IonQ (NYSE: IONQ) has published what it calls the world's first complete, end-to-end fault-tolerant resource estimate for Shor's algorithm, concluding that a 20,000-qubit trapped-ion machine on the company's Walking Cat architecture could crack the 256-bit elliptic curve behind Bitcoin in just under 26 days per attempt.
A Fully Compiled Blueprint For Q-Day
The paper, released on September 8 alongside IonQ's Superion 256 launch and 2026 investor day, targets secp256k1 — the elliptic-curve signature standard used by digital-asset chains and countless authentication systems. IonQ says the study is the first estimate that compiles every operation down to the actual error-correction primitives its architecture runs, rather than approximating the parts that usually dominate real-machine runtime.
The numbers: 25.7 days to solve the 256-bit ECDLP per attempt, on 19,397 physical qubits, using 1,457 logical qubits and 39 million Toffoli gates. The result maps to systems already on IonQ's public roadmap for the 2028 timeframe. "This is the first time anyone has taken a utility-scale quantum algorithm and estimated its cost without approximating away the parts that usually dominate a real machine's runtime," said Chris Ballance, IonQ's President of Quantum Computing.
Walking Cat Meets Elliptic Curves
The blueprint extends IonQ's Walking Cat architecture, first published in April 2026 as a full-stack fault-tolerant plan built on trapped ions and quantum low-density parity-check (qLDPC) codes. September's update introduces an optimized version tailored for the elliptic curve discrete logarithm problem, provably bounding the algorithm's success probability rather than assuming it. IonQ argues the same full-stack methodology now applies across chemistry, financial services, materials, optimization, defense, and intelligence workloads it is pursuing with partners including NVIDIA and qBraid.
Q-Day Timeline Shifts Forward
IonQ chairman and CEO Niccolo de Masi said the finding validates his 2025 call that the "Q-Day" timeline for quantum threats to public-key cryptography has shifted from the 2030s into the 2020s. The White House issued its executive order on quantum security earlier this summer, and IonQ says it followed responsible disclosure practices — sharing advance copies of the paper with U.S. government and industry partners before publication. The exposure is authentication and integrity rather than confidentiality: elliptic-curve signatures underpin code signing, certificate hierarchies, device identity and long-lived roots of trust.
The Migration Question
Mitigations already exist: NIST-standardized Stateless Hash-Based Digital Signature Algorithm (SLH-DSA) and ML-DSA are both unaffected by this class of attack. Yet signature migration has historically lagged the encryption side of the post-quantum transition because roots of trust are the hardest element to swap. IonQ is targeting a fully fault-tolerant 10,000-qubit system in 2027, with the 20,000-qubit scale roughly a year behind. The company's MOU with Sandia National Laboratories and its recent Galaxy Digital quantum-readiness collaboration position it to help critical-infrastructure customers plan the switch before the machines arrive.
Reporting based on coverage from IonQ, The Quantum Insider and Quantum Computing Report.