What Is Q-Day?
Q-Day is shorthand for the first day a cryptographically-relevant quantum computer (CRQC) exists — a machine powerful enough to run Shor's algorithm on the elliptic-curve keys that protect Bitcoin addresses and virtually every other public-key cryptosystem in use today. On that day, any exposed public key (any address that has ever sent a transaction) becomes trivially crackable given enough time and compute.
The term is deliberately stark. It is not a gradual degradation. Once the qubit threshold is crossed, the cryptographic assumptions underlying roughly $1.8 trillion in Bitcoin alone collapse overnight. The question is not whether quantum computers will reach that threshold, but when — and whether the ecosystem migrates fast enough beforehand.
This tracker exists because that "when" keeps shifting. Every major hardware milestone changes the credible range. We update it whenever a new machine is announced, benchmarked, or shipped.
The Milestone Tracker: 2019 – 2026
The table below captures every hardware and algorithmic milestone that materially changed the timeline picture. "Relevance" scores how much each event moved the needle on Q-Day estimates.
| Date | Organization | Milestone | Qubits | Relevance to Crypto |
|---|---|---|---|---|
| Oct 2019 | Sycamore — "quantum supremacy" on random circuit sampling | 53 | Low — proved noisy qubits can outpace classical on narrow tasks; no error correction | |
| Nov 2021 | IBM | Eagle — first 100+ qubit processor | 127 | Low — hit psychological milestone but error rates still far from threshold |
| Nov 2022 | IBM | Osprey — 433 qubits | 433 | Low-Medium — scale increasing but logical qubit demos still absent |
| Jun 2023 | IBM | Condor — 1,121 qubits; Heron R1 — low-error connectivity | 1,121 / 133 | Medium — Heron's lower error rate more significant than Condor's raw count |
| Dec 2024 | Google Willow — below-threshold error correction demonstrated | 105 | High — first public proof that adding qubits reduces logical error rate; a turning point | |
| Feb 2025 | Microsoft | Majorana 1 — first topological qubit chip | 8 topological | High (long-term) — topological qubits promise far lower error rates; near-term utility limited |
| Q1 2025 | IBM | Heron R2 — improved gate fidelity over R1 | 156 | Medium — incremental but each fidelity gain compresses the error-correction overhead required |
| 2025–2026 | IBM | Flamingo roadmap — 1,386-qubit modular architecture target | ~1,386 (projected) | Medium — modular interconnects critical for scaling toward millions of qubits |
Hardware Generations at a Glance
Raw qubit counts are only one axis. Error rate and connectivity determine whether those qubits can be turned into logical qubits — the fault-tolerant kind that can actually run Shor's algorithm without the computation drowning in noise. The table below maps hardware generations to logical qubit efficiency and their practical distance from the cryptographic threat threshold.
| Generation | Representative Chip | Physical Qubits | Approx. Physical / Logical Ratio | Logical Qubits Available | Crypto Relevance |
|---|---|---|---|---|---|
| NISQ (2019–2022) | Sycamore, Eagle | 53–127 | N/A (no QEC) | ~0 | None |
| Early error-suppressed (2022–2024) | Osprey, Condor | 433–1,121 | ~1,000:1 | <2 | None |
| Below-threshold QEC (2024–2026) | Willow, Heron R2 | 105–1,386 | ~100–300:1 | ~5–14 | Negligible — proof of concept only |
| Early fault-tolerant (2027–2030 est.) | IBM Flamingo+, Google next-gen | 10,000–100,000 | ~30–100:1 | 100–3,000 | Low — approaching but below ~4,000 logical minimum |
| Cryptographically relevant (threshold) | Unknown — 2030–2035 est. | 13M–317M | ~3,000–80,000:1 | ~4,000 (logical minimum) | Full threat to secp256k1 |
What Qubit Counts Actually Mean for Bitcoin
The numbers in the tracker above become meaningful only when you understand the calculation behind the threat. Bitcoin's security rests on the secp256k1 elliptic curve. Breaking it requires running Shor's algorithm to compute a discrete logarithm — an operation that demands fault-tolerant logical qubits, not the noisy physical qubits that current machines provide.
Three benchmarks dominate the academic literature:
- ~4,000 logical qubits — the theoretical minimum under best-case algorithmic optimizations, assuming near-perfect gates and unlimited time. No timeline constraint.
- 13 million physical qubits — what you need to break a Bitcoin key within one hour, assuming error-corrected superconducting qubits at a 10⁻³ physical error rate (the best achieved in lab conditions as of 2025).
- ~317 million physical qubits — the number required at today's average qubit fidelities on production machines (~10⁻² error rate), still assuming the one-hour attack window.
The gap between current hardware (~1,000–1,500 physical qubits) and the 13 million threshold is roughly four orders of magnitude. That sounds comfortable, but hardware density has followed an exponential curve: IBM's qubit count has doubled roughly every 12–18 months since 2016. If that pace holds — and there is genuine debate about whether physical limits slow it down in the coming years — the gap closes faster than intuition suggests.
There is a second, subtler consideration. Not all Bitcoin addresses carry the same risk. Addresses that have never sent a transaction expose only a hash of the public key — far more resistant to quantum attack. Addresses that have sent transactions expose the raw public key on-chain, meaning a sufficiently powerful quantum computer could derive the private key and drain the wallet before the owner reacts. An estimated 25–40% of all Bitcoin supply sits in exposed addresses today.
Google Willow: Why December 2024 Mattered
Google Willow, announced in December 2024, was the first public demonstration of below-threshold quantum error correction at scale. Previous machines saw logical error rates stay flat or worsen as you added more physical qubits — a ceiling that made fault-tolerant computing look far away. Willow flipped that: adding qubits made the logical error rate drop exponentially, exactly as QEC theory predicts it should when you are operating below the fault-tolerance threshold.
This was not a demonstration that Q-Day is imminent. Willow has 105 physical qubits and showed the principle on a small surface code. But it removed a major empirical uncertainty. Until Willow, skeptics could reasonably argue that real hardware would never hit the below-threshold regime outside of theory. That argument is now harder to sustain. The engineering challenge shifts from "can we do this at all" to "how quickly can we scale it."
IBM's Current Roadmap
IBM's current roadmap is the most detailed public projection from any major player. Key waypoints:
- Heron R2 (2025) — Improved two-qubit gate fidelity over R1; the workhorse for near-term quantum utility experiments.
- Flamingo (2025–2026) — A modular 1,386-qubit design using quantum communication links between processor tiles. Modularity is critical: you cannot fabricate a single wafer with 13 million qubits, so interconnected modules are the only plausible path to CRQC scale.
- Kookaburra and beyond (2027+) — IBM has described targets beyond Flamingo but has pulled back on publishing specific qubit counts past 2026, instead focusing on "100x improvement in error rates" as the operative goal.
The honest read of IBM's roadmap is that they are on track to demonstrate compelling quantum utility in chemistry and optimization over the next 2–3 years, but the jump from ~10,000 quality qubits to the millions needed for cryptographic relevance remains the harder half of the problem. It requires breakthroughs in qubit connectivity, classical control electronics, and cryogenic engineering that are not simply a matter of repeating what already works at a larger scale.
Microsoft's Topological Bet
Microsoft's Majorana 1 chip, unveiled in February 2025, pursues a fundamentally different strategy. Rather than building more error-correction overhead around inherently noisy transmon or superconducting qubits, topological qubits aim to store quantum information in physical modes that are intrinsically protected from local noise sources. The theory predicts that topological qubits would require orders-of-magnitude fewer physical qubits per logical qubit — potentially as low as 10:1 instead of the 1,000:1 typical of current superconducting approaches.
Majorana 1 demonstrated the first topological qubit that passes Microsoft's own readiness criteria. The machine has 8 topological qubits, far too few for any practical computation. But the architectural implication is significant: if topological qubits mature, the physical qubit counts in the threat-threshold tables above drop dramatically. A 13 million physical qubit target under superconducting assumptions might become 130,000 under mature topological assumptions. That collapses the timeline considerably.
The caveat is that topological qubits are still early. Gate operations on them are slower than superconducting qubits, and scaling from 8 to millions faces its own unsolved engineering challenges. Most analysts treat Majorana 1 as a 5–8 year option rather than a near-term disruptor.
Timeline Projections: What the Research Actually Says
Aggregating recent peer-reviewed estimates and institutional forecasts produces a rough consensus:
| Scenario | Q-Day Estimate | Key Assumptions | Probability (expert survey avg.) |
|---|---|---|---|
| Optimistic / accelerated | 2029–2031 | Topological qubits mature early; algorithmic improvements reduce threshold; heavy state investment | ~10–15% |
| Mainstream consensus | 2032–2035 | Superconducting scaling continues; error correction improves incrementally; no major surprise | ~50–60% |
| Conservative / delayed | 2036–2040+ | Physical scaling hits fundamental limits; error correction overhead does not improve as projected | ~25–35% |
| Pre-2029 (black swan) | Before 2029 | Classified breakthrough; radical algorithmic improvement; undisclosed nation-state capability | <5% |
Note that even the "delayed" scenario lands within 15 years. Bitcoin's blockchain is permanent — a transaction broadcast today can be retroactively attacked once Q-Day arrives if the public key was exposed. This is why the migration window matters: the question is not just when Q-Day arrives, but whether wallets and protocols migrate before it does.
What Crypto Holders Should Watch For
Rather than tracking raw qubit counts in press releases, focus on the following signal events — each one materially changes the timeline picture:
- First 10,000-logical-qubit demonstration. This would mean the below-threshold QEC demonstrated by Willow has been sustained at meaningful scale. Not a threat yet, but the clearest harbinger that the threshold is approaching.
- A public Shor's algorithm run on a non-trivial integer. Factoring integers over 2,048 bits would require resources orders of magnitude beyond current machines — but incremental demos factoring progressively larger numbers will benchmark progress directly.
- NIST PQC migration deadlines passing without major protocol adoption. NIST finalized its first post-quantum cryptography standards in August 2024. If Bitcoin and major exchanges have not begun migration by 2027–2028, the window compresses dangerously.
- Nation-state quantum program disclosures. The US, China, and the EU are all running classified programs. A policy disclosure or credible leak about capability ahead of public milestones would be the most alarming single signal.
- Microsoft topological qubit scaling announcements. If Majorana 1 successors reach 1,000+ topological qubits by 2027–2028, revise every timeline estimate downward by 3–5 years.
The Current Gap — And Why It Is Shrinking
As of October 2026, the best public hardware sits at roughly 1,000–1,500 physical qubits, with logical qubit counts in the single or low double digits. The minimum physical qubit threshold for a realistic Bitcoin attack — 13 million under optimistic error-correction assumptions — is still four orders of magnitude away.
But the shape of that gap matters as much as its size. Three years ago, it was unclear whether below-threshold error correction was achievable in practice. That question is now answered. Two years ago, modular multi-chip quantum systems were theoretical. IBM and others are now demonstrating them. The engineering challenges that remain are hard, but they are now clearly engineering challenges rather than fundamental physics unknowns.
The historical pattern in cryptographic transitions is instructive. RSA-512 was considered secure until 1999 when it was factored — then suddenly every 512-bit key was at risk. RSA-768 fell in 2009. The transitions happened faster than most projections, and the practical response lagged by years. The quantum transition will be slower overall, but the political and organizational lag in updating embedded systems, legacy wallets, and protocol governance may well eat up most of the available window.
How QuanChain Approaches This
QuanChain was built on the premise that the window to migrate is finite and the cost of waiting rises nonlinearly as Q-Day approaches. Our architecture uses post-quantum signature schemes that are already resistant to Shor's algorithm regardless of when — or whether — any of the projections above prove correct. The migration case does not depend on a precise Q-Day prediction. It depends only on the asymmetry: the cost of migrating now is bounded and certain; the cost of being caught unprepared is unbounded.
If you hold Bitcoin or operate infrastructure that relies on classical public-key cryptography, the right frame is not "when exactly is Q-Day" but "how much of the window have I already used." You can assess your own exposure with our quantum threat calculator — it maps your address types, holding durations, and migration options against current timeline projections to give you a practical risk estimate rather than a theoretical one.
We will continue updating this tracker as new milestones arrive. Bookmark it, or subscribe to QuanChain Research for milestone alerts.


