Research

Q-Day Tracker 2026: Every Quantum Milestone That Matters for Bitcoin and Crypto

A live-updated timeline of every quantum computing milestone relevant to Bitcoin and crypto — from Google Sycamore to Willow, IBM's roadmap, and what the current qubit gap really means.

QuanChain Research
October 10, 2026
10 min read
Share
Q-Day Tracker 2026: Every Quantum Milestone That Matters for Bitcoin and Crypto
TL;DR: Q-Day — the moment a quantum computer can break Bitcoin's elliptic-curve cryptography — requires roughly 13 million physical qubits under optimistic error-correction assumptions, or ~317 million under today's qubit fidelities. The most powerful machines in late 2026 top out near 1,000–1,500 physical qubits. Academic consensus puts Q-Day somewhere between 2030 and 2035 — but hardware milestones are arriving faster than most projections from just three years ago. This tracker collects every relevant milestone in one place and explains what each one means for your holdings.

What Is Q-Day?

Q-Day is shorthand for the first day a cryptographically-relevant quantum computer (CRQC) exists — a machine powerful enough to run Shor's algorithm on the elliptic-curve keys that protect Bitcoin addresses and virtually every other public-key cryptosystem in use today. On that day, any exposed public key (any address that has ever sent a transaction) becomes trivially crackable given enough time and compute.

The term is deliberately stark. It is not a gradual degradation. Once the qubit threshold is crossed, the cryptographic assumptions underlying roughly $1.8 trillion in Bitcoin alone collapse overnight. The question is not whether quantum computers will reach that threshold, but when — and whether the ecosystem migrates fast enough beforehand.

This tracker exists because that "when" keeps shifting. Every major hardware milestone changes the credible range. We update it whenever a new machine is announced, benchmarked, or shipped.

The Milestone Tracker: 2019 – 2026

The table below captures every hardware and algorithmic milestone that materially changed the timeline picture. "Relevance" scores how much each event moved the needle on Q-Day estimates.

Date Organization Milestone Qubits Relevance to Crypto
Oct 2019 Google Sycamore — "quantum supremacy" on random circuit sampling 53 Low — proved noisy qubits can outpace classical on narrow tasks; no error correction
Nov 2021 IBM Eagle — first 100+ qubit processor 127 Low — hit psychological milestone but error rates still far from threshold
Nov 2022 IBM Osprey — 433 qubits 433 Low-Medium — scale increasing but logical qubit demos still absent
Jun 2023 IBM Condor — 1,121 qubits; Heron R1 — low-error connectivity 1,121 / 133 Medium — Heron's lower error rate more significant than Condor's raw count
Dec 2024 Google Google Willow — below-threshold error correction demonstrated 105 High — first public proof that adding qubits reduces logical error rate; a turning point
Feb 2025 Microsoft Majorana 1 — first topological qubit chip 8 topological High (long-term) — topological qubits promise far lower error rates; near-term utility limited
Q1 2025 IBM Heron R2 — improved gate fidelity over R1 156 Medium — incremental but each fidelity gain compresses the error-correction overhead required
2025–2026 IBM Flamingo roadmap — 1,386-qubit modular architecture target ~1,386 (projected) Medium — modular interconnects critical for scaling toward millions of qubits

Hardware Generations at a Glance

Raw qubit counts are only one axis. Error rate and connectivity determine whether those qubits can be turned into logical qubits — the fault-tolerant kind that can actually run Shor's algorithm without the computation drowning in noise. The table below maps hardware generations to logical qubit efficiency and their practical distance from the cryptographic threat threshold.

Generation Representative Chip Physical Qubits Approx. Physical / Logical Ratio Logical Qubits Available Crypto Relevance
NISQ (2019–2022) Sycamore, Eagle 53–127 N/A (no QEC) ~0 None
Early error-suppressed (2022–2024) Osprey, Condor 433–1,121 ~1,000:1 <2 None
Below-threshold QEC (2024–2026) Willow, Heron R2 105–1,386 ~100–300:1 ~5–14 Negligible — proof of concept only
Early fault-tolerant (2027–2030 est.) IBM Flamingo+, Google next-gen 10,000–100,000 ~30–100:1 100–3,000 Low — approaching but below ~4,000 logical minimum
Cryptographically relevant (threshold) Unknown — 2030–2035 est. 13M–317M ~3,000–80,000:1 ~4,000 (logical minimum) Full threat to secp256k1

What Qubit Counts Actually Mean for Bitcoin

The numbers in the tracker above become meaningful only when you understand the calculation behind the threat. Bitcoin's security rests on the secp256k1 elliptic curve. Breaking it requires running Shor's algorithm to compute a discrete logarithm — an operation that demands fault-tolerant logical qubits, not the noisy physical qubits that current machines provide.

Three benchmarks dominate the academic literature:

  • ~4,000 logical qubits — the theoretical minimum under best-case algorithmic optimizations, assuming near-perfect gates and unlimited time. No timeline constraint.
  • 13 million physical qubits — what you need to break a Bitcoin key within one hour, assuming error-corrected superconducting qubits at a 10⁻³ physical error rate (the best achieved in lab conditions as of 2025).
  • ~317 million physical qubits — the number required at today's average qubit fidelities on production machines (~10⁻² error rate), still assuming the one-hour attack window.

The gap between current hardware (~1,000–1,500 physical qubits) and the 13 million threshold is roughly four orders of magnitude. That sounds comfortable, but hardware density has followed an exponential curve: IBM's qubit count has doubled roughly every 12–18 months since 2016. If that pace holds — and there is genuine debate about whether physical limits slow it down in the coming years — the gap closes faster than intuition suggests.

There is a second, subtler consideration. Not all Bitcoin addresses carry the same risk. Addresses that have never sent a transaction expose only a hash of the public key — far more resistant to quantum attack. Addresses that have sent transactions expose the raw public key on-chain, meaning a sufficiently powerful quantum computer could derive the private key and drain the wallet before the owner reacts. An estimated 25–40% of all Bitcoin supply sits in exposed addresses today.

Google Willow: Why December 2024 Mattered

Google Willow, announced in December 2024, was the first public demonstration of below-threshold quantum error correction at scale. Previous machines saw logical error rates stay flat or worsen as you added more physical qubits — a ceiling that made fault-tolerant computing look far away. Willow flipped that: adding qubits made the logical error rate drop exponentially, exactly as QEC theory predicts it should when you are operating below the fault-tolerance threshold.

This was not a demonstration that Q-Day is imminent. Willow has 105 physical qubits and showed the principle on a small surface code. But it removed a major empirical uncertainty. Until Willow, skeptics could reasonably argue that real hardware would never hit the below-threshold regime outside of theory. That argument is now harder to sustain. The engineering challenge shifts from "can we do this at all" to "how quickly can we scale it."

IBM's Current Roadmap

IBM's current roadmap is the most detailed public projection from any major player. Key waypoints:

  • Heron R2 (2025) — Improved two-qubit gate fidelity over R1; the workhorse for near-term quantum utility experiments.
  • Flamingo (2025–2026) — A modular 1,386-qubit design using quantum communication links between processor tiles. Modularity is critical: you cannot fabricate a single wafer with 13 million qubits, so interconnected modules are the only plausible path to CRQC scale.
  • Kookaburra and beyond (2027+) — IBM has described targets beyond Flamingo but has pulled back on publishing specific qubit counts past 2026, instead focusing on "100x improvement in error rates" as the operative goal.

The honest read of IBM's roadmap is that they are on track to demonstrate compelling quantum utility in chemistry and optimization over the next 2–3 years, but the jump from ~10,000 quality qubits to the millions needed for cryptographic relevance remains the harder half of the problem. It requires breakthroughs in qubit connectivity, classical control electronics, and cryogenic engineering that are not simply a matter of repeating what already works at a larger scale.

Microsoft's Topological Bet

Microsoft's Majorana 1 chip, unveiled in February 2025, pursues a fundamentally different strategy. Rather than building more error-correction overhead around inherently noisy transmon or superconducting qubits, topological qubits aim to store quantum information in physical modes that are intrinsically protected from local noise sources. The theory predicts that topological qubits would require orders-of-magnitude fewer physical qubits per logical qubit — potentially as low as 10:1 instead of the 1,000:1 typical of current superconducting approaches.

Majorana 1 demonstrated the first topological qubit that passes Microsoft's own readiness criteria. The machine has 8 topological qubits, far too few for any practical computation. But the architectural implication is significant: if topological qubits mature, the physical qubit counts in the threat-threshold tables above drop dramatically. A 13 million physical qubit target under superconducting assumptions might become 130,000 under mature topological assumptions. That collapses the timeline considerably.

The caveat is that topological qubits are still early. Gate operations on them are slower than superconducting qubits, and scaling from 8 to millions faces its own unsolved engineering challenges. Most analysts treat Majorana 1 as a 5–8 year option rather than a near-term disruptor.

Timeline Projections: What the Research Actually Says

Aggregating recent peer-reviewed estimates and institutional forecasts produces a rough consensus:

Scenario Q-Day Estimate Key Assumptions Probability (expert survey avg.)
Optimistic / accelerated 2029–2031 Topological qubits mature early; algorithmic improvements reduce threshold; heavy state investment ~10–15%
Mainstream consensus 2032–2035 Superconducting scaling continues; error correction improves incrementally; no major surprise ~50–60%
Conservative / delayed 2036–2040+ Physical scaling hits fundamental limits; error correction overhead does not improve as projected ~25–35%
Pre-2029 (black swan) Before 2029 Classified breakthrough; radical algorithmic improvement; undisclosed nation-state capability <5%

Note that even the "delayed" scenario lands within 15 years. Bitcoin's blockchain is permanent — a transaction broadcast today can be retroactively attacked once Q-Day arrives if the public key was exposed. This is why the migration window matters: the question is not just when Q-Day arrives, but whether wallets and protocols migrate before it does.

What Crypto Holders Should Watch For

Rather than tracking raw qubit counts in press releases, focus on the following signal events — each one materially changes the timeline picture:

  1. First 10,000-logical-qubit demonstration. This would mean the below-threshold QEC demonstrated by Willow has been sustained at meaningful scale. Not a threat yet, but the clearest harbinger that the threshold is approaching.
  2. A public Shor's algorithm run on a non-trivial integer. Factoring integers over 2,048 bits would require resources orders of magnitude beyond current machines — but incremental demos factoring progressively larger numbers will benchmark progress directly.
  3. NIST PQC migration deadlines passing without major protocol adoption. NIST finalized its first post-quantum cryptography standards in August 2024. If Bitcoin and major exchanges have not begun migration by 2027–2028, the window compresses dangerously.
  4. Nation-state quantum program disclosures. The US, China, and the EU are all running classified programs. A policy disclosure or credible leak about capability ahead of public milestones would be the most alarming single signal.
  5. Microsoft topological qubit scaling announcements. If Majorana 1 successors reach 1,000+ topological qubits by 2027–2028, revise every timeline estimate downward by 3–5 years.

The Current Gap — And Why It Is Shrinking

As of October 2026, the best public hardware sits at roughly 1,000–1,500 physical qubits, with logical qubit counts in the single or low double digits. The minimum physical qubit threshold for a realistic Bitcoin attack — 13 million under optimistic error-correction assumptions — is still four orders of magnitude away.

But the shape of that gap matters as much as its size. Three years ago, it was unclear whether below-threshold error correction was achievable in practice. That question is now answered. Two years ago, modular multi-chip quantum systems were theoretical. IBM and others are now demonstrating them. The engineering challenges that remain are hard, but they are now clearly engineering challenges rather than fundamental physics unknowns.

The historical pattern in cryptographic transitions is instructive. RSA-512 was considered secure until 1999 when it was factored — then suddenly every 512-bit key was at risk. RSA-768 fell in 2009. The transitions happened faster than most projections, and the practical response lagged by years. The quantum transition will be slower overall, but the political and organizational lag in updating embedded systems, legacy wallets, and protocol governance may well eat up most of the available window.

How QuanChain Approaches This

QuanChain was built on the premise that the window to migrate is finite and the cost of waiting rises nonlinearly as Q-Day approaches. Our architecture uses post-quantum signature schemes that are already resistant to Shor's algorithm regardless of when — or whether — any of the projections above prove correct. The migration case does not depend on a precise Q-Day prediction. It depends only on the asymmetry: the cost of migrating now is bounded and certain; the cost of being caught unprepared is unbounded.

If you hold Bitcoin or operate infrastructure that relies on classical public-key cryptography, the right frame is not "when exactly is Q-Day" but "how much of the window have I already used." You can assess your own exposure with our quantum threat calculator — it maps your address types, holding durations, and migration options against current timeline projections to give you a practical risk estimate rather than a theoretical one.

We will continue updating this tracker as new milestones arrive. Bookmark it, or subscribe to QuanChain Research for milestone alerts.

Assess your exposure now. Use the QuanChain Quantum Threat Calculator to understand which of your holdings are most at risk and what migration steps are available today — before the timeline compresses further.

QuanChain Research

Research Division

The QuanChain Research Division investigates post-quantum cryptographic standards, quantum hardware timelines, and blockchain protocol security. Research outputs inform both the QuanChain protocol roadmap and the broader open-source post-quantum blockchain community.

Related Articles