qubit count is needed to attack them. Every transaction exposes a public key on-chain, and a quantum computer running Shor's algorithm could theoretically work backward from that public key to the private key. The "harvest now, decrypt later" strategy — collecting public keys today to crack them once hardware arrives — has moved from theoretical concern to active planning.
NIST has finalized post-quantum standards including FIPS 203 (ML-KEM) and FIPS 204 (ML-DSA), replacing RSA and elliptic curve systems with lattice-based approaches. Google has embedded these standards into Chrome and Android, setting 2029 as its internal migration deadline. Ethereum's Vitalik Buterin has updated the roadmap to stage post-quantum replacements for BLS signatures, KZG commitments, and ECDSA across multiple upgrades. Bitcoin has no central authority or coordinated engineering body, and its governance culture historically moves slowly on fundamental changes — Taproot took years of community discussion before activation.
Circle's warning comes as the stablecoin issuer faces its own post-quantum migration obligations. The company's USDC operates on multiple blockchain networks, each requiring coordinated cryptographic upgrades. The Zcash rally that followed Google's March 2026 paper showed how quickly investor positioning can shift on quantum security news — a signal that quantum risk is beginning to factor into token valuations.
This article is for informational purposes only and does not constitute investment advice.