New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Quantum Hardware Milestones - Quantum Solving ECDLP Timing: "Wen QDay?"

ETHCluj MeetupWed, Sep 9, 2026, 12:00 AM

Transcript

So this topic is partly a response to my adventures in the United States going to Bitcoin conferences and they just got this completely wrong. Nobody there had any idea what the current status of quantum hardware is. And they were arguing against very wellestablished physics um and claiming just ab absolute craziness as a way to say that Bitcoin is actually safe. Physics is wrong. The physics that you use every day is wrong.

It's not it's not true. So, um, you've heard me chatting a little bit about each of these companies. This is the 2024 list. This is 45ish companies. Um, the current list is over 4,000.

I'll go into this more in depth, but this is the old old list. And most people had only heard of one or two maybe three companies that were working on this and they were only measuring the progress of those three companies. Uh Quantum is the company that I'm most concerned about and they have four quantum computers. They have been doing mass production for two years and we have no idea about the performance or size of any of their quantum computers. We have no disclosure.

So this is U McKenzie. This was their predictions. And there's a a couple problems with this uh this estimate. First off, you'll notice that the algorithms improve in efficiency. It was actually much sharper of a trend.

Every one to two years. the quantum algorithms were improving by 10 to 100x and it's been doing that since 2020. Um the second major issue is that this is for RSA 2048 and I'll cover this more in depth. It's actually much easier to break elliptic curves than it is to break RSA just due to the size of the keys involved. Um and you're noticing that they kind of begin the window in 2027.

Uh I would say that is also when the risk window begins because this is when the com the companies that make the hardware say that they will have enough hardware to break elliptic curves. Um and I I thought that was unlikely. Um partly because of the people involved. I don't trust anything I own Q says. Um and partly because uh some of the companies that were saying 2026 2027 missed some of their targets.

Um however their current target is 2028. They have some of the best performing hardware. Um they were doing megahertz gates in 2023 when everyone else was doing kilohertz gates or running at literal hertz was cycles per second, not millions of cycles per second. And that was due to a partnership with AMD. So what does this do?

Quantum computers can take the public key and turn it into the private key. It was expected this would be like 8 to 10 years off. They were doing these fancful projections based off RS 2048 2048. uh since it's a smaller problem and they broke it into smaller pieces, it happens a lot faster. So the the hardware has not grown exponentially up until recently.

Now it is doubling cubit counts about once every nine months based off of uh QRA in June of last year and uh Oraic in March of this year. It's doing 3,000 and then 6,000 cubit systems. Both of those being neutral atoms. Um, I had to change this slide. This used to say 1 million cubits.

Now it says 0.5 million cubits because that was the the major shift. That's the conservative estimate. Uh whereas the old estimate was the aggressive estimate. So the actual increase was like a 4x or you know cutting the amount of cubits required by about 4x.

This scaling law I'll cover a few times but every time on multiple different kinds of quantum computers if you triple the size of there's of the cubits it runs seven times faster. This doesn't have the diminishing returns. This has compounding returns. This has exponential returns. So if you can build one of these things in the network kit to a second one and then a third one, the whole thing now runs seven times faster.

So going from a one or an eight hour break, you're now looking at a little over an hour break for just building two more of the exact same thing. So uh I I've heard that this is going to break the world. Most quantum uh attacks would occur against elliptic curves. Elliptic curves only used by several architectures. Um most people have already begun the move back in 2019.

The banks began like publicly saying we're we're upgrading and they've been working on for a while. Um signal is you know fully post hybrid postquantum. Um, you're looking at basically uh lean Ethereum says they're going to have the cryptography ready by 2029, but I expect that it will take them longer just because of the the massive number of changes that they need to make. Uh, and then you have to do the migration as soon as that's done. Google and um Cloudflare independently said that it would take you have to finish the migration by 2029.

You have to be completely done by 2029. So that's a problem. What this what happens in web 3 is that every time when you I'll I'll back up. Bitcoin has a 35% uh public key disclosure. 35% of Bitcoin can be solved for the private key and then spent.

Most of that's on exchanges. They can move a lot of it. Now, for Ethereum, it's 65% based off of a study by Deoid. For DeFi, it is 100%. because if you've done a transaction, you've exposed your public key.

Um there is the possibility of using account abstraction, but they're using the same cryptography. And so all they've done is push the cryptography risk to the edge as opposed to having it on the ledger. uh I don't know of anybody managing DeFi contracts that is running using account abstraction as the admin contract. So basically the quantum computers can become anybody in the network. They can become bridges.

They can become anything the admin can do. They can do this is go ahead. Sorry, for for Ethereum you said 65% exposure on public keys. But why is that? Because basically if you have a wallet or you have an address and you just do one simple transaction already exposed.

So back when they were when they were doing mining the the miners would accumulate funds but not spend them.

Okay. And that that's those are the addresses that are not

right

included in this. And if you send someone ETH and they don't do a transaction afterwards, then it's not included. And this 35% of um essentially everybody doesn't have a public key associated that could include account abstraction, but it it in practice it it hasn't been adopted really. So shores algorithm is the one that everyone talks about. There's also optimistic shores, red jevs, uh, kiskies, and quantum phase estimation.

So there's five different algorithms. It's not just one. Just one gets all of the notoriety. Um, the hells have different profiles and different things they do well. So if a quantum computer couldn't run shores for some reason, they could probably run kisks and still get the private key.

All of the algorithms are multiple query, multiple solve. So you can send in 10 keys and it will break all 10 for the same time it would have taken it to break one. It requires extra cubits to hold the question and extra cubits to hold the answer. So they generally just calculate one for their costs and then they just keep adding cubits and uh or if they have spares then it will work just fine. um the total value locked is is is bad.

Basically, there's there's a huge risk here. Um I don't want to spend too much time on this slide, but the the exposure exceeds the value. There'll be a run on the banks in order to withdraw when people figure out that Qday is going to be coming soon. And then that will cause all the prices to crash which will cause everyone to withdraw even if they didn't believe in quantum.

That's what I'm buying.

If you believe the quantum is absolutely fake that would be a good buy.

It can be partially

um it I that is a common trend among Bitcoiners. Uh and they say well even after quantum one bitcoin is still one bitcoin and you won't have a better time to pick up one bitcoin. Yeah, but we have so but the problem is that so the problem is the exposure of public keys for now, right? And you still have that 10 minutes window where uh you expose the transaction and and it has to be uh correct 10 minutes,

right? Uh however um there so the Bitcoiners refer to things as long attacks and short attacks. The long attack is a known public key that's already been predisclosed. The uh project 11 risk maintains the 7 million bitcoin that have exposed public keys. The short attack is when that this is where the scaling comes in.

When they can just make more of the same machine and make it run fast enough to solve transactions before they have been mined, then they will be able to steal the Bitcoin before the transaction has been mined, do replace by fee, and then redirect the funds to their account. Also, they'll be able to do the postquantum migration. So, they will have postquantum Bitcoin from your Bitcoin.

Agree. Technically, yes. But uh socially speaking or in the real life, let's let's say it basically there's the first attack today happening. They would probably attack for an address that for which the public keywords will be exposed and it might be that it happens. That that's what I'm referring.

This depends on the attacker. If the attacker is China, they will cause as much damage to the entire ecosystem at the greatest profit at at the greatest hype and exaggeration possible. They are going bankrupt as a country. Their debt to GDP ratio is like four times the US. Um, and people complained about the US debt.

We have no idea how big the local debt is. Um, people have been trying to send money abroad by buying art and getting 10% of their money back out when they sell the art, but they get euros instead of yuan. So on the news, China declared that they have to destroy Bitcoin in order to survive. The Chinese Communist Party says they will not survive if blockchain survives. Do you think that they will wait to have the technology to attack the whole network once or would it happen right?

Uh I suspect gradually solved and if I were the attacker I would go after false postquantum chains because they wouldn't disclose we got hit by a quantum attacker and they have no reputation to begin with so no one will believe them no matter what they say. Uh, and then I would go after the layer twos that have low low reputation and target them and and withdraw from them. And then I would target the bridges. I would not go after Tether directly because if I did that, then Tether could figure out that it was a quantum attacker because they would know their own custodial chain. So I would target u one of the bridges and I would declare uh $1 trillion belonging to me on the bridge and then you know attempt to withdraw or you know do swaps and then withdraw.

Um I'd send it through mixing protocols and other things in order to disguise the withdrawal. But the entire system ends up fragmenting. And that's why I would have short sales on ETFs, short sales on the Bitcoin stock treasuries, and short sales on um you know, derivatives and so forth. So I would make money off of the trady even as DeFi is is crashing and burning and no one will exchange it anymore.

So I thought about this way too much. The risk is real. Uh, I do not recommend holding a large amount of unprotected crypto and I'd like to convince you why.

I I don't I don't don't disagree. I just said that there will be bounces. So, so if if I'll buy at $20, I'll probably be able to sell at 1,000. Right. There is a bounce.

or do you think it's going straight down and it's only a shorting straight?

That is entirely dependent upon if the attacker wants to maximize the funds that they withdraw or to maximize the damage to the ecosystem. If they want to cause the the ecosystem to go to zero, they'll simply drain the money as it's as it's available and there will be no bounce. That's what why I was asking if you think it's going to be first a partial attack or total attack.

If if it's corporate, it'll be partial. If it's China, it'll be complete. They'll just crash it to zero and there'll be no trust in the ecosystem and the headlines will read Bitcoin hacked, uh, Ethereum dead, end of story. Um, because that is what they will try to cause everyone to believe. And there will be no longer any trust in any of the math that is relied upon today.

Thanks. So, does it mean you already sold your Bitcoin in preparation of this doom state scenario?

I sold my Bitcoin because the people involved can have lost the ability to discuss things rationally. Knots versus core, the Nazis versus core, the the child pornography on the chain, the the spam claims, the Bitcoin is money and only money claims. They have just completely gone aggro against each other and the conference has just made it more obvious and worse. So now I'm going to try to cover what I think is the thing that people are getting wrong. So we used to have these calculations where you would run a quantum circuit and the quantum circuit was like a giant tape.

The width of the tape was the number of cubits that you could hold in memory to hold the data required. So for you know 256 bit cryptography you need to have 256 times some multiplier and it was usually like one and a half or two and a half. for 2048 bit cryptography. Now that it's 20048 times the same, you know, one and a half or two and a half depending on the algorithm that is then multiplied by the number of operations that need to be performed on those on that data and the entire thing processed like a single serial tape. If there was any wrinkle and or any error in the calculations, the entire calculation was dead.

you did not get the private key. The calculation failed. Start over. That is no longer the case. So, three different architectures have had uh cubit reuse.

Now, the first one, this is the one that made me panic was scantum in 2024. And that's when I started building postquantum cryptography was 2024 within a week of reading that the Latinsky paper from Cyclone and he talked about uh active volume and the ability to basically treat it more like RAM. They can just send photons down fiber optic lines and read them out exactly when they need them. Um they can schedule delays. They can make the system work in parallel.

they can do background tasks and foreground tasks simultaneously. Uh the total size of the system is based off of um how quickly they need to generate those cubits. It is not based off the total number of gate operations. It's based off of simply their speed to replenish them. And they can just reuse the same cubits, the same photons over and over and over.

they call them resource generators because the the the shift was complete. Um and this is the active volume paper from Latinsky in 2024. Uh Oratomic said they accomplished basically the same thing for uh neutral atoms. Um the actual geometry is they have a a giant circle and they just keep the laser rotating in a circle and they keep replenishing new cubits and they can keep performing the calculations as they need to. Um, I was explaining a little bit about QA before and how they had a pool of 30,000 cubits and then that generated 3,000 usable cubits and they maintain this for hours of c of computation on their inaugural launch.

You know their first use public use was a fully fault tolerant logical cubit wielding uh strontium calculation doing new novel chemistry that we did not have before and it lasted hours with 3,000 cubits. They did not have cubit reuse at the time. So now instead of having this this idea of this long tape drive, now it's just how much RAM do you need to hold the current question and then how fast does that run? Can you maintain stability to finish the computation? The cubit reuse has limitations uh specific to each platform.

Um, Scantum needs to have like a consistent supply of new photons. So, they've mastered releasing one photon pair at a time. Uh, Oratomic needs to have their rotating circle operate at a speed that exceeds their consumption. Um, and that's at 99.1% efficiency.

So there is you know basically nine out of a thousand their initial system will fail. Uh it is no longer about how many cubits you have. It's about your ability to continue the calculation. And then Q has a grand design that they have not demonstrated. So I I just put they they claim it but Oattomic proved it and Scantum proved it.

So they have very solid claims to this basically unlimited quantum computer. So the second kind of devastating change is that we're re using cubits and the more of them that are available at any given time, the faster the entire calculation goes. So now it's not just it's going to take us, you know, eight hours and it's going to take, you know, this number of cubits. The question is well if we can get more cubits the entire thing runs much faster and the total cubits involved in the computation alters the speed of the computation dramatically. Every 3x in cubits is a 7x increase in speed.

So networking has been solved by a lot of people recently uh usually using microwaves even between superconducting systems and microwaves tend to destroy superconducting systems like that's you know kind of your default but they've managed to do networking between separate superconductors. They've got uh another system actually has a cryogenic cable that connects superconducting quantum cubits and makes separate chips mutually entangled to each other. Uh, China recently said that they have neutral atoms working as a a multi-processor quantum computer, but they did not disclose if that was two independent or two mutually entangled systems. So, I don't put the Chinese paper in in the slides at all. Um, Sai Quantum has the best networking.

It uses the telecom equipment that we've been using for the last like 30 years. That's gotten very good. Um, fiber optics were far superior to Silicon when I was in Silicon Valley 25 years ago. They're amazing now. Uh, they have no problems in networking at all.

And then the the last sort of like trapped ions uh they've done networking using lasers, microwaves, and like multiple media relays. They've managed to make a superconducting system network with a trapped ion system even though they run at completely different clock speeds. Uh basically the superconductors run about 2,000 times faster than the trapped ion. They did not provide specific timing details for their two specific systems, but that's the general speed. And the two systems were able to to stay mutually entangled and one would do short operations, the other would do slow operations.

If you read papers from 2016 to 2020, you'll read a lot of like quantum RAM has never been solved. Uh these days quantum RAM is solved by having a slow machine talking to a fast machine. The slow machine holds the answer. The fast machine processes the answer. There is error correction zoo.

Um they have over 1,000 different logical cubit codes. They all have different geometries. They all have different architectures that they're compatible with. They all have different yield. they nobody's using the same logical cubit architecture between systems.

Um Google is classified as a superconductor but their actual technology is um a piece of gold. It's really flat and they have regions of electron of negatively charged areas and then they entangle those together and they're able to create logical cubits out of regions of pieces of gold. Um, and that was what their their papers were on. Um, they're switching to neutral atoms because it scales much easier and much much faster um in terms of like effort versus yield. However, the there are other architectures that have quasi particle mutual entanglement and they call this an anon braid and basically this error correction built in and every cubit there is a logical cubit because it has the error correction as part of the architecture.

The reason I'm going into the details here is that I want you to realize that when you look at logical cubit on system one, it does not compare to logical cubit from system two. They have basically nothing in common. Um there are error correction routines and there are error detection routines. There's also something called anciliary cubits. These are basically spare tires that they can just use as needed to continue the the calculation.

So these three systems have a massive amount of overlap. Um there is no single strategy but there's also no barrier. This is an implementation engineering cost, not new physics. It's not new programming. All of these error codes have been massively demonstrated and massively researched, massively documented.

It's just pick and choose. How many of these error codes do you want to to use? Do you want to use two? Do you want to use three? Do you want to scale them or use them in parallel?

Do you want to have quantum RAM use a different logical error code than your calculation cubits? It's all fine. There is no barrier, just time. And the time is getting close. So, we went from about 45 companies in 2024 um to over 4,000 today.

There is uh a second fundamental shift to disclose here. back in 2022 when I was reading lots and lots of quantum papers and worrying, you know, is Bitcoin gonna, you know, migrate in time and I couldn't get anyone interested. The the issue was that all of these innovations that were occurring in 2022, had they been in a single company and a single platform, that would have been a massive jump right then and there. But they're all spread out. They're all scattered.

And every single lab had to make their own equipment. If you needed an isome isotopic isotopically pure version of silicon 28, you had to craft that device yourself. You had to try to get that isotope purity yourself. That switched to supply chain. You can now order it and it arrives at your door and it is 99.

9% pure or 99.1% pure, you know, depending on which isotope you need, what device you need, uh what it functions, what temperature you can get it to operate at. There is now a massive supply chain that is accelerating the hardware. A lot of the reason that it was so slow is that you were dealing with a whole bunch of people that were essentially shoe makers making their own tools to make the shoes. And now you're dealing with drop ship delivery.

So the quantum hardware is scaling up now. It's really scaling up. This is something you will not read about in the news. This is something that keeps me uh bothered. Metamaterials are the idea that when you do chemistry, you can create a terrain and then that terrain can be scouted for behaviors and then those behaviors are then mapped and you now have properties that you can use.

for example, room temperature cubits from photonics and they generally operate at late the things that they have in common is that there is a laser and there's some surface thing that they did. There is nothing else that they have in common. Some of them use independent lasers. Some of them have one laser. Some have a lens that they that they aim at the region that they're trying to calculate.

They've done things like constructing the Statue of Liberty out of individual atoms. This is precise and it's cheap. In order to to make your own cubits at home, you take one of dozens of metals and you dunk it into one of dozens of metals and then you beam a laser at it. The cost to start your own quantum computing company went from, you know, 10 million or hundred million dollars to how much does it cost you to order the materials and perform cutting edge science. Um, there was this was an unheard of concept in in 2024.

In 2025, there's a couple hundred papers. Now there's papers flooding uh arxiv talking about metamaterials. You will see three major classes of papers. Uh the first one is material science because they're like literally researching the way that what happens when we combine these two chemicals. Um can we turn that into a usable device is the second category.

And then the third category is, you know, for quantum computing. So if you're going to read about metamaterials, it's the quant- section of arxiv that will show you papers on metamaterialbased quantum computing. Um I am not an expert. I only read about 15 papers in three days um that were on that topic. What I concluded is that this is now something that people in rural India can do very cheaply as opposed to something that was restricted to large labs like IBM with a large supply of helium from a nuclear reactor.

That is what is used to cool down to 20 millichelvin. You can get to 2 Kelvin just by adding adding helium and compressing it. That's what cyclone uses. They just use compressed helium. It's very very cheap to make.

In order to get helium 3 and helium 4, you need to have either a volcano, an ice field that used to be a volcano, or you have a nuclear reactor that you're pumping helium into. and you're getting helium 3 and helium 4 out. And these are isotopes that turn to a metal when they get close to zero Kelvin. And that's how you keep IBM system cold. Metamaterials has changed the game.

So now you don't need any of that crazy infrastructure. Now you just need a laser and a recipe that you can do in your in your bathtub. Now purity still matters. So there is still a lot of like innovation that has to occur here. They have not created chains of cubits.

I checked again last night. Um there is not uh a gate system here, but this is one of those fields where there's now thousands of people looking at it. There's thousands of teams working on this specific problem and innovation is occurring rapidly. So the problem ultimately is that it took me two years with my team to adopt cryptography correctly on EVM to switch all of the postquantum cryptography for the consensus the um the wallets. Uh we had to change the compiler.

we had to change uh you know the the size of the addresses to 256 bits because 160 bits is not quantum safe. Um that is a project that was attempted by Vitalic back in 2020 and they gave up. They said that they could not change the address base of Ethereum. It was too hard. uh the only reason that we were able to do it is that we were starting from scratch and that reduced the difficulty dramatically.

Um I do not wish to underestimate the work that needs to be done by Ethereum. The only reason that we succeeded is that we were starting from scratch. It was hard. We had tons of problems uh with the entire stack top to bottom that has not even been properly considered by lean Ethereum in my estimation. We've succeeded.

I do not expect that startups that use AI to vibe code their PQC chain, which I've seen about five of will get it correct. Most of them are still using ED25519. Um, I maintain a list of companies that claim to use postquantum cryptography. I track their GitHubs and what cryptography they actually use. U there's about three that have actually implemented postquantum cryptography but did so incorrectly.

Um, there's two that have implemented it correctly. Uh oh, I have a low opinion of QRL because they do not believe in applying security patches even when there are known exploits. So I can't recommend one of them. This migration that will need to occur is going to be extremely hazardous to the ecosystem because it is a tragedy of the commons. Whatever the worst security is equals the value.

If somebody hasn't migrated and the quantum computer is available, they're now able to take those assets. So, there will need to be an enormous amount of slashing. Um, Algarand has made enormous progress on their implementation of a backup to their uh chain history, which I think is useless. And they've also implemented postquantum cryptography on their wallet, which I disagree with their choice of cryptography. They still have to do all of their state proofs, all of their ZK, their architecture, their onchain tools, their off-chain tools, their bridging, their data, and the smart contract admins.

I do not think that they will succeed even though that they've been trying to do this for four years. I expect that if they are going to succeed, it will by by turning their chain malleable and just editing the history. I do not expect them to succeed any other way. Um, and they're using Falcon, which is easy to just steal the keys from.

Know about the other teams or

um I can pop up the list. I'll send you the list. Um, Hideera, uh, Quantinium, excuse me, uh, I I got that name wrong. There's so many things to start off with Q these days. Uh, Ozone, uh, like they don't even use the cryptography they claim.

They just use P6K1. Solana did a a $50,000, you know, payment to Project 11 to make a postquantum cryptography version of Sana. And the result was Falcon ran poorly, not well, and wouldn't possibly serve as a solution. Um, the data won't fit on their chain. Uh, Sooie has a very good design.

They will need to add three new architectures in order to support the new technique that they're proposing. It is a a variation of ED25519 that uses a leaf and maintains the same key. So, everyone can rotate in place, but they have no way of detecting to see if someone has rotated their key in place to the postquantum system unless there's like another auditing tool that they add. I don't know they're going to be able to do it in time. Uh Aptos last year was claiming that there is no threat from quantum security.

This year they're claiming that they're the leader. They intend to copy what Sooie does. Uh I do not believe that other chains have a chance. Um, the long and short of this is basically if something has value outside of web 3 that should probably migrate first, especially real assets. Um, I have done an enormous number of GitHub digs and and checked the cryptography that people are using.

It's hard. Uh there's been a few that made me just throw up a question mark and a warning going they need an audit. I don't have the time to do the audit. The audit will probably take weeks from someone who just only does postcry cryptography audits. It's hard.

Uh it's probable that most people will screw it up. So, um, KillVPN is just based on Sellframe. QRL, I don't recommend. Mochimo, they've been around. Um, it's a small like few hundred,000 chain that has no web 3 capabilities at all.

So, um, like CKB claims to have stuff, but they paid some guy $700 to write a test wallet. Um, Aleand talked about. So any questions in our last remaining like two minutes?

Question related to uh to the research that you did about about quantum computer companies. So um what what is their what do you think is their business model except cracking cryptocurrency cryptography?

So uh depends on the company. Uh in the case of Cyclquantum I think their business model is to take money from the NSA and DARPA. In the case of ion Q I think it's to sell stock. Um there are four other technologies that are easier to make than a cryptographically relevant quantum computer. Uh quantum sensing is very good for drone warfare.

It cannot be blocked. It cannot be jammed. It's more accurate than GPS even in the worst case scenario. So a lot of them are branching out and doing quantum sensing which is really easy to do and that's like a possible revenue model. Um quantum key distribution and quantum cryptography are lasers between peers.

It doesn't work without lasers between peers. Uh that's really a banking network thing. So when you see them selling like this it's it's really awkward to see more than one product there. I I don't trust like a second or a third product. I think they're just going for the stock pump.

The f the easiest thing for them to do with an actual quantum computer is to break blockchain. Unfortunately, there's no intermediate scale systems that are also solvable problems. There's been challenges where they're offering millions of dollars. Can we use this for anything else in the meantime? The answer is no.

They they don't have anything.

Is there any like Chinese on this front? Because what you listed there were were mostly based companies.

So China took all of their companies and said, "You now work for the government. Go work in the lab. Make one of everything." And so they're not doing trapped ion or superconductor only. They're doing one or two of everything.

Um they have like a bad photonics project and an amazing superconducting project. We only know what they tell us and they only tell us things when they want to prove that they're ahead of the west. And I've tried to verify as much as I can but we're we're just getting little tidbits here and there. We have no clear data. Everything we do get we have to examine very carefully.

Thank you. Y

Automatic transcript — names and jargon may be misspelled.