IonQ Compiles Shor’s Attack on secp256k1 Down to 19,397 Ions and 26 Days per Attempt

Table of Contents

September 8, 2026 – IonQ published a 70-page resource estimate on Tuesday concluding that a trapped-ion quantum computer with 19,397 physical qubits, built on the company’s Walking Cat architecture, could compute a 256-bit elliptic-curve discrete logarithm on the secp256k1 curve in about 25.7 days per attempt. The company released the paper on its website with a press release, on the same day it launched its Superion 256 platform and held its 2026 investor day at the New York Stock Exchange.

The paper, titled “Computing 256-bit elliptic curve discrete logarithms in 26 days on a fault-tolerant trapped-ion quantum computer with 20,000 qubits,” is dated 3 September and lists 14 authors, all at IonQ, with Thomas Häner, Felix Tripier and Jacob Young credited equally as lead authors and Michael Naehrig, Martin Roetteler, Nicolas Delfosse and John Gamble among the co-authors. secp256k1 is the curve under Bitcoin and Ethereum transaction signatures, and the authors attack it with Shor’s algorithm. The figures are specific to that curve. The acknowledgments state that generative AI tools assisted with code and figure generation, proof exploration and proofreading, and that the authors wrote the manuscript themselves. As of publication the paper had not appeared on arXiv.

At the logical level, the authors wrote that they reduced the Toffoli count of André Schrottenloher’s June 2026 secp256k1 circuits from about 58 million to 39 million, at 1,457 logical qubits against Schrottenloher’s 1,462, using a modified in-place multiplication and a modular squarer specialized for the curve’s pseudo-Mersenne prime. They also derived a proven lower bound on the success probability of the full algorithm that accounts for the phase and arithmetic errors introduced by the approximations, in place of the heuristic arguments used in earlier estimates.

At the physical level, the authors compiled every component of the algorithm to a measurement schedule that obeys the constraints of a modified Walking Cat device, and counted 75,251,329 measurement layers, 40,420,330 Toffoli-state injections and 369,882,166 other logical measurements. Charging every layer at the 29.5-millisecond duration of a Toffoli injection gives the 25.7-day runtime, which the authors describe as an upper bound. Routing between components, once merged into the arithmetic components themselves, accounts for 5% of the total.

The device contains 69 memory blocks of a [[102, 22, 9]] quantum LDPC code, four CCZ magic-state factories of 319 qubits each, 24 mobile cat-state bundle pairs, 12 Bell-state bundles, four blocks reserved for Clifford-frame clearing and a 34-ion loading reservoir. The authors removed the beacon qubits of the original Walking Cat design by replacing its qubit-loss model, which cut each memory block from three times to twice its 102 data qubits, or 207 ions per block with its three local reservoir ions.

The estimate assumes two-qubit gate errors of $10^{-4}$ and single-qubit errors of $10^{-5}$ per gate, and ion loss of $10^{-7}$ and leakage of $10^{-5}$ per ion per 200-microsecond operation cycle. The logical error rate of the memory code was extrapolated from simulations at physical error rates between $5 \times 10^{-4}$ and $2 \times 10^{-3}$. Combining memory, factory, measurement and reservoir failures gives a 26% probability that a run fails for logical reasons.

The authors put the end-to-end single-attempt success probability at 63.3% using Martin Ekerå’s heuristic post-processing estimate and at 40.7% using Michele Mosca’s rigorous lower bound. Five identical devices run in parallel would raise the probability that at least one attempt succeeds to 99.3%, they wrote.

The authors wrote that previous trapped-ion estimates for the same problem required between 1.2 million and 9.4 million physical qubits. Google Quantum AI’s March 2026 estimate put the attack at fewer than 500,000 superconducting qubits with a runtime of 18 to 23 minutes at a $10^{-3}$ error rate, and a March 2026 paper from Oratomic and Caltech put a comparable attack on the P-256 curve at a few days on 26,000 neutral atoms.

Niccolo de Masi, IonQ’s CEO, said in the release that he had flagged in 2025 that the Q-Day horizon was moving from the 2030s into the 2020s, and that the company was on track to produce a fault-tolerant 10,000-physical-qubit system in 2027. Chris Ballance, IonQ’s president of quantum computing, said the paper proved rather than assumed a lower bound on the probability that the full computation succeeds. Martin Roetteler, IonQ’s vice president of quantum applications R&D and a co-author, said a computation that once demanded millions of physical qubits now fits on a 20,000-qubit machine on the company’s roadmap.

IonQ said it had shared advance copies with U.S. government and industry partners before publication and that it was withholding the specific circuits, following the practice of comparable recent work (not that the recent approach to hold back information worked that well). The company said the exposure concerns authentication and integrity rather than confidentiality, and that ML-DSA (CRYSTALS-Dilithium) and SLH-DSA (SPHINCS+) are unaffected by this class of result.

IonQ’s published roadmap targets 10,000 physical qubits in 2027 and 20,000 in 2028 with 1,600 logical qubits. The company’s June 2025 roadmap announcement described the 2028 system as two chips connected to each other, and the current roadmap table lists a photonic interconnect from 2029. In a separate release on Tuesday the company said its Superion 256 system, a 256-qubit platform using electronic qubit control on chips fabricated at its SkyWater subsidiary, is available to order with customer deliveries in 2027, and that the follow-on Superion 10K is expected to reach fault tolerance in a laboratory setting in 2027 and commercial availability in 2028. IonQ’s current commercial generation, Tempo, is a 100-qubit-class system, and the roadmap’s 2026 band is 100 to 256 physical qubits. IonQ’s shares rose about 7% during the day on the combined announcements, and within hours the estimate was circulating in trade and financial outlets under headlines about a quantum computer breaking Bitcoin in 26 days.

My Analysis

By mid-afternoon the story had a headline, and it was not the paper’s title. The Quantum Insider ran the 26-day figure as a machine that could break Bitcoin’s curve. Investing.com’s AI-assisted item had it breaking “Bitcoin encryption,” and StockTitan reprinted the release as a future quantum computer breaking Bitcoin’s signature code. Quantum Zeitgeist asked “26 days to break Bitcoin?” in its headline, told readers the calculation was not theoretical, and moved a threat it had placed in the 2030s forward. It also called the paper peer-reviewed; no journal or review record exists for it, IonQ published it on its own website, and it was not on arXiv when I checked. Every reprint carried IonQ’s line that the hardware matches its roadmap for around 2028, and by evening the question in my inbox was whether Bitcoin breaks in 2028. Here is what the paper says. A machine of 19,397 ions that nobody has built would need 25.7 days per attempt to recover one secp256k1 key, succeeding 41% or 63% of the time depending on which of the paper’s two estimates you take, at error rates IonQ has demonstrated on two ions. IonQ’s own 2028 roadmap entry promises logical error below $10^{-7}$ and does not say what that figure measures; the memory blocks in this design are modeled at $10^{-11}$ per cycle and its factory below $10^{-9}$ per state. IonQ has promised $10^{-7}$ on that line and has not promised $10^{-11}$, so on the roadmap as written the company has not committed to what this design requires. Nothing was broken today, on any chain.

In 2017, Martin Roetteler, Michael Naehrig, Krysta Svore and Kristin Lauter published the reference cost of a quantum attack on a 256-bit elliptic curve: 2,330 logical qubits and roughly $1.3 \times 10^{11}$ Toffoli gates, on no particular machine. Nine years later Roetteler and Naehrig, with Thomas Häner from the 2020 follow-up, sign a paper at a hardware company that prices the same attack at 1,457 logical qubits and 39 million Toffolis, on a named machine of 19,397 ions, with a runtime in days. I have argued since my analysis of why ECC is the easiest quantum target that the curves were underexplored next to factoring and that their cost would fall in a rush once anyone looked. The rush arrived in March. This paper is the first I have read that prices the attack for one modality down to the individual ion.

A 20,000-ion machine that IonQ hasn’t built would need about a month per attempt against secp256k1, and longer per key, if every number in the model is right. The error rates in the model are the ones IonQ’s labs have shown on two ions. The algorithmic side of the ECC attack is now within a factor of a few of the data-register floor I described in June, and most of the uncertainty that remains is in hardware that IonQ says it will ship in 2028.

I’ll take the paper and the press release separately.

What the Paper Adds to a Crowded Year

The ECDLP-256 literature has produced a paper a month since March. Babbush et al. at Google cut the logical cost to 1,200 or 1,450 qubits, depending on the gate budget, and withheld the circuits behind a zero-knowledge proof, which I covered in March. Schrottenloher published matching circuits in the open in June. Luo et al. reached 835 logical qubits in July with a deterministic circuit that pays for its width in gates. The ecdsa.fail leaderboard has been grinding the constants in public since. Schrottenloher’s and Luo’s results are logical-level numbers, qubits and Toffolis with no machine attached. Google attached a surface-code superconducting machine to its numbers, down to a physical-qubit count and a runtime, and Cain et al. at Oratomic attached neutral atoms under what they called plausible assumptions. In June I described the ECC attack as two curves, an algorithmic requirement falling toward the two-coordinate register floor near 500 logical qubits and a hardware capability still climbing, with a CRQC existing the moment they cross. This paper moves the first curve a little, the 58-to-39-million Toffoli cut at nearly unchanged width, and then does something the others didn’t: it prices the second curve for a trapped-ion machine at the level of individual measurement layers.

“Fully compiled” has a concrete meaning here. Every adder, multiplier and lookup was lowered to a schedule of logical measurements that a Walking Cat device could execute as written, with the cross-block routing merged into the components rather than estimated afterwards. The count came to 75.25 million measurement layers, 40.4 million Toffoli-state injections and 369.9 million other logical measurements, with several measurements sharing a layer wherever the schedule allows. The compiled circuits always execute their conditional phase comparators, and the count includes the initial table lookup. The phase-fix lookup they use is also less efficient. Those three, the paper says in its appendix, put 40.4 million injections above a logical Toffoli count of 39 million. The physical gates, transport and readout beneath the measurements come from the architecture’s timing model rather than from an enumerated pulse sequence. Earlier estimates charged the Toffolis and abstracted the remainder, and the authors name what that omits. Half the cost of a Gidney adder is the measurement-based uncomputation of its temporary ANDs, which a Toffoli count never sees. The syndrome-extraction time comes from the circuit itself, 27 operation cycles for the memory code, where previous estimates assumed a flat millisecond for any code. Transport, loss, leakage and ion reloading are all in the model. Within that model the authors erred toward the pessimistic end: every layer is charged as a full Toffoli injection, and the memory-failure bound treats all 69 memory blocks as holding data for the entire 26 days, which they don’t.

The architecture had to change to get there. The general-purpose Walking Cat design that I wrote up in April would have taken at least 411 days on this problem, by the authors’ own arithmetic. Its T-state factories produced states at a logical error rate of $7 \times 10^{-8}$, too noisy for the 273 million T states a seven-T Toffoli decomposition would consume, and each injection cost a logical measurement of about 40 milliseconds. The secp256k1 device replaces that with a two-level magic-state factory that produces CCZ states directly in a new [[66, 4, 10]] code at an error rate below $10^{-9}$. Each factory takes about 111 milliseconds per accepted state, so four of them together supply one about every 28 milliseconds, ahead of the 29.5-millisecond injection that consumes them. The device adds a depth-one injection circuit, parallel cat-state measurements on disjoint operators, and a pipelined version of the logical CliNR scheme from Webster and Delfosse’s July paper that needs four extra code blocks instead of two per memory block, 138 in all. The Toffoli time fell from 910 milliseconds to 29.5, a factor of 31, and all of it came from the architecture rather than the circuit. The authors named the factory “Eastinthillation,” a splice of Bryan Eastin’s 2013 Toffoli-state distillation protocol with the “synthillation” of Campbell and Howard, and note that the informal name “East Mode” may appear in fan-made songs about the paper. Fourteen authors put that joke in a 70-page resource estimate.

The paper claims the first ECDLP architecture for trapped ions built on quantum LDPC codes. The press release claims the first complete, end-to-end fault-tolerant resource estimate for running Shor’s algorithm at all. Craig Gidney’s May 2025 RSA-2048 paper compiled to surface-code operations with magic-state cultivation, and Webster et al.’s Pinnacle architecture did the same on qLDPC codes for RSA-2048 at 100,000 qubits. Neither charged every Clifford and measurement on a compiled schedule with transport included, and on that narrow reading IonQ can claim a first in accounting depth. The paper’s own sentence is the defensible one. The 20,000-qubit figure is not new territory either. Cain et al. put the neutral-atom floor at 10,000 and the P-256 attack at 26,000 atoms in a few days back in March.

The Ledger of Assumptions

Every number in the paper descends from a short list of inputs.

The two-qubit gate error is $10^{-4}$. The citation is the October 2025 result from Oxford Ionics, now IonQ, in which Amy Hughes and colleagues measured $8.4 \times 10^{-5}$ on an electronically controlled gate between two ions without ground-state cooling. Single-qubit errors are $10^{-5}$. Ion loss is set at one thousandth of the gate error per operation cycle and leakage at one tenth, ratios carried over from the Walking Cat paper. The operation cycle is 200 microseconds, with a transport step at one twentieth of that. The loss model changed between the two papers. In the April paper a lost ion ejects its partner when their wells merge. Here the well is deep enough to keep the heated ion in place with its position randomized. The authors flag that as still simplified: the physical situation, they write, is more nuanced, and they leave it to future work. The memory code’s logical error rate, $9.34 \times 10^{-12}$ per extraction cycle, was not simulated at $10^{-4}$. Direct simulation there would take too many shots, so the authors fit a $p^5$ ansatz to data taken at physical error rates from $5 \times 10^{-4}$ to $2 \times 10^{-3}$ and read the value off the fit. By that fit, the lowest simulated point is near $6 \times 10^{-8}$, so the design operates about four orders of magnitude below the lowest directly simulated point, and no Q102 block has been measured on hardware at any error rate. That is standard practice in this literature, and it is also where the 26% comes from.

Memory failure is the largest term in that 26%, at 23.3%. I ran the paper’s own fitted curve at slightly worse physical error rates. At $1.5 \times 10^{-4}$, the same conservative bound puts memory failure alone at 89%. At $2 \times 10^{-4}$ the paper’s own conservative bound puts failure at effectively 100%. The authors say the same thing in their own words, that the bound is conservative and that a higher code distance or a tuned decoder can bring it down; the higher distance costs qubits the 19,397 does not include. So the 19,397 is the count at the model’s $10^{-4}$ two-qubit error, with the single-qubit, loss and leakage rates tied to it, sustained across the device for 26 days. The 26% total also multiplies five failure mechanisms as if they were independent; correlated errors and drift across 26 days are not in that arithmetic. The October measurement was two ions. This is below-threshold operation at scale, the capability I score hardest in my framework, and the paper leaves it exactly where the April paper left it.

The 200-microsecond cycle is the one number that turns 75 million layers into 26 days. A cycle twice as slow is 51 days. The $8.4 \times 10^{-5}$ gate the paper cites runs longer than 200 microseconds on the ramp timings in its own experimental section, so the cycle assumes a faster gate than the one it cites for its error rate. I don’t know what a 20,000-ion Superion cycle will take once transport, cooling and readout are all in the loop. Nobody outside IonQ does either.

Twenty-Six Days Is per Attempt

The 25.7 days is one run, which the paper’s model succeeds 63.3% of the time on the heuristic estimate and 40.7% on the rigorous one. Both figures multiply an algorithmic success figure by the 73.5% survival the paper’s hardware model allows, so the rigorous one depends on the same assumed error rates as the heuristic one. The expected time to one key is therefore about 41 days on the heuristic and up to about 63 days on the bound. The paper’s alternative is five devices in parallel, roughly 97,000 ions, for a 99.3% chance within one attempt’s wall-clock time on the heuristic figure and 92.7% on the rigorous one. Any of those framings is defensible. The release’s bullet list does say per attempt. Its opening sentence, the one the headlines copied, says the machine is expected to break secp256k1 in just under 26 days, and IonQ’s own post on X hedged that further with “once developed” and “expected to be able to.” The social team hedged; the wire copy didn’t.

Set the three machines side by side. Google’s design uses fewer than 500,000 superconducting qubits at $10^{-3}$ error rates and finishes in 18 to 23 minutes, or nine to twelve from a primed state, depending on the circuit. Oratomic’s uses 26,000 atoms for P-256 in days. IonQ’s uses 19,397 ions at $10^{-4}$ and takes weeks. Measured in qubit-days at Google’s 500,000-qubit ceiling, IonQ’s design is 60 to 80 times larger, on about a twenty-fifth of the qubits. Google’s authors sorted the field into fast-clock and slow-clock architectures and wrote that they don’t expect slow-clock machines, ion traps among them, to mount the minutes-scale attack. IonQ’s design is a slow-clock machine in exactly that sense, and its numbers match the description. In June I wrote that a leaner attack circuit folds the same computation narrower and longer, and that the fold moves the burden onto continuous operation and real-time decoding, the two capabilities furthest from demonstration. This design is that fold, executed deliberately for a platform with slow gates and few qubits.

Twenty-six days per key also changes who is exposed. The minutes-scale superconducting estimate made the mempool attack thinkable, the theft of a key between the moment a transaction reveals its public key and the moment the block confirms. A machine that needs a month per key cannot do that against a ten-minute block interval. What it can do is target any secp256k1 key whose public half has been visible for weeks: Bitcoin’s pay-to-public-key outputs, Taproot outputs, any address whose key an earlier spend revealed, and every externally owned Ethereum account that has sent a transaction. Google’s paper puts the pay-to-public-key total at over 1.7 million BTC, and Taproot outputs expose a tweaked public key by design. Certificate-authority roots, code-signing and firmware keys and SSH host keys mostly do not use secp256k1. The same mathematics exposes them on their own curves; the only architecture-level estimate for another curve, Cain et al.’s for P-256, is nowhere near this depth. This is the Trust Now, Forge Later (TNFL) exposure I first described as Sign Today, Forge Tomorrow in 2018, and IonQ’s release gets the category right for signatures: integrity rather than confidentiality, exploitable forward and not against recorded traffic. It stops one step short. A public key on a blockchain or in a certificate is harvested today, and the forgery is dated later. And a discrete-log solver on a curve recovers ECDH secrets from recorded key exchanges on that curve as readily as it recovers signing keys, so the confidentiality side is not zero; it is just not this paper’s application. For the digital-asset side I keep a standing analysis of which outputs are exposed and why.

One more limit on the number. The 39 million Toffolis use the shape of secp256k1’s prime, $2^{256} – 2^{32} – 977$, in the modular squarer and the reductions. Schrottenloher’s generic prime-field circuit costs 84 million Toffolis against 58 million for secp256k1 at the same 1,462-qubit width, and the IonQ runtime is 61% in-place multiplication and about a third table lookups, both of which scale with that arithmetic. P-256, the NIST curve behind ECDSA in the web PKI and much of TLS key agreement, has a differently shaped prime, and this paper supplies no estimate for it. The nearest thing is Cain et al.’s P-256 estimate, at a fraction of this depth; for Ed25519 I know of nothing. A headline about “256-bit elliptic-curve signatures” covers secp256k1 only.

The Machine on the Slide and the Machine in the Paper

The roadmap’s 2028 entry is 20,000 physical qubits and 1,600 logical qubits. When IonQ announced that roadmap in June 2025, it described the 2028 system as two interconnected 10,000-qubit chips; the current table lists a photonic interconnect from 2029, and the roadmap page says IonQ scales by connecting smaller systems rather than building monolithic ones. Superion 10K, the nearest product on the roadmap to this device, reaches fault tolerance in the lab in 2027 and commercial availability in 2028 on Ballance’s account, and IonQ has not said which product would run this computation.

The device in the paper is one contiguous grid. It packs the 69 memory blocks and the four frame-clearing blocks into a nine-by-nine array, with four factories along the top edge and a loading reservoir down the right side, and cat states walk between blocks at 10-microsecond transport steps. The word “photonic” appears once in the paper, inside a 2014 citation. The model has no inter-module boundary in it. If the 2028 machine is modular, as IonQ’s roadmap language says its machines will be, then cat states and logical qubits have to cross whatever joins the modules. Nothing in the paper prices that crossing, and a photonic link in particular is not a 10-microsecond transport step. I’d like IonQ to say how the modules connect and what the crossing costs in this model. Engineering scale and manufacturability is where SkyWater and electronic qubit control could change the trapped-ion story, and it is also where this paper says nothing.

The list of things nobody has demonstrated is short and specific. IonQ has run qLDPC codes on ions: in June, on a stationary chain of 40 barium ions with no transport, it reached breakeven with five qLDPC codes of up to 30 physical qubits, the best of them at a logical error rate near 1% per logical qubit per cycle, with detected leakage post-selected away. The Q102 block in this design is modeled at $9.34 \times 10^{-12}$ per cycle with transport included. The June measurement and the Q102 model differ in both code and quantity, and the distance between them, at face value, is still nine orders of magnitude, with no block of the Q102 class run anywhere. Quantinuum’s Helios, at 98 ions, is the largest QCCD device I know of in operation. The $8.4 \times 10^{-5}$ gate was measured on two ions, and transport-included error rates at thousands of ions have not been published by anyone. A 26-day run needs 69 memory blocks decoded in real time for the entire period, plus twelve factory and four frame-clearing blocks whenever they hold encoded states, with about ten ions per second reloaded from the reservoir. The April paper reported mean decoding and reaction times below a millisecond for Q102 in a sliding-window decoder, against a 5.4-millisecond extraction cycle; this paper doesn’t repeat that exercise under its new loss model, across every block at once, for 26 days. Against my CRQC Quantum Capability Framework, this is the strongest public entry I’ve seen for full fault-tolerant algorithm integration on any modality, and it moves nothing, in demonstrated terms, on below-threshold scaling, decoder performance, continuous operation or manufacturability. Score it on algorithm integration alone; the paper reports no hardware result for the other capabilities.

Investor Day and the Two Fronts

The press release calls the paper historic, the world’s first, and says the machine is expected to break secp256k1. De Masi says he flagged in 2025 that Q-Day was moving into the 2020s and that enterprises and the U.S. government now concur, and points to the White House’s action on quantum security, Executive Order 14412 of 22 June, without naming it, an order that sets migration deadlines and no Q-Day date. The same morning IonQ launched Superion, raised its 2026 revenue guidance to between $450 million and $460 million after the SkyWater acquisition, and announced an $8.18 million quantum-security contract with Congruity360.

Two wrong readings follow from that context, and I fight both on this site. The Q-FUD reading is that Bitcoin is broken in 2028. The denialist reading is that this is stock promotion and can be ignored. To my thinking the paper is the most careful public accounting of a Shor run on any hardware platform. The press release is an investor-day wrapper. It reads a design with a 41-to-63% per-attempt success estimate, at a physical error rate demonstrated on two ions, as “expected to break.” Both halves are true at once, and readers who want one without the other will be wrong about something.

I have read enough IonQ releases to know the house style, and this one is a good specimen. The paper is historic, twice. The estimate is the world’s first in the headline and the first complete one in the lead. IonQ’s approach is superior and the company uniquely positioned. The subhead says the Q-Day timeline accelerates, which a resource estimate for a machine that does not exist cannot do. Ballance’s quote assures readers that no deployed digital asset or crypto platform was affected during the research, which is true of every paper ever written. The paper, by contrast, says “per attempt” in its results section and “we expect future work to improve” in its conclusion. The company’s own explainer is better than the release on the large question, stating in bold that no machine capable of running the attack exists, and worse on the small ones. Its FAQ describes a system with a “29.5-millisecond measured error-correction cycle time.” In the paper, 29.5 milliseconds is the estimated injection interval and 5.4 milliseconds is the extraction cycle, neither of them measured. It also says the methodology generalizes directly to RSA-2048 and to the curves in TLS, for which the paper supplies no numbers. I’ve been through this before. In May the Q1 earnings call’s “logical qubit count required to challenge RSA-2048” by 2028 or 2029 had become Q-Day-by-2028 by the time it reached my inbox, and I wrote up the gap. In April IonQ’s blog called the Walking Cat paper the blueprint the company would use to build the fault-tolerant era, while the paper’s own Shor demonstration was a compile of period-finding for an integer any laptop factors instantly. IonQ’s papers are careful and its press releases are not, and the trade coverage reprints the wire copy.

The withheld circuits are the part of the wrapper I’d push back on hardest. IonQ cites the practice of comparable recent work, which is Google’s. That secret lasted 63 days: Schrottenloher then published independently built circuits with matching costs, and Gidney wrote on his blog that releasing them openly would have been better. Of every number in this paper, the 39 million is the one that needs no IonQ hardware to check. It is also the one nobody outside IonQ can currently rerun, because the compilation pipeline that produced it is internal and the circuits are withheld. The ecdsa.fail verifier checks the point-addition primitive that this whole estimate is built from. IonQ should publish the circuits or submit them.

What I Would Do With the Number

For a CISO the paper changes one sequencing decision. Signatures have been scheduled last in many migration plans, the federal one included; the usual reasoning is that roots of trust are the slowest thing to replace, so their deadline is set last. Google’s and Oratomic’s March papers both priced a 256-bit-curve attack well below an RSA-2048 attack under their own hardware assumptions, this paper adds the trapped-ion compile, and the non-RSA signature schemes in wide deployment, ECDSA and EdDSA, run on curves. ML-DSA (CRYSTALS-Dilithium) and SLH-DSA (SPHINCS+) are standardized; a CISO’s remaining work is inventory, replacement lead time and trust anchors. Certificate-authority roots, firmware-signing keys and code-signing infrastructure have replacement tails measured in years. Start them.

The deadlines are already set. Executive Order 14412 directs guidance giving agencies until the end of 2030 to move key establishment on their high-value and high-impact systems to PQC, national-security systems excluded, and until the end of 2031 for digital signatures, and directs the FAR Council to propose a rule holding covered contractors to 31 December 2030. NSA’s CNSA 2.0 requires its algorithms in new national-security-system acquisitions from 1 January 2027 and mandates them by the end of 2031, and its current FAQ singles out firmware roots of trust as the most urgent case because their verification code is locked in for the life of a system. For those systems the approved signature options are ML-DSA-87, plus the stateful hash-based LMS and XMSS for firmware and software signing; SLH-DSA is not approved for national-security use. Boards fund obligations, and every one of those dates was fixed before IonQ published. What the paper removes is the excuse for leaving signatures until last.

Five things will tell me whether the ledger is closing:

  1. Independent review of the circuit and factory claims by the people who built the prior estimates, Gidney, Schrottenloher and Ekerå among them. An arXiv posting would help; it is not the review.
  2. A Q102-class qLDPC memory block on trapped-ion hardware, with transport, at a per-cycle logical error rate within sight of the $10^{-11}$ the authors assume.
  3. Gate and transport error rates from a Superion 10K prototype at thousands of ions, with loss and leakage reported, and a decoder keeping pace across every block at once.
  4. A compiled estimate for P-256 at the same depth.
  5. IonQ publishes the point-addition circuits for secp256k1, or runs them through the ecdsa.fail verifier.

In 2017 the cost of this attack was a formula. In 2026 it is a floor plan with an assumption ledger. I’ll check that ledger, not the qubit count, against every IonQ hardware paper between now and 2028.

The post appeared first on PostQuantum - Quantum Computing, Quantum Security, PQC.

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论