Why the New Attack Estimate Did Not Move a Single Deadline

Board-ready intelligence on quantum innovation · Biomedical discovery · Post-quantum transition
A journal put the quantum cost of breaking elliptic-curve cryptography roughly twenty times lower than the standing estimate. Every migration date stayed exactly where it was.

Post-Quantum Transition

A journal put the quantum cost of breaking elliptic-curve cryptography roughly twenty times lower than the standing estimate. Every migration date stayed exactly where it was.

Published by Quentir Systems LLC · August 22, 2026 · 7 min read

On the night of 31 January 1953 the North Sea came over the dikes of the southwestern Netherlands and killed 1,836 people. The commission that answered the flood did something engineers rarely get to do: it turned a physical estimate into a legal number. The Delta norm fixed a design water level for each region — one exceedance in ten thousand years for the densely populated west — and the works were built to that number rather than to whichever storm-surge paper had appeared most recently. Estimates of surge and sea level kept moving for six decades. The norm moved once, deliberately, when the risk-based standards of the Water Act took effect on 1 January 2017.

That gap between a moving estimate and a fixed norm reopened in cryptography this month, and it is worth pressing on directly. PRX Quantum has accepted a Perspective by Ryan Babbush and colleagues — a Google-led multi-institution team whose authors include Craig Gidney, Adam Zalcman, Tanuj Khattar, Justin Drake and Dan Boneh — putting the quantum cost of breaking elliptic-curve cryptography at roughly 1,200 logical qubits and 90 million Toffoli gates in one configuration, or 1,450 logical qubits and 70 million in another. Mapped onto hardware, that is fewer than 500,000 physical qubits: about twenty times below the prior physical-qubit estimate for the same task. The work has been public since its preprint appeared on 30 March 2026 and was accepted by the journal on 6 July. None of the migration dates examined below has moved since. Is that silence negligence, or is it design?

The number that moved

The first thing to be exact about is that this is a resource estimate, not a demonstration. It describes a machine nobody has built, running circuits at error rates nobody has yet sustained at that scale. The second is that the runtime figure everyone quotes needs its condition attached. Executed straight through, the two configurations take 23 and 18 minutes. Only a primed attack — one where the precomputation is finished in advance and the machine is waiting when the key appears — comes down to roughly 12 and 9 minutes. That distinction is the whole operational story. A slow attack threatens stored secrets. An attack held primed and spent on demand threatens live ones, because it approaches the interval in which a transaction sits on a public network with its key visible and its confirmation pending. It does not comfortably fit inside that interval; it draws level with it, which is quite different from the headline reading.

Two findings cut against treating any of this as a countdown, and they cut in opposite directions. The same question answered on different hardware gives a very different answer: a neutral-atom estimate from Oratomic puts the task at about 26,000 physical qubits over several days — two orders of magnitude fewer qubits, running far too slowly to touch a confirmation window at all. Resource estimation compares architectures at least as much as it forecasts dates. Cutting the other way is the plainer point that a published estimate describes only the publicly known state of the art, and there is no reason to assume that is the best anyone has.

A smaller strand of this record deserves more attention than it has drawn, and it comes in two separable parts. Google withheld its strongest circuits and published a zero-knowledge proof instead, so the claim could be checked without the method being disclosed. Trail of Bits then attacked the implementation of that proof itself and got through it. Separately, and by a different route, André Schrottenloher used the existence of the hidden circuits as a prompt and independently constructed comparable ones of his own. Those are two different governance lessons. One says a proof system is only as strong as the code that runs it. The other says that in cryptanalysis, announcing that a better circuit exists is itself most of the disclosure. Together they argue for reading a published estimate as a floor on what is known rather than a ceiling.

The dates that did not

Set that against the instruments actually in force. In the United States, Executive Order 14412, signed 22 June 2026 and carried operationally by OMB memorandum M-26-15, requires federal high-value and high-impact systems to reach approved post-quantum key establishment by 31 December 2030 and post-quantum digital signatures by 31 December 2031, and directs a proposed Federal Acquisition Regulation rule extending obligations to covered contractors. Its reach beyond that is a matter of separate sector rulemaking, not of the order itself. In Europe, the roadmap announced in June 2025 has Member States beginning the transition by the end of 2026 and completing critical infrastructure by 2030. The International Civil Aviation Organization has been working toward a compatible passport specification around the middle of 2027, with backward compatibility as a hard constraint.

The chronology matters and it is not uniform. The US order was signed on 22 June 2026, nearly three months after the preprint appeared; the European roadmap and the ICAO target were both set in 2025, before it. So one instrument was written with this work already on the record and two were not — and none of the three has been publicly revised since. A search of official communications carried out on 22 August 2026 found nothing in the US, EU or ICAO record referring to the estimates: no revised date, no supervisory statement, no acknowledgement. Someone following only official channels would not know the number underneath the calendar had changed at all — the same quiet we described when the vulnerability record itself was rebuilt without a word about cryptography.

Practical takeaway. A resource estimate that falls does not shorten your migration. It shortens the margin on the part of your data that can never be re-keyed, and that part is usually a short list you can write down this week.

Why the calendar is right not to chase the paper

The honest answer to the opening question is that these deadlines were never derived from a resource estimate. They are procurement calendars. They track hardware refresh cycles, contract renewals, certification queues and the pace at which vendors can ship something a regulator will accept — and that pace is measurable. Crypto4A announced this week that its QASM module had obtained FIPS 140-3 Level 3 validation, certificate 5497 on the CMVP list, with support for the NIST post-quantum algorithms including ML-DSA and SLH-DSA. That validation covers the cryptographic module and nothing beyond it: it is not a certificate hierarchy, not a deployment and not a public-key infrastructure. Between a validated module and a working post-quantum certificate sits integration, key ceremony and issuance practice, none of which had produced a public announcement as of 22 August 2026. A deadline that outran that queue would not be a stricter deadline; it would be an unmeetable one, and unmeetable deadlines are how migration programs acquire their first exemption.

The second answer comes from inside the paper. Dan Boneh, one of its co-authors, has said plainly that a hasty transition to post-quantum cryptography is more likely to cause a catastrophic bug than a quantum attack is. That is an unusual sentence to find attached to a result that makes the attack look cheaper, and it is the most useful line in the week's record. The people best placed to read the number as an alarm are telling everyone else not to.

The third answer is the Dutch one. A norm that tracked every hydrological revision would have been useless to build against; the value of the Delta norm was that a contractor could price it and an inspector could test it. Migration standards work the same way. Estimates of this kind move roughly quarterly. Instruments that moved quarterly would produce a decade of replanning and no replacement.

Where that reasoning runs out

All of it holds on one condition: that the secret can be rotated. Where it cannot, the logic inverts, and the date in the instrument is not the real deadline at all.

The clearest case is sitting in a drawer in most households, and it needs to be stated carefully, because two different threat models get run together here. Passport chips carry a face image and, in many issuing states, fingerprints. A booklet issued in 2026 stays valid into the middle of the next decade; the biometric behind it is valid for a lifetime. The first threat model is confidentiality: whether a chip-reading session recorded today can be decrypted later depends on the access-control and key-establishment protocol in force when the chip was read, so harvest now, decrypt later applies to those sessions conditionally rather than universally — but where it applies, a face cannot be reissued the way a key can. The second is authenticity, and it is the one the document-signing infrastructure governs: once a signature algorithm falls, the question is not who can read a document but who can mint one that verifies. Those failures need different remedies on different timescales, which is part of why a standards date in 2027 carries more weight than its modest wording suggests. We made an adjacent point about how much state control now travels inside a passport.

Financial markets reached the same conclusion earlier, and without waiting for anyone to publish. Roughly 6.9 million bitcoin — close to a third of the 21-million maximum supply, including more than a million attributed to Satoshi — sit at addresses whose public keys are already visible on chain, which is precisely the exposure a primed attack is built for. In January 2026 Christopher Wood at Jefferies dropped a 10 percent bitcoin allocation from his model portfolio and named quantum risk as the reason — two months before the preprint appeared and five before the executive order was signed. That is a published recommendation rather than a measured capital flow, and it is worth exactly that much: one prominent strategist adjusted his stated allocation ahead of the record, while the instruments have not been adjusted since. Both responses are rational, because they answer for different things: one for a position that can be reversed next quarter, the other for a standard thousands of vendors must be able to meet.

The gap worth worrying about is in neither camp. A readiness survey published on 21 August found that 46 percent of organizations have nobody named as owner of their post-quantum migration, and that around half have never assessed their public-facing infrastructure to see what it actually negotiates. For those organizations the migration is not being managed; it is being done to them by their infrastructure providers, on a schedule they did not choose and cannot audit.

How Quentir Reads It

The right answer to a moving estimate is not a moving deadline. It is an inventory sorted by reversibility. Two questions do most of the work: can this secret be rotated, and how long does it have to stay secret? Everything in the first column can wait for the certification queue, because that queue is the binding constraint and no executive order shortens it. The second column — biometrics, genomic records, sealed archives, keys already published — needs splitting once more, and this is where the argument earns its keep. Whatever has already left your control and been captured is beyond any deadline; no instrument reaches it. Whatever is still under your control can still be protected against future capture, and for that material the calendar is real and worth meeting. The estimate narrowed the confidence interval around the threat. It did not move anything from one column to another.

What made the Dutch norm durable was not only that it separated the estimate from the standard. It also named who owned each stretch of dike. The post-quantum calendar has its standard; in roughly half of organizations it does not yet have the owner. That is the part of the problem no regulator can revise downward, and the part that will decide whether a 2030 date means anything.

The Signature Brief edition tracking this thread carries the dated jurisdiction-by-jurisdiction comparison behind the summary above, with the refresh triggers that separate a date which has genuinely moved from an estimate which has. This post is the reading; that edition is what survives being handed to whoever has to defend the schedule. How the thread has developed week by week is visible across our published posts.

The next thing to watch is not the next resource estimate. There will be one, and it will move again. It is the first certificate authority to announce post-quantum certificate issuance using keys held in a validated module, or the first product integration that puts one into service. Until something like that is announced, the calendar rests on standards that exist and deployments that mostly do not — and that, rather than any qubit count, is what would make a 2030 date slip.

Sources: Ryan Babbush, Craig Gidney, Adam Zalcman, Tanuj Khattar, Justin Drake, Dan Boneh and colleagues (a Google-led multi-institution team; Drake and Boneh are not Google Quantum AI authors), “Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities: Resource Estimates and Mitigations”, a Perspective accepted by PRX Quantum on 6 July 2026 and listed by APS as an accepted paper (DOI 10.1103/j3xf-bw18); no final volume or article number is claimed here, and the text above says “accepted” rather than “published in issue” for that reason. Preprint at arXiv:2603.28846, for the 1,200-logical-qubit/90-million-Toffoli and 1,450/70-million configurations, the sub-500,000 physical-qubit mapping and the roughly twentyfold reduction against the prior physical-qubit estimate, the 23- and 18-minute straight-execution runtimes, the 12- and 9-minute primed-attack runtimes, and the ~6.9 million bitcoin (against a 21-million maximum supply) held at addresses with public keys already exposed on chain. The preprint carries the 30 March 2026 date used above for the chronology against Executive Order 14412. Madelyn Cain and colleagues, arXiv:2603.28627, for the neutral-atom counterpart estimate of about 26,000 physical qubits over several days. Trail of Bits, “We beat Google’s zero-knowledge proof of quantum cryptanalysis”, 17 April 2026, for the attack on the proof implementation; André Schrottenloher, arXiv:2606.02235, separately, for the independent construction of comparable circuits prompted by the existence of the withheld ones — the two are distinct events and are described as such above. Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks”, signed 22 June 2026, with OMB memorandum M-26-15, for the 31 December 2030 key-establishment and 31 December 2031 signature dates for federal high-value and high-impact systems and the directed proposed Federal Acquisition Regulation rule for covered contractors. European Commission, “EU reinforces its cybersecurity with post-quantum cryptography”, June 2025, for the end-2026 start and 2030 critical-infrastructure roadmap dates and for the fact that the roadmap predates the March 2026 preprint. ICAO Facilitation Conference material, FALC 2025 presentation, for the 2027 specifications target discussed in 2025. The confidentiality-versus-authenticity distinction in the passport section follows the standing structure of the ICAO machine-readable travel document scheme, in which chip-session protection is a function of the access-control and key-establishment protocol used at read time while the country-signing and document-signer certificate hierarchy governs authenticity; no claim is made here about any specific issuing state's configuration. Crypto4A’s own announcement of FIPS 140-3 Level 3 validation for its QASM module, 19 August 2026, with CMVP certificate 5497, reported by Quantum Computing Report on 20 August 2026. On what that validation does and does not cover, see NIST’s Cryptographic Module Validation Program: the scope is a cryptographic module, not a certificate hierarchy, a deployment or an issuance practice, which is why the text above makes the narrower claim. Help Net Security, Axiad post-quantum migration readiness report, 21 August 2026, for the 46 percent no-named-owner figure and for the statement that around half of organizations have not assessed their public-facing infrastructure; that article does not itself publish a more precise second figure, and none is claimed above. Dan Boneh's caution on a hasty transition is quoted as reported in coverage of the paper since its March 2026 preprint; the primary transcript was not located for this post and the remark is presented as reported speech, not as a citation to the paper's text. The Block, “Jefferies’ Wood drops bitcoin allocation over quantum computing fears”, 16 January 2026, for the model-portfolio change; that is a published recommendation, and no measured capital flow is claimed above. The two negative statements above — that no US, EU or ICAO communication refers to these estimates and that no post-quantum certificate issuance using a validated module had been announced — are findings from a search of official communications and public announcements carried out on 22 August 2026, bounded to those jurisdictions and to public announcements; they are not assertions that no such action exists. Netherlands flood and standards history from the public record of the 1953 North Sea flood and the Delta Works programme, and from the risk-based flood-protection standards of the Dutch Water Act (Waterwet), which entered into force on 1 January 2017. All fast-moving claims above were checked against public sources on 22 August 2026.

Published intelligence, built to inform your own decisions. Published: August 22, 2026.

© 2026 Quentir Systems LLC
Previous
Previous

€1.05 Billion, and the IP Has to Stay in Romania

Next
Next

Five Days to Four Kelvin: Reading IBM's Modular Cryogenics Milestone