Research

Google Willow 2026: Progress Update and What the Next Chip Means for Bitcoin

Google's Willow chip proved below-threshold error correction at scale in 2024. In 2026, the question is: what has Google built since, and how close is the roadmap to a chip that actually threatens Bitcoin?

QuanChain Research
October 10, 2026
8 min read
Share
Google Willow 2026: Progress Update and What the Next Chip Means for Bitcoin
TL;DR: Google's Willow chip (105 physical qubits, December 2024) proved that quantum error correction scales below the fault-tolerance threshold — a prerequisite for useful quantum computing. In 2026, Google is pursuing its stated goal of a "useful" quantum computer, likely with a larger-scale successor chip. Willow still has zero logical qubits and cannot touch Bitcoin's secp256k1 curve. Breaking Bitcoin would require roughly 4,000 logical qubits — thousands of times what any public system has demonstrated. But the physics are validated, the roadmap is accelerating, and the next chip matters more than this one did.

Willow Recap: What the 2024 Chip Actually Proved

When Google published its Willow results in Nature in December 2024, the headlines ranged from "Bitcoin is doomed" to "nothing to see here." Neither was accurate. Our original Willow analysis covered the physics in depth; the short version is this: Willow's 105-qubit superconducting processor demonstrated below-threshold error correction at scale for the first time.

That phrase — below-threshold — is the whole story. Quantum computers are inherently noisy. Physical qubits decohere, gate operations introduce errors, and running any useful algorithm requires encoding many noisy physical qubits into reliable logical qubits through error correction codes. The catch is that error correction only helps if the physical error rate is below a critical value called the fault-tolerance threshold. Above that threshold, adding more physical qubits per logical qubit makes things worse. Below it, error rates fall exponentially as you scale.

Before Willow, this scaling behavior had been theorized but not cleanly demonstrated at meaningful processor size. Willow showed that as Google increased code distance — adding more physical qubits per logical qubit — the logical error rate dropped the way the theory predicted. The physics work. That is not a minor result. It removed the largest single uncertainty hanging over the entire field.

Willow also ran a random circuit sampling benchmark in under five minutes that Google characterized as taking a classical supercomputer 1025 years. That number traveled widely and caused most of the Bitcoin panic. It is worth stating clearly: random circuit sampling has no cryptographic relevance. It is a synthetic problem designed to showcase quantum advantage, not to factor numbers or solve discrete logarithms. Willow's RCS result says nothing about its ability to run Shor's algorithm against secp256k1.

Where Google Stands in 2026

Google has not published a detailed public roadmap with specific qubit targets and dates the way IBM has. What Google has stated publicly is a goal of demonstrating a "useful" quantum computer — one that can solve problems of practical value that classical computers cannot — as a near-term milestone on the path to a fully fault-tolerant system.

Based on the trajectory from Sycamore (53 qubits, 2019) to Willow (105 qubits, 2024), and accounting for the typical two-to-three year cadence between major Google quantum hardware announcements, a successor chip with meaningfully higher qubit counts and potentially first demonstrations of actual logical qubit operation is consistent with the 2026 timeframe. Google's quantum hardware team, led by Julian Kelly and operating under Google DeepMind since the 2023 reorganization, has continued publishing results on error correction codes, qubit connectivity improvements, and gate fidelity advances throughout 2025 and into 2026.

The Gemini integration angle is worth noting. Google has explicitly explored connections between its AI infrastructure and quantum computing research, not in the sense of running LLMs on quantum hardware — that is not near-term feasible — but in using AI methods to discover better quantum error correction codes, optimize circuit compilation, and simulate quantum systems. Results from Google researchers in 2025 used reinforcement learning to discover error correction protocols that outperformed hand-designed ones. This AI-assisted quantum research loop is likely to accelerate the hardware roadmap in ways that are difficult to extrapolate linearly from past qubit counts.

The key hardware milestone to watch for in the next chip is not raw qubit count but logical qubit demonstration. Willow proved below-threshold physics. The natural next step is to encode and operate actual logical qubits — demonstrating that a single logical qubit can perform a meaningful computation reliably. That would be the transition from "error correction works in principle" to "we can actually use it." No public system has demonstrated this cleanly as of mid-2026.

Google vs IBM: Two Different Bets

IBM and Google represent the two dominant approaches to near-term quantum hardware, and comparing them is useful for understanding where the field is heading. IBM's approach is explicitly modular: rather than building a single enormous processor, IBM is constructing a network of smaller processors connected by quantum communication links. The Heron processor delivered IBM's best qubit quality in 2023. The Flamingo and Kookaburra architectures that followed extend the system using modular interconnects.

Google's approach has been monolithic: scale a single superconducting die. Willow's 105 qubits are all on one processor, connected by Google's transmon qubit architecture with tunable couplers. The advantage of the monolithic approach is that local qubit connectivity is dense and fast. The disadvantage is that you eventually hit physical limits on how many qubits you can fit on a single chip while maintaining the fabrication quality needed for low error rates.

Microsoft is pursuing a fundamentally different strategy — topological qubits using Majorana zero modes. Microsoft's Majorana 1 chip, announced in early 2025, represented a significant step toward hardware-native error protection: topological qubits are theoretically more robust to local noise than superconducting qubits, which could dramatically reduce the physical-to-logical qubit overhead. If topological qubits work at scale, the resource requirements for fault-tolerant computation — including cryptographic attacks — could compress substantially faster than superconducting timelines suggest.

The table below compares the three leading systems on the metrics that matter for cryptographic relevance:

System Physical Qubits 2-Qubit Gate Error Logical Qubits (Public) Crypto Relevance
Google Willow 105 ~0.3% 0 (demonstrated EC, not LQ operation) None — millions of phys. qubits required
IBM Heron r2 133 ~0.25% 0 (error correction research stage) None — logical qubit milestone not reached
Microsoft Majorana 1 8 (topological) ~1% (early-stage) 0 (hardware protection only, not fault-tolerant) None — but lower overhead path if it scales

The key column is logical qubits. All three systems sit at zero. The entire industry is still in the stage of proving that logical qubits can be built reliably, not running algorithms on them. IBM's competing approach is targeting fault-tolerant demonstrations on a published timeline; Google's roadmap implies similar ambitions without public milestone dates.

Why Willow Still Cannot Touch secp256k1

Bitcoin's elliptic curve digital signature algorithm uses the secp256k1 curve — a 256-bit elliptic curve over a prime field. Breaking it requires running Shor's algorithm for the elliptic curve discrete logarithm problem. The qubit threshold for Bitcoin — the number of logical qubits needed to execute this attack in a cryptographically relevant timeframe — sits at roughly 4,000 to 10,000 logical qubits depending on the implementation and parallelism assumptions. Recent algorithmic work has pushed the lower bound of some estimates below 2,000 logical qubits under favorable conditions, but the consensus range remains in the low thousands.

Willow has zero logical qubits. This is not a question of degree — it is a categorical gap. Willow demonstrated that error correction can scale below threshold, meaning the exponential suppression of error rates with added physical qubits is real. But no one has yet encoded a logical qubit on Willow and run a non-trivial algorithm on it. The jump from "error correction scales correctly" to "we have operational logical qubits" to "we have enough logical qubits to run Shor's algorithm against a 256-bit key" involves at minimum two additional engineering milestones, each of which is a multi-year program.

Furthermore, even once logical qubits exist, the physical-to-logical overhead matters enormously. With current surface code implementations, achieving one reliable logical qubit requires on the order of 1,000 physical qubits at current error rates. At 4,000 logical qubits needed for a Bitcoin attack, that implies approximately 4 million physical qubits. Willow has 105. The gap is not incremental.

QLDPC codes — quantum low-density parity-check codes — could change this math significantly. These codes achieve much better encoding rates than surface codes by coupling non-adjacent qubits through more complex connection graphs. Theoretical analyses show QLDPC codes could reduce physical-to-logical overhead by one to two orders of magnitude, potentially compressing the physical qubit requirement for a Bitcoin attack from millions to tens of thousands. But QLDPC codes are significantly harder to implement in superconducting hardware than surface codes, because their non-local connectivity requirements do not map naturally onto the 2D nearest-neighbor geometry of most superconducting processors. They are more naturally suited to neutral-atom platforms, which have programmable connectivity. Google's Willow architecture does not currently implement QLDPC codes at scale.

What the Next Google Chip Would Need to Matter

For a Google quantum chip to meaningfully advance the timeline for Bitcoin-threatening capability — not to pose an immediate threat, but to change the trajectory in ways that compress the remaining distance — it would need to hit several specific milestones:

  • Operational logical qubits: Demonstrating that one or more logical qubits can be encoded and used to run a complete algorithm, not just showing that error correction suppresses noise. This is the next major milestone for the field.
  • Qubit counts in the low thousands: With surface-code overhead, several thousand physical qubits per logical qubit is required. A chip with 1,000+ high-quality physical qubits starts to make single logical qubit experiments tractable. A chip with 10,000+ starts to make multi-logical-qubit experiments tractable.
  • Error rates below 0.1%: Current superconducting two-qubit gate error rates hover around 0.2–0.5%. Dropping below 0.1% would significantly reduce the physical-to-logical overhead needed for fault tolerance and accelerate the timeline to usable logical qubits.
  • QLDPC code implementation or a different architecture: Unless Google moves to non-local connectivity (through modular links, shuttle qubits, or a different qubit technology), the surface code overhead will remain the binding constraint. A chip that demonstrates non-local connectivity at scale would be a qualitatively different result.

A chip that hits even the first two of these milestones would be a meaningful acceleration of the threat timeline, even if it still cannot approach a Bitcoin attack. It would close the logical qubit gap — the categorical gap that currently separates all public systems from crypto-relevant computation.

The Compounding Effect: Algorithms Getting More Efficient Too

Hardware qubit counts are only one axis of the threat. The other axis — often underweighted in public coverage — is algorithmic efficiency. The resource requirements for running Shor's algorithm against ECDSA have been revised downward repeatedly as researchers find more efficient implementations. The 2012 estimate for breaking RSA-2048 required billions of physical qubits. By 2022, optimized approaches brought that figure down by several orders of magnitude. Work published in 2025 by researchers at PsiQuantum and the University of Waterloo proposed circuit implementations for secp256k1 attacks requiring as few as 317 logical qubits under aggressive parallelism assumptions.

This compression is not a coincidence or a lucky break — it reflects a systematic effort by the quantum algorithms community to minimize resource requirements, motivated partly by the fact that hardware is expensive and partly by the competition to be the first group to demonstrate a practically relevant result. The algorithms will keep getting more efficient as hardware milestones give researchers new targets to optimize toward.

The combination of hardware scaling and algorithmic improvement means that the threat timeline is being compressed from both ends simultaneously. You can calculate your exposure against different timeline scenarios using the QuanChain threat calculator, which models both the hardware trajectory and the algorithmic compression curve.

What Holders and Builders Should Watch For

The next inflection point in the quantum-Bitcoin threat timeline is not a qubit count — it is the first public demonstration of a logical qubit running a complete algorithm. When that result appears, it will signal that the categorical gap between physical-qubit research and fault-tolerant computation has been crossed. The distance from that milestone to a cryptographically relevant system is still large, but it will no longer be categorical.

Watch for three types of announcements in the next twelve to twenty-four months: first, any Google publication describing logical qubit operation (not just error correction scaling); second, IBM's progress on its published fault-tolerance roadmap targets; third, any Microsoft result showing that Majorana-based topological qubits can be operated coherently at circuit depths relevant to Shor's algorithm. Any one of these would meaningfully update the threat timeline.

For anyone building on or holding assets in quantum-vulnerable addresses, the appropriate response is not to wait for that announcement before acting. Public key exposure on Bitcoin and Ethereum is an accumulated risk that grows with every passing hardware milestone. The infrastructure that eliminates that risk — post-quantum signature schemes, atomic key rotation, zero-exposure wallet architectures — exists today. The question is whether adoption outpaces the hardware curve.

Google Willow proved the physics. The next chip will prove the engineering. That is a different kind of result, and it is closer than the 2024 coverage suggested.

QuanChain Research

Research Division

The QuanChain Research Division investigates post-quantum cryptographic standards, quantum hardware timelines, and blockchain protocol security. Research outputs inform both the QuanChain protocol roadmap and the broader open-source post-quantum blockchain community.

Related Articles