The ledger to 2026-09-23Now
40 dated rows since 2024, newest first, each with what happened and what it does not mean. Kept by hand from the sources; a row resting on a single secondary source is marked.
40 rows
| date | who | what happened | what it does not mean |
|---|---|---|---|
| 2026-09-19 | Stephen Weis, Anthropic | RSA-896 (896 bits, 270 digits) factored with a GPU port of CADO-NFS, run as a low-priority job on up to 2,048 idle GPUs for ten days — about 30 GPU-years. | Weis: no improvement to the number field sieve's running time and no effect on deployed RSA-2048; it does put RSA-1024 within reach of anyone with a data-centre GPU fleet. [101] |
| 2026-09-04 | IonQ — Häner and thirteen others | A blueprint: a 256-bit curve key in 25.7 days on 19,397 trapped-ion qubits (about 1,457 logical), 40 million Toffoli gates, 63% success. | A design on paper; IonQ's largest machine is 256 qubits. [100] |
| 2026-09-03 | Eric Lu, Cognition | RSA-260 (862 bits) factored: CADO-NFS ported to GPUs with coding agents, 4,923 GPU-days on B200-class parts, about sixteen days elapsed. | Lu: 'essentially no algorithmic advancements'. The sieve is the same; 2048 bits is not structurally closer. [99] |
| 2026-09 | Wikipedia's records page | States that 2^1277 − 1 (1,277 bits) was factored by the special number field sieve in September 2026. unconfirmed | No announcement found on the usual lists; unverified. [102] |
| 2026-08-27 | Jonas Nick and Mikhail Kudinov, Blockstream | SHRINCS: a SHA-256-based post-quantum signature of about 324 bytes, sized so Bitcoin's throughput survives; demonstrated on Liquid in March. | Security proof pending, no audit, needs a soft fork. [114] |
| 2026-06-22 | The White House — Executive Order 14412 | Federal high-value systems to move key establishment to post-quantum by end of 2030 and signatures by end of 2031. | Applies to federal systems; says nothing new about machines. [98] |
| 2026-06-13 | Coinbase's advisory board | About 7 million BTC exposed: 1.7 million in some 20,000 legacy P2PK addresses, about 5 million by address reuse, some in exchange cold wallets. | Same doors, counted a third way. [107] |
| 2026-05-22 | Glassnode | 6.04 million BTC (30.2%) with the spending key visible: 1.92 million structural (P2PK, Taproot), 4.12 million from address reuse, of which 1.66 million belongs to exchanges. | Visible is not stolen; the count is of doors, not of thieves. [106] |
| 2026-05-05 | Xue and Covey | Shor's algorithm compiled across a modular half-million-atom machine with 16% overhead against one module. | An architecture study; no such machine. [97] |
| 2026-04-24 | Project Eleven; Giancarlo Lelli | The Q-Day Prize awarded for a 15-bit curve key on IBM Heron processors. | Bitcoin developers reproduced the result from random bits within a day; Project Eleven's CEO agreed it 'is not Q-Day'. [96] |
| 2026-04-16 | BitMEX Research | A 'quantum canary': coins in an address only a quantum machine could open; a spend from it proves the capability and triggers restrictions on old wallets automatically. | Critics: the first attacker may steal quietly rather than ring the bell. [113] |
| 2026-04-13 | Q-CTRL — Mundada and others | RSA-2048 in 9.2 days with 381,000 physical qubits by parking idle logical qubits in slower memory. | Compiler accounting on assumed hardware; the '138×' headline is against a different baseline than Gidney 2025. [94] |
| 2026-03-31 | Caltech and Oratomic | A neutral-atom machine of 10,000–26,000 physical qubits could break a 256-bit curve key, at about ten days per key. | Atoms are a thousand times slower per step than superconducting qubits; days, not minutes. [93] |
| 2026-03-30 | Babbush, Zalcman, Gidney, Broughton, Khattar, Neven, Bergamaschi, Drake, Boneh | A 256-bit curve key with under 1,450 logical qubits, 70–90 million Toffoli gates, fewer than 500,000 physical superconducting qubits, in 18–23 minutes — a twentyfold cut. Fast-clock machines could work inside Bitcoin's ten-minute block; ion and atom machines could not. | A cost model; no such machine exists. Google withheld the circuits and published a zero-knowledge proof of their correctness instead. [91] |
| 2026-03-25 | Google — Adkins and Schmieg | Google will finish its own post-quantum migration by 2029, a year ahead of NIST's deprecation, citing hardware, error correction and the new resource estimates; Android 17 ships ML-DSA. | A migration deadline, not a claim that RSA falls in 2029. [90] |
| 2026-03-09 | Global Risk Institute — Mosca and Piani | The 2025 expert survey: 26 experts put the chance of a 24-hour RSA-2048 break within ten years at 28–49%, the highest in the series; 92% give it even odds within twenty. | Opinions of experts, weighted by how they were asked; not a date. [119] |
| 2026-02-12 | Iceberg Quantum (Webster and others) | 'Pinnacle': RSA-2048 with fewer than 100,000 physical qubits on qLDPC codes, about 22,000 at 0.01% error. | Needs long-range connectivity and real-time decoding nobody has built; Aaronson: timeline effect unknown. [88] |
| 2026-02-11 | BIP 360 and BIP 361 | BIP 360 becomes Pay-to-Merkle-Root (P2MR, addresses bc1z): Taproot's script tree with the key path removed. BIP 361 is Lopp's sunset schedule, numbered and merged as a draft in April. | Both are drafts; neither has an activation path. [109] |
| 2026-02-09 | CoinShares | About 1.6 million BTC in exposed P2PK outputs, over 32,000 outputs of about 50 BTC each; the threat put at least a decade out. | Counts only P2PK; reused addresses add millions more. [105] |
| 2026-01-23 | Coinbase | An independent advisory board on quantum risk: Aaronson, Boneh, Drake, Kannan, Lindell, Malkhi. | A board; its April paper says the threat is 'on the horizon' and blockchains are safe today. [108] |
| 2025-11-12 | IBM | Nighthawk (120 qubits) and the experimental Loon chip with the long-range couplers qLDPC codes need. | Physical-qubit devices; no logical factoring demonstration. [87] |
| 2025-11-05 | Quantinuum | Helios: 98 trapped-ion qubits, 48 error-corrected logical qubits, two-qubit fidelity 99.92%. | 48 logical qubits is a few percent of a key-breaking budget, and the runs are shallow. [86] |
| 2025-07-13 | Jameson Lopp, on the bitcoindev list | A migration proposal: three years after a post-quantum output type exists, stop sending to legacy scripts; two years after that, stop accepting old signatures — freezing coins that did not move. | A draft for discussion; no activation path. [110] |
| 2025-07-11 | Steve Tippeconnic | A 5-bit elliptic-curve key recovered with a Shor-style circuit on IBM's 133-qubit machine. | A 32-element group; a pencil does it faster. [85] |
| 2025-06-10 | IBM | Roadmap to Starling in 2029: 200 logical qubits and 100 million gates on qLDPC codes, via Loon (2025), Kookaburra (2026), Cockatoo (2027). | Starling as described would still be below every published RSA-2048 budget. [84] |
| 2025-05-21 | Craig Gidney | RSA-2048 with fewer than a million noisy qubits in under a week — a twentyfold drop from the 2019 figure, from better arithmetic, 'yoked' surface codes and cheaper magic states. | Assumes 0.1% error and a microsecond cycle; the biggest machines have a hundred to a thousand qubits. [58] |
| 2025-05-09 | BlackRock | The iShares Bitcoin Trust prospectus adds that advances in quantum computing could undermine Bitcoin's cryptography and that any fix needs broad network consensus. | Standard risk disclosure, as Bloomberg's ETF analyst said at the time. [120] |
| 2025-05 | Chaincode Labs — Milton and Shikhelman | The Bitcoin report: about 6.26 million BTC (roughly 30%) sits in outputs whose public key is already visible; migrating every coin would take about 76 days of full blocks at best. | A count of exposed keys, not of coins at risk today: no machine can use them yet. [104] |
| 2025-04-16 | Project Eleven | The Q-Day Prize: one bitcoin for the largest elliptic-curve key broken with Shor's algorithm on real hardware by 5 April 2026. | Toy keys of 1 to 25 bits; a yardstick for hardware, not a measure of wallet risk. [83] |
| 2025-04 | Wang Chao's group, via the South China Morning Post | A 90-bit RSA integer reported factored on a D-Wave machine. unconfirmed | No paper found; 90 bits is far below the 896-bit classical record. [82] |
| 2025-03-11 | NIST | HQC chosen as a fifth post-quantum algorithm, a backup to ML-KEM built on different mathematics. | Insurance against a lattice break, not a reaction to any factoring result. [81] |
| 2025-02-19 | Microsoft | Majorana 1 announced as an eight-qubit topological processor. | Nature's own editorial note said the paper does not show the topological states claimed; no error-corrected computation was shown. [80] |
| 2024-12-30 | Wang Chao and others | 'A first successful factorization of RSA-2048 integer by D-Wave quantum computer', on 'a class of special integers'. | The two primes differ in two low bits; Fermat's method from 1643 splits every such number in milliseconds. Not an RSA key. [78] |
| 2024-12-09 | Google Quantum AI | Willow, 105 qubits: the first chip clearly below the error-correction threshold — logical error falls by about 2.1× each time the code grows a step, up to distance 7. | One logical memory qubit, no logical gates; the 'ten septillion years' line is a sampling benchmark with nothing to do with factoring. [62] |
| 2024-11-12 | NIST | Draft IR 8547: RSA-2048 and 256-bit curves deprecated after 2030, all quantum-vulnerable public-key algorithms disallowed after 2035. | A policy calendar, not a forecast of when a machine arrives; still a draft in September 2026. [64] |
| 2024-09-10 | Microsoft and Quantinuum | Twelve logical qubits on the 56-qubit H2 trapped-ion machine, with a 22-fold drop in circuit error against raw qubits. | Twelve; a key break needs over a thousand, running billions of gates. [79] |
| 2024-08-13 | NIST | FIPS 203 (ML-KEM), 204 (ML-DSA) and 205 (SLH-DSA): the first final post-quantum standards. | New locks on the shelf; nothing yet says when to take the old ones off. [63] |
| 2024-05-31 | Guth and Maynard | The first improvement since Ingham (1940) on how many zeta zeros can lie off the critical line in a range; published in the Annals in 2026. | Progress on the Riemann Hypothesis, not a proof; no bearing on factoring. [39] |
| 2024-05 | Wang Chao and others, Shanghai University | A 22-bit RSA integer factored on a D-Wave annealer; in October the story runs worldwide as 'China breaks military-grade encryption'. | 22 bits against 2048; annealing has no known scaling advantage; no key in use was affected. [77] |
| 2024-02 | Chevignard, Fouque, Schrottenloher | RSA-2048 with about 1,730 logical qubits by approximate residue arithmetic — a third of the usual count, at the price of about a thousand times more gates. | Fewer qubits, far more time; a trade, not a shortcut. [76] |
This week's feed fetched 2026-09-23, unread by a person
A GitHub Action fetches these every Monday from arXiv and a few public feeds and rebuilds the page. Titles as published. Nothing here has been checked; the ledger above has.
Papers
- A finite arithmetic form of Robin's inequality and its equivalence to the Riemann hypothesis — Challenger Mishra, Rahul Sarkar, 2026-09-22
- Distinct exponents in the prime factorization — Mikhail R. Gabdullin, Vitalii V. Iudelevich, 2026-09-21
- Domain Specific Post Quantum Signatures for Blockchains — Maja Lie, Ben Marsh, 2026-09-21
- The lower bound of shifted primes with large prime factors — Zhiyuan Yang, 2026-09-21
- A Sharp Noise Threshold for Shor's Quantum Factoring and Discrete Log Algorithms — Jin-Yi Cai, Ben Young, 2026-09-21
- Selberg sieve weights and sign changes of Kloosterman sums. II. Square-free moduli with at most four prime factors — Yixiu Xiao, Hongze Li, 2026-09-21
- Benchmarking Post-Quantum Cryptography in Lightweight Virtualization Environments on Embedded Hardware — Nikolai Puch, Chi Hieu Ta, Moritz Beckel, 2026-09-20
- An attainable Gill-Massar-type bound for spin-factor models — Koichi Yamagata, 2026-09-19
- Searching for Primes: A Neural AlphaZero Approach to a Factoring Game — Marcel Crasmaru, 2026-09-19
- ServeGuard: Verifiable, Bounded-Residual Confinement of Operator-Invisible Channels Without Revealing the Certified Read Factor — Dominik Dahlem, Rui Vieira, 2026-09-18
- Transcript-Bound Combiners for Downgrade-Resilient Hybrid Post-Quantum Key Establishment: Definition, Proof, and Embedded-Device Cost — Bhanwar Gupta, Sanjeev Rana, 2026-09-18
- Quantum Entropy Contraction and Factorization from Hypercontractivity — Li Gao, Lijun Wang, 2026-09-17
- Proof of Shor's conjecture on the accessible information of quantum dichotomies — Michele Dall'Arno, 2026-09-17
- Asymptotic counting of integers with prime factors $p_{r^a s^b}$ — Mehdi Golafshan, 2026-09-16
- A Global Readiness and Sovereignty Capability Model for Post-Quantum Cryptography Migration — Mohamed Aly Bouke, 2026-09-16
- 1/f frequency noise in mechanical resonators scales inversely with volume, not with quality factor — M. L. Roukes, 2026-09-15
- Analyzing Multi-Factor Authentication Through Cryptographic Security Properties — Ryan Tipping, Yousef Tahboub, Krishna Bodige, 2026-09-14
- Performance in Symmetry-Restricted Searches for Post-Quantum Correlations — Marek Gazdzicki, Francesco Giacosa, 2026-09-14
- Long runs of integers with small prime factors and the divisor function of $n!$ — Tristan Freiberg, 2026-09-14
- On the largest prime factors less than $y$ of consecutive shifted primes — Zhiyuan Yang, 2026-09-14
News
- Quantum-Safe Bitcoin Design Revolutionizes Lightning Network Security - OneSafe.io — OneSafe.io, 2026-09-23
- Inside Coinbase’s $250 Billion Playbook for Post-Quantum Bitcoin Custody - Decrypt — Decrypt, 2026-09-22
- Lattice Mach-N2 Meets CNSA 2.0 Standards For Post-quantum Crypto - Quantum Zeitgeist — Quantum Zeitgeist, 2026-09-22
- Bitcoin may go quantum-safe while Lightning privacy stays exposed - Cryptonews.net — Cryptonews.net, 2026-09-22
- RSA-896 Has Been Factored. Steve Weis Reports Factoring RSA-896 Using Claude - Quantum Zeitgeist — Quantum Zeitgeist, 2026-09-21
- Why Quantum Computers Could Steal Satoshi’s Bitcoin First - CryptoPotato — CryptoPotato, 2026-09-21
- Quantum computing threatens bitcoin, VanEck says solution exists even if slow - 디지털투데이 — 디지털투데이, 2026-09-21
- RSA-896 Cracked with Claude AI, Second Factoring Record in Sixteen Days - Tech Times — Tech Times, 2026-09-20
- RSA-896 factored with AI assistance, pushing the public record to 896 bits - Crypto Briefing — Crypto Briefing, 2026-09-20
- Bitcoin Quantum Risk: 7M BTC Exposed, BIP-360 Still Just a Proposal [2026] - shattered.io — shattered.io, 2026-09-20
- Blockchain Developers Are Racing to Protect Against the Quantum Threat. Here's What It Means for Bitcoin and Ethereum Investors. - Yahoo Finance — Yahoo Finance, 2026-09-18
- Trump Signs Quantum Orders Amid Bitcoin Risk - CoinMarketCap — CoinMarketCap, 2026-09-18
- With Quantum Computers a Threat to Bitcoin After 2030, Developers Unveil a Quantum-Resistant Roadmap - CryptoRank — CryptoRank, 2026-09-17
- Ledger CTO Warns Bitcoin’s Quantum Migration Could Take Years as Wallet Risks Come Into Focus - Bitcoin Foundation — Bitcoin Foundation, 2026-09-17
- Bitcoin quantum migration may take years, Ledger CTO says - Crypto News — Crypto News, 2026-09-17
- Bitcoin quantum resistance plan targets 2029 as attack risk halves - The Cryptonomist — The Cryptonomist, 2026-09-17
- Where Does the Quantum World End and Ours Begin? — Quanta Magazine, 2026-09-17
- Quantum-Proof Blockchain: Why Math Beats Machines - Memeburn — Memeburn, 2026-09-16
- Bitcoin Developers Propose Freezing Quantum-Vulnerable Addresses in BIP-361 - CoinMarketCap — CoinMarketCap, 2026-09-15
- Bitcoin’s Post-Quantum Roadmap Gains Clarity with P2MR - Cryptonews.net — Cryptonews.net, 2026-09-15
- Bitcoin Quantum Fix Could Trigger New Vulnerabilities, Mow Warns - Yellow.com — Yellow.com, 2026-09-15
- LayerZero Cuts Quantum-Safe Proofs Down To 65 Kilobytes With Akita - Yellow.com — Yellow.com, 2026-09-15
- Will Bitcoin Survive Quantum Computing? Inside the Race Toward Q-Day - CoinMarketCap — CoinMarketCap, 2026-09-14
- Bitcoin exchanges can reduce quantum exposure before a network upgrade - CryptoSlate — CryptoSlate, 2026-09-14
- Bitcoin's First Quantum-Resistant Transaction Just Went Live - Yellow.com — Yellow.com, 2026-09-13
- Post-Quantum Cryptography Explained: New Math To Protect Bitcoin - Yellow.com — Yellow.com, 2026-09-12
- OpenSSL’s new alpha build speeds up post-quantum crypto - Help Net Security — Help Net Security, 2026-09-10
- Moving Bitcoin’s Post-Quantum Readiness Forward - Coinbase — Coinbase, 2026-09-09
- a16z Crypto Rebuilds Jolt Proof System With Post-Quantum Security And Faster Performance - The Quantum Insider — The Quantum Insider, 2026-09-09
- Guest Post: Why Enterprises Need to Start Post-Quantum Migration Now - The Quantum Insider — The Quantum Insider, 2026-09-09