A quantum computer successfully cracks a standard 256-bit elliptic-curve private key before 2035.
Cryptographers monitor quantum computing developments to assess when Shor's algorithm can feasibly break Bitcoin's secp256k1 signature scheme.
Across 6 frontier models answering independently, the panel has all but ruled it out: the median is 6%.
They broadly agree, 11 points between Gemini at 14% and DeepSeek at 3%.
Nothing is settled until 16 Sept 2036, when the outcome is checked against sources and every number above gets a permanent score.
What each one said
-
GeminiGoogle
Cracking secp256k1 requires millions of physical qubits with low error rates, far beyond credible 2035 hardware roadmaps.
- Shor's algorithm for 256-bit ECC requires roughly 2,000 logical qubits, equating to over 1 million physical qubits at 10^-3 error rates.
- Roadmaps from IBM and Google project only thousands of physical qubits by 2030, making commercial-scale fault tolerance by 2035 unlikely.
- A breakthrough in quantum error correction architectures requiring sub-100k physical qubits would significantly raise these odds.
14% -
GPTOpenAI
It turns on building millions of error-corrected logical qubits with sustained low-latency quantum operations.
- Shor attacks on secp256k1 require a fault-tolerant machine far beyond today’s noisy, sub-thousand-qubit hardware.
- Published resource estimates generally imply millions of physical qubits plus long coherent computation, not merely a larger chip.
- A credible 2030s fault-tolerant breakthrough or sharply lower code overhead would move this estimate materially upward.
9% -
GrokxAI
Fault-tolerant QC with ~2.3k logical qubits must run Shor on secp256k1 by 31 Dec 2034.
- IBM/Google roadmaps still project only noisy 100k-qubit machines ~2029–33, far short of the millions of physical qubits needed.
- No public demonstration even of 10-logical-qubit factoring exists; historical QC scaling has slipped 5–10 years repeatedly.
- A 2027–28 breakthrough in error-correcting codes that cuts overhead 10× would be the main thing that moves this above 20.
8% -
ClaudeAnthropic
Requires millions of logical qubits with error correction, far beyond any credible 2035 roadmap.
- Breaking secp256k1 needs ~2000-3000 logical qubits with millions of physical qubits under current error-correction overhead estimates.
- Current best quantum computers have order-hundreds of noisy physical qubits and only nascent logical qubit demonstrations, nowhere near this scale.
- Roadmaps from IBM, Google, and others target thousands of physical qubits by early-2030s, still orders of magnitude short of what's needed for 256-bit ECC.
4% -
DeepSeekDeepSeek
This needs millions of error-corrected qubits; the field is roughly three orders of magnitude short with under a decade left.
- Breaking secp256k1 via Shor needs ~2,330 logical qubits and ~1.3 billion Toffoli gates, translating to millions of physical qubits at realistic error rates.
- Best current hardware is ~100-1,000 noisy physical qubits; Google's 2024 roadmap targets one logical qubit by 2030, not millions.
- RSA-2048 factoring and ECC-256 breaking are comparable-scale milestones, and neither has been approached; no credible lab claims a path before 2035.
3% -
QwenAlibaba
Requires ~2,500 logical qubits with error correction; no roadmap shows that threshold being reached before 2035.
- Breaking secp256k1 needs ~2,500 logical qubits (millions of physical); IBM's 2033 roadmap targets ~100K physical qubits, far short.
- No lab has demonstrated fault-tolerant logical qubits at scale beyond single-digit counts as of 2026; error-correction overhead is the binding constraint.
- A surprise architectural breakthrough (e.g., topological qubits at scale) could shift this, but no credible path exists in any published roadmap within 9 years.
3%
6 of 6 models answered · 11 points between the highest and lowest. None was shown the market price.
Question sourced from a news sweep on 19 Sept 2026. Forecast by google/gemini-3.8-flash, anthropic/claude-sonnet-5, openai/gpt-5.6-terra, x-ai/grok-4.6, deepseek/deepseek-v4.1-flash, qwen/qwen3.8-max-0902 via OpenRouter.