Skip to the page
Big Numbers, Split

The ledger to 2026-09-23Now

40 dated rows since 2024, newest first, each with what happened and what it does not mean. Kept by hand from the sources; a row resting on a single secondary source is marked.

40 rows
datewhowhat happenedwhat it does not mean
2026-09-19Stephen Weis, AnthropicRSA-896 (896 bits, 270 digits) factored with a GPU port of CADO-NFS, run as a low-priority job on up to 2,048 idle GPUs for ten days — about 30 GPU-years.Weis: no improvement to the number field sieve's running time and no effect on deployed RSA-2048; it does put RSA-1024 within reach of anyone with a data-centre GPU fleet. [101]
2026-09-04IonQ — Häner and thirteen othersA blueprint: a 256-bit curve key in 25.7 days on 19,397 trapped-ion qubits (about 1,457 logical), 40 million Toffoli gates, 63% success.A design on paper; IonQ's largest machine is 256 qubits. [100]
2026-09-03Eric Lu, CognitionRSA-260 (862 bits) factored: CADO-NFS ported to GPUs with coding agents, 4,923 GPU-days on B200-class parts, about sixteen days elapsed.Lu: 'essentially no algorithmic advancements'. The sieve is the same; 2048 bits is not structurally closer. [99]
2026-09Wikipedia's records pageStates that 2^1277 − 1 (1,277 bits) was factored by the special number field sieve in September 2026. unconfirmedNo announcement found on the usual lists; unverified. [102]
2026-08-27Jonas Nick and Mikhail Kudinov, BlockstreamSHRINCS: a SHA-256-based post-quantum signature of about 324 bytes, sized so Bitcoin's throughput survives; demonstrated on Liquid in March.Security proof pending, no audit, needs a soft fork. [114]
2026-06-22The White House — Executive Order 14412Federal high-value systems to move key establishment to post-quantum by end of 2030 and signatures by end of 2031.Applies to federal systems; says nothing new about machines. [98]
2026-06-13Coinbase's advisory boardAbout 7 million BTC exposed: 1.7 million in some 20,000 legacy P2PK addresses, about 5 million by address reuse, some in exchange cold wallets.Same doors, counted a third way. [107]
2026-05-22Glassnode6.04 million BTC (30.2%) with the spending key visible: 1.92 million structural (P2PK, Taproot), 4.12 million from address reuse, of which 1.66 million belongs to exchanges.Visible is not stolen; the count is of doors, not of thieves. [106]
2026-05-05Xue and CoveyShor's algorithm compiled across a modular half-million-atom machine with 16% overhead against one module.An architecture study; no such machine. [97]
2026-04-24Project Eleven; Giancarlo LelliThe Q-Day Prize awarded for a 15-bit curve key on IBM Heron processors.Bitcoin developers reproduced the result from random bits within a day; Project Eleven's CEO agreed it 'is not Q-Day'. [96]
2026-04-16BitMEX ResearchA 'quantum canary': coins in an address only a quantum machine could open; a spend from it proves the capability and triggers restrictions on old wallets automatically.Critics: the first attacker may steal quietly rather than ring the bell. [113]
2026-04-13Q-CTRL — Mundada and othersRSA-2048 in 9.2 days with 381,000 physical qubits by parking idle logical qubits in slower memory.Compiler accounting on assumed hardware; the '138×' headline is against a different baseline than Gidney 2025. [94]
2026-03-31Caltech and OratomicA neutral-atom machine of 10,000–26,000 physical qubits could break a 256-bit curve key, at about ten days per key.Atoms are a thousand times slower per step than superconducting qubits; days, not minutes. [93]
2026-03-30Babbush, Zalcman, Gidney, Broughton, Khattar, Neven, Bergamaschi, Drake, BonehA 256-bit curve key with under 1,450 logical qubits, 70–90 million Toffoli gates, fewer than 500,000 physical superconducting qubits, in 18–23 minutes — a twentyfold cut. Fast-clock machines could work inside Bitcoin's ten-minute block; ion and atom machines could not.A cost model; no such machine exists. Google withheld the circuits and published a zero-knowledge proof of their correctness instead. [91]
2026-03-25Google — Adkins and SchmiegGoogle will finish its own post-quantum migration by 2029, a year ahead of NIST's deprecation, citing hardware, error correction and the new resource estimates; Android 17 ships ML-DSA.A migration deadline, not a claim that RSA falls in 2029. [90]
2026-03-09Global Risk Institute — Mosca and PianiThe 2025 expert survey: 26 experts put the chance of a 24-hour RSA-2048 break within ten years at 28–49%, the highest in the series; 92% give it even odds within twenty.Opinions of experts, weighted by how they were asked; not a date. [119]
2026-02-12Iceberg Quantum (Webster and others)'Pinnacle': RSA-2048 with fewer than 100,000 physical qubits on qLDPC codes, about 22,000 at 0.01% error.Needs long-range connectivity and real-time decoding nobody has built; Aaronson: timeline effect unknown. [88]
2026-02-11BIP 360 and BIP 361BIP 360 becomes Pay-to-Merkle-Root (P2MR, addresses bc1z): Taproot's script tree with the key path removed. BIP 361 is Lopp's sunset schedule, numbered and merged as a draft in April.Both are drafts; neither has an activation path. [109]
2026-02-09CoinSharesAbout 1.6 million BTC in exposed P2PK outputs, over 32,000 outputs of about 50 BTC each; the threat put at least a decade out.Counts only P2PK; reused addresses add millions more. [105]
2026-01-23CoinbaseAn independent advisory board on quantum risk: Aaronson, Boneh, Drake, Kannan, Lindell, Malkhi.A board; its April paper says the threat is 'on the horizon' and blockchains are safe today. [108]
2025-11-12IBMNighthawk (120 qubits) and the experimental Loon chip with the long-range couplers qLDPC codes need.Physical-qubit devices; no logical factoring demonstration. [87]
2025-11-05QuantinuumHelios: 98 trapped-ion qubits, 48 error-corrected logical qubits, two-qubit fidelity 99.92%.48 logical qubits is a few percent of a key-breaking budget, and the runs are shallow. [86]
2025-07-13Jameson Lopp, on the bitcoindev listA migration proposal: three years after a post-quantum output type exists, stop sending to legacy scripts; two years after that, stop accepting old signatures — freezing coins that did not move.A draft for discussion; no activation path. [110]
2025-07-11Steve TippeconnicA 5-bit elliptic-curve key recovered with a Shor-style circuit on IBM's 133-qubit machine.A 32-element group; a pencil does it faster. [85]
2025-06-10IBMRoadmap to Starling in 2029: 200 logical qubits and 100 million gates on qLDPC codes, via Loon (2025), Kookaburra (2026), Cockatoo (2027).Starling as described would still be below every published RSA-2048 budget. [84]
2025-05-21Craig GidneyRSA-2048 with fewer than a million noisy qubits in under a week — a twentyfold drop from the 2019 figure, from better arithmetic, 'yoked' surface codes and cheaper magic states.Assumes 0.1% error and a microsecond cycle; the biggest machines have a hundred to a thousand qubits. [58]
2025-05-09BlackRockThe iShares Bitcoin Trust prospectus adds that advances in quantum computing could undermine Bitcoin's cryptography and that any fix needs broad network consensus.Standard risk disclosure, as Bloomberg's ETF analyst said at the time. [120]
2025-05Chaincode Labs — Milton and ShikhelmanThe Bitcoin report: about 6.26 million BTC (roughly 30%) sits in outputs whose public key is already visible; migrating every coin would take about 76 days of full blocks at best.A count of exposed keys, not of coins at risk today: no machine can use them yet. [104]
2025-04-16Project ElevenThe Q-Day Prize: one bitcoin for the largest elliptic-curve key broken with Shor's algorithm on real hardware by 5 April 2026.Toy keys of 1 to 25 bits; a yardstick for hardware, not a measure of wallet risk. [83]
2025-04Wang Chao's group, via the South China Morning PostA 90-bit RSA integer reported factored on a D-Wave machine. unconfirmedNo paper found; 90 bits is far below the 896-bit classical record. [82]
2025-03-11NISTHQC chosen as a fifth post-quantum algorithm, a backup to ML-KEM built on different mathematics.Insurance against a lattice break, not a reaction to any factoring result. [81]
2025-02-19MicrosoftMajorana 1 announced as an eight-qubit topological processor.Nature's own editorial note said the paper does not show the topological states claimed; no error-corrected computation was shown. [80]
2024-12-30Wang Chao and others'A first successful factorization of RSA-2048 integer by D-Wave quantum computer', on 'a class of special integers'.The two primes differ in two low bits; Fermat's method from 1643 splits every such number in milliseconds. Not an RSA key. [78]
2024-12-09Google Quantum AIWillow, 105 qubits: the first chip clearly below the error-correction threshold — logical error falls by about 2.1× each time the code grows a step, up to distance 7.One logical memory qubit, no logical gates; the 'ten septillion years' line is a sampling benchmark with nothing to do with factoring. [62]
2024-11-12NISTDraft IR 8547: RSA-2048 and 256-bit curves deprecated after 2030, all quantum-vulnerable public-key algorithms disallowed after 2035.A policy calendar, not a forecast of when a machine arrives; still a draft in September 2026. [64]
2024-09-10Microsoft and QuantinuumTwelve logical qubits on the 56-qubit H2 trapped-ion machine, with a 22-fold drop in circuit error against raw qubits.Twelve; a key break needs over a thousand, running billions of gates. [79]
2024-08-13NISTFIPS 203 (ML-KEM), 204 (ML-DSA) and 205 (SLH-DSA): the first final post-quantum standards.New locks on the shelf; nothing yet says when to take the old ones off. [63]
2024-05-31Guth and MaynardThe first improvement since Ingham (1940) on how many zeta zeros can lie off the critical line in a range; published in the Annals in 2026.Progress on the Riemann Hypothesis, not a proof; no bearing on factoring. [39]
2024-05Wang Chao and others, Shanghai UniversityA 22-bit RSA integer factored on a D-Wave annealer; in October the story runs worldwide as 'China breaks military-grade encryption'.22 bits against 2048; annealing has no known scaling advantage; no key in use was affected. [77]
2024-02Chevignard, Fouque, SchrottenloherRSA-2048 with about 1,730 logical qubits by approximate residue arithmetic — a third of the usual count, at the price of about a thousand times more gates.Fewer qubits, far more time; a trade, not a shortcut. [76]

This week's feed fetched 2026-09-23, unread by a person

A GitHub Action fetches these every Monday from arXiv and a few public feeds and rebuilds the page. Titles as published. Nothing here has been checked; the ledger above has.

Papers

News