Paper 2026/1916

Computing 256-bit elliptic curve discrete logarithms in 26 days on a fault-tolerant trapped-ion quantum computer with 20,000 qubits

Thomas Häner, IonQ
Felix Tripier, IonQ
Jacob Young, IonQ
Michael Naehrig, IonQ
Andrii Maksymov, IonQ
Safwan Alam, IonQ
Dmitri Maslov, IonQ
Matthew Parrott, IonQ
Yvette de Sereville, IonQ
Jordan Sullivan, IonQ
Mark Webster, IonQ
Nicolas Delfosse, IonQ
John Gamble, IonQ
Martin Roetteler, IonQ
Abstract

One of the strengths of our recently proposed Walking Cat Architecture for a trapped-ion quantum computer is that it is straightforward to extend and optimize for a specific application. As a proof-of-concept, here we present such optimizations for solving the $256$-bit elliptic curve discrete logarithm problem (ECDLP) on $\mathtt{secp256k1}$, which is the elliptic curve used by blockchain technologies such as Bitcoin, using Shor's algorithm. We optimize the circuits from Schrottenloher's recent work and arrive at a logical quantum circuit for solving the ECDLP using about $1450$ qubits and $40\cdot 10^6$ Toffoli gates, with a rigorous lower bound on the logical-level success probability that holds with confidence at least $1-2^{-128}$, as well as a heuristic estimate thereof. Using our compilation toolchain in combination with manual optimization of the logical layout and integrated routing, we produce estimates for the logical measurement depth and the required number of physical qubits by compiling all components to measurement schedules that obey the architectural constraints. A key ingredient is a fast CCZ magic-state factory and a depth-one CCZ state injection, reducing the execution time of CCZ gates by a factor of $31$. We increase the logical-measurement parallelism using non-overlapping cat-based measurements in parallel, and we leverage the recently proposed logical CliNR protocol to speed up Clifford operations. To reduce the qubit overhead, we introduce a more efficient loss correction protocol, design a layout that allows us to recycle the CliNR ancilla qubits, and provision reusable cat-state resources according to the circuit's peak measurement parallelism. All results and optimizations combined, we conclude that a trapped-ion quantum computer based on our architecture would be able to solve the ECDLP on $\mathtt{secp256k1}$ in approximately $25.7$ days using $19{,}397$ physical qubits with an estimated success probability of $63\%$.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
quantum algorithmsShor's algorithmECDLP
Contact author(s)
thomas haener @ ionq co
tripier @ ionq co
jacob young @ ionq co
michael naehrig @ ionq co
maksymov @ ionq co
mohammad alam @ ionq co
dmitri maslov @ ionq co
matthew parrott @ ionq co
yvette desereville @ ionq co
jordan sullivan @ ionq co
mark webster @ ionq co
nicolas delfosse @ ionq co
gamble @ ionq co
martin roetteler @ ionq co
History
2026-09-10: approved
2026-09-08: received
See all versions
Short URL
https://ia.cr/2026/1916
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1916,
      author = {Thomas Häner and Felix Tripier and Jacob Young and Michael Naehrig and Andrii Maksymov and Safwan Alam and Dmitri Maslov and Matthew Parrott and Yvette de Sereville and Jordan Sullivan and Mark Webster and Nicolas Delfosse and John Gamble and Martin Roetteler},
      title = {Computing 256-bit elliptic curve discrete logarithms in 26 days on a fault-tolerant trapped-ion quantum computer with 20,000 qubits},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1916},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1916}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.