Novel ApproachesPre-launch
← All posts
Privacy

The data you share today has to survive tomorrow's computers

A new engineering estimate puts breaking the curve behind Bitcoin at about 20,000 qubits and 26 days, on a machine nobody has built. The practical question is which of your records still need protecting when someone does.

AI
  • AI-generated draft · Reviewed by an editor

Quantum computing stories usually arrive with a large number and very little a reader can do with it. This one has a number too, but it also has a practical end, and the two are worth keeping apart.

Abstract illustration: bars of different lengths on a teal grid, crossed by a dashed vertical line. (AI-generated)
AI-generated illustration.

Researchers at IonQ have published a detailed engineering estimate for solving the 256-bit elliptic curve discrete logarithm problem on secp256k1, the curve behind Bitcoin, in a paper on the Cryptology ePrint Archive[1]. Their figure is roughly 19,397 physical qubits running for about 25.7 days, with an estimated success probability of 63 percent, from a logical circuit of about 1,450 qubits.

It is an estimate for a machine that has not been built. The authors describe the work as a proof of concept that optimises their own proposed trapped-ion architecture for this one problem, and conclude that a computer based on it "would be able to" solve it. Nothing has been broken. What has changed is the published estimate of what breaking it would take.

The organisations that run the internet's core infrastructure are treating that as a scheduling problem. Cloudflare has enabled validation of DNSSEC signatures made with ML-DSA-44, a post-quantum signature algorithm standardised by NIST, on its 1.1.1.1 resolver. Its engineering post[2] says that quantum computers capable of these attacks do not exist today, that the company is preparing for the possibility of one being built by 2030, and that it plans to be fully post-quantum by 2029. The same post shows why this takes years: an ML-DSA-44 signature is 2,420 bytes against 64 bytes for ECDSA P-256, almost 38 times larger, enough to exceed size limits built into DNS software decades ago.

Governments are working to similar timescales. CISA and the G7 Cyber Security Working Group[3] set out five priorities for the transition: raising awareness of quantum risks, developing national strategies, advancing research and development, fostering public-private partnerships, and building post-quantum cryptography into cyber security requirements and procurement. In the UK, the NCSC has published dates[4]: define migration goals and complete a discovery exercise by 2028, carry out the highest-priority migration work by 2031, and finish by 2035.

Where this touches you

Encrypted information can be copied now, kept by whoever copied it, and decrypted years later if the capability arrives. Cloudflare uses the usual name for this, harvest now, decrypt later, and it is why migration deadlines sit well ahead of any expected breakthrough. The NCSC comes at the same point from the holder's side: a discovery exercise, it tells organisations, should record the data they hold, including its expected lifetime and its value to an adversary.

That changes the question for a reader. It is less whether this afternoon's messages will matter in 2035, and more which records will still be sensitive by then: medical history, genetic test results, identity documents, immigration and legal files, financial records, anything about your children. Organisations hold those, often for decades, and often in more copies than you would guess.

Not every use of cryptography is exposed. Cloudflare notes that DNSSEC provides authenticity rather than confidentiality, so harvest now, decrypt later does not apply to it at all. The exposure attaches to confidential data that is stored or intercepted.

What you can do this year

  • Ask the organisations holding your long-lived records, particularly health providers, banks and anywhere that has your identity documents, what their post-quantum migration plan is. In the UK, the NCSC dates give you something specific to ask against.
  • Close accounts and delete records you no longer need kept. Data deleted now is not there to be copied later.
  • Ask how long each organisation keeps your data after you stop being a customer. Retention periods are where most long-term exposure sits.
  • Reduce what sits in data broker and people-search listings. That material is already public, so reading it needs no future decryption.
  • Keep your software up to date. Cloudflare's account of the move to post-quantum TLS notes that larger messages exposed assumptions and bugs in existing network software, the nearer-term practical risk in this area.

The dates above come from a UK regulator and a G7 group, so the specifics vary by country. The question underneath them travels: an organisation that cannot say what it holds about you, or for how long, is unlikely to have a plan for protecting it a decade from now.

Sources

  1. Computing 256-bit elliptic curve discrete logarithms in 26 days on a fault-tolerant trapped-ion quantum computer with 20,000 qubits, IonQ, Cryptology ePrint Archive 2026/1916https://eprint.iacr.org/2026/1916
  2. 1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of it, Cloudflarehttps://blog.cloudflare.com/post-quantum-dnssec-1111/
  3. Preparing for the Post-Quantum Era: A Call to Action, CISA and the G7 Cyber Security Working Grouphttps://www.cisa.gov/resources-tools/resources/preparing-post-quantum-era-call-action
  4. Timelines for migration to post-quantum cryptography, UK National Cyber Security Centrehttps://www.ncsc.gov.uk/guidance/pqc-migration-timelines
23 September 2026Report an error
Share

© 2026 Novel Approaches. All rights reserved. What you may do with this article