Circle recently launched Quantum Tracker, which uses a continuously updated public chart to track two curves that are getting closer: one shows how many error-corrected logical qubits have been demonstrated in experiments, and the other indicates how many logical qubits are estimated to be required to crack the commonly used 256-bit elliptic curve cryptography in blockchain systems. The page was developed by Circle Research, and the code and data sources are made public. The intention is not to predict an attack that will inevitably occur on a certain day, but rather to bring together the information scattered across papers, experiments, and vendor roadmaps into the same coordinate system.
As of the data date marked on the page, July 21, 2026, the tracker shows that the experimental demonstration capability is still at the level of double-digit logical qubits. The latest research estimates for breaking through ECDSA are around 800 logical qubits or more. There is still a significant gap between the two, and the "number of logical qubits" is not the only barrier: the attack also requires a low enough error rate, a sufficiently deep circuit, stable operating time, and substantial support from physical qubits. Therefore, the gap shown in the graph cannot be directly converted into the number of years remaining.
Circle also emphasizes at the bottom of the page that the data comes from public third-party sources, which may be incomplete, not independently verified, and can change. Therefore, it does not constitute any guarantee or recommendation. This disclaimer is not merely routine text. The evidence levels for quantum hardware achievements, vendor goals, and cryptographic analysis papers vary. Presenting them all in one chart helps to observe trends, but it should not be assumed that the announced roadmaps represent capabilities that have already been achieved.
On one side are 96 demonstrated logical bits, and on the other side is a continuously decreasing cost of attack.
The tracker records quantum capabilities as “error-corrected logical qubits,” rather than using physical qubits which are easier to manipulate to produce large numbers. Physical qubits are very fragile, and typically require many physical units to encode a single reliable logical unit. The capabilities listed on the page have evolved from early error-correction experiments to 48 logical qubits in 2023, and it is recorded that by 2026, related work with QuEra demonstrated 96 logical qubits. Different hardware approaches and experimental tasks are not entirely comparable directly, but this metric is closer to the resources required to run large fault-tolerant algorithms.
Another curve comes from the resource estimation for attacks on the Shor algorithm and elliptic curves. A systematic study in 2017 estimated that breaking P-256 would require approximately 2330 logical quantum bits, while windowed modular operations in 2020 reduced this number to 2124. In 2026, several studies further lowered the estimate to below 1200, with a study in July indicating around 835 logical quantum bits. The decrease in numbers is mainly due to algorithm and circuit optimizations, and does not imply that quantum hardware has suddenly increased by the same multiple in just a few months.
This is precisely the risk that trackers wish to highlight: the defense window will be squeezed by both advancements in hardware and improvements in attack algorithms. If the industry focuses only on the scale of quantum computers, it may overlook the fact that academia is working to reduce the resources required; conversely, if one only looks at the minimum number of logical bits in a paper, they will also miss out on considerations such as the number of gate operations, error correction overhead, and sustained operation time. A truly targeted attack on on-chain signatures requires all these conditions to be met simultaneously.
The page also lists the future goals of companies such as IBM, but these are distinguished from the demonstrated results by the use of hollow dots. The vendor's plans can help to establish scenarios, and they should not be presented as set dates. Roadmaps may be postponed, and experimental indicators may not be directly scalable. The most prudent approach is to use the charts as an annual risk review tool: when there is a major breakthrough on either side, re-evaluate the migration plan, rather than announcing a "target date for the end of a certain year" based on an extrapolation line.
What's truly urgent is the migration period, rather than waiting for the keys to be cracked on-site.
Bitcoin, Ethereum, and many stablecoin systems rely on elliptic curve signatures to prove asset control rights. If quantum attacks reach a practical scale, addresses that have made their public keys public and still have remaining balances may face even greater risks. Nodes, wallets, custodians, and smart contracts also need to support new signature verification methods. The problem is that replacing the cryptographic algorithm is not a matter of a single software update: it requires standard maturation, implementation audits, hardware wallet upgrades, user migrations, and cross-chain coordination, which often takes many years.
"Collect first, then decrypt later" behaves differently in the context of signing than in encrypted communications, but publicly available identities, infrastructure certificates, and historical data that are valid over the long term should still be inventoried in advance. For blockchain organizations, the primary task is to establish a list of cryptographic assets: which systems use which encryption algorithms, when public keys are exposed, who approves upgrades, how to migrate old addresses, and what to do if users are not online for an extended period. Without such a list, it is impossible to estimate how long a full network migration will take.
Post-quantum solutions also come with their costs. New signatures are usually larger, which may lead to increased verification costs and bandwidth requirements; the transition period that supports both old and new algorithms can increase the complexity of the code and the potential for vulnerabilities; rushing to adopt untested implementations may even result in traditional security flaws before the threat of quantum computing becomes a reality. A reasonable strategy is not to abandon existing cryptography immediately, but rather to conduct test networks, compatibility, and performance evaluations first, reserve mechanisms for protocol upgrades, and design phased migrations for high-value assets.
The launch of this tool by Circle is directly related to its stablecoin business: digital assets that are intended to circulate over the long term must take into account the lifecycle of their cryptographic systems. Tracers have not proven that quantum attacks are imminent, nor have they concluded that USDC or any other public blockchain has completed quantum-resistant upgrades. What it offers is a more honest approach to management—admitting that the timing is unknown while making observable indicators and sources public.
Quantum risks are most likely to waver between the statements "we can talk about it in a few decades" and "it will be zeroed out tomorrow." Both views lack engineering value. There is still a significant gap between hardware and algorithms, but protocol migration is also a lengthy process. What needs to be done today is not to create panic, but to include cryptographic lists, upgrade paths, testing, and governance in the roadmap ahead of time. A truly reliable system is not one that accurately predicts the date of a quantum breakthrough, but one that retains sufficient room for migration even when that date is unpredictable.











