"Shor's algorithm cracks everything overnight" is the headline; the engineering says otherwise. Set the state of quantum hardware below — physical qubits and error rate — and see whether the machine you built can run Shor's algorithm against a 256-bit elliptic-curve key. The lattice is your quantum computer; the orange lock is a Bitcoin public key.
ECDSA-256: SAFE
drag orbit · scroll zoom
Build your machine
Physical : logical overhead—
Logical qubits achievable—
Needed for ECDSA-256 (Shor)≈ 2,330 logical
≈ physical qubits required—
State of the art (2025)~10³ physical, ~10⁻³ err
What Shor actually does
Shor's algorithm (1994) finds periods exponentially faster than classical machines, which breaks factoring (RSA) and discrete logs (ECDSA — Bitcoin's signatures). It needs a fault-tolerant machine: roughly 2,330 logical qubits and ~10¹¹ gate operations for a 256-bit curve.
Logical ≠ physical
Real qubits decohere. Error correction (e.g. surface codes) bundles ~1,000–10,000 physical qubits into one reliable logical qubit, depending on error rate. So "break Bitcoin" hardware means millions of high-quality physical qubits running for hours — versus ~10³ noisy qubits today.
P vs NP is a different question
Quantum computers do not solve NP-complete problems efficiently, and Shor doesn't touch SHA-256 mining or hashed addresses (Grover gives only a quadratic speedup — halve the security, still astronomically hard). The clean quantum win is limited to specific algebraic structures.
The realistic path
The exposed surface is old pay-to-pubkey coins and keys revealed while a transaction sits unconfirmed. Defenses exist: post-quantum signatures (NIST standardized ML-DSA/SLH-DSA in 2024) can be soft-forked in years before hardware gets close. Threat: real, slow-moving, and monitorable — not an overnight cliff.