Research / Q-Day
Resource estimates and Q-Day
Q-Day is the informal name for the first moment a cryptographically relevant quantum computer can break production ECC. The date is a range. The direction of the resource estimates is not.
Google, 2026
In March 2026, Google Quantum AI published Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities, with a companion responsible-disclosure blog post and a paper on ePrint 2026/625. Under standard superconducting assumptions they give two Shor circuits for ECDLP-256:
- ≤ 1,200 logical qubits and ≤ 90 million Toffoli gates
- ≤ 1,450 logical qubits and ≤ 70 million Toffoli gates
Compiled to a planar surface-code machine at 10⁻³ physical error rate, they estimate those circuits run in minutes with fewer than 500,000 physical qubits, roughly an order of magnitude below earlier public single-instance estimates. They also distinguish fast-clock machines (superconducting, photonic) that could attack in-flight mempool transactions from slower architectures.
Project Eleven
Project Eleven has treated Q-Day as an engineering problem, not a thought experiment. In April 2026 their Q-Day Prize produced a 15-bit elliptic-curve break on publicly accessible ~70-qubit hardware. This is still nowhere near 256-bit keys, but a live demonstration of the attack class. In July 2026 they published an unaudited prototype for proving Bitcoin ownership after Q-Day using a post-quantum ZK proof over BIP-32 derivation, in case a migration window closes with coins still sitting on ECC addresses.
How to read the timeline
Public Q-Day ranges still cluster in the early 2030s, with tails in both directions. Hardware may slip. Algorithms have been getting cheaper. LPs do not need a precise year to notice that a 10-year fund with a 2024–2026 vintage is long a cryptographic assumption whose published cost is falling.
vc.fail does not assign a Q-Day date to any fund. It only asks whether the public book has started to leave ECC.