THE QUANTUM THREAT / ADVANCED

Elliptic Curves Fall First: The 2026 Quantum Estimates For ECC

Estimates published in 2026 suggest 256-bit elliptic curve keys need fewer quantum resources to break than RSA-2048. Here is what the papers claim, what they assume and which points are contested.

Checked against primary sources and independently reviewed on . Sources are listed at the end.

Elliptic curve cryptography (ECC) became popular because it gives the same classical security as RSA with much shorter keys. TLS 1.3 supports elliptic curve Diffie-Hellman for key exchange and ECDSA and EdDSA for certificate signatures,1 and elliptic curve signatures also secure software, devices and most cryptocurrencies. Short keys turn out to have a downside. Against Shor’s algorithm, smaller numbers mean a smaller quantum circuit.

This article sets out the resource estimates for breaking 256-bit elliptic curve keys, especially the burst of results in March 2026, and compares them with the RSA-2048 figures covered in How Many Qubits To Break RSA. It is current as of October 2026. These numbers have moved quickly and are likely to move again.

Why Smaller Keys Are Easier Targets

Shor’s algorithm attacks the discrete logarithm problem on elliptic curves just as it attacks factoring. The circuit’s size depends mainly on the size of the numbers involved. NIST rates a 256-bit elliptic curve key as comparable in classical strength to a 3072-bit RSA key, both at 128 bits,2 yet the quantum computer only has to work with 256-bit values.

That was clear well before 2026. In 2017 Roetteler, Naehrig, Svore and Lauter derived precise costs for elliptic curve discrete logarithms. For a curve over an n-bit prime field they needed at most 9n plus a small term logical qubits, which comes to about 2,330 for P-256. They concluded that at comparable classical security levels, elliptic curves need fewer qubits than RSA, making ECC “an easier target than RSA”.3

The Estimates Over Time

  1. About 2,330 Logical Qubits

    Roetteler and colleagues, P-256. Concludes ECC is an easier quantum target than RSA.

  2. 2,124 Logical Qubits

    Häner and colleagues, as cited by Chevignard, Fouque and Schrottenloher.

  3. About 1,193 Logical Qubits, Far More Gates

    Chevignard, Fouque and Schrottenloher, EUROCRYPT 2026. Trades space for a much larger gate count.

  4. Under 1,200 Logical Qubits And Under 90 Million Toffoli Gates

    Babbush, Gidney, Boneh and colleagues. Under half a million physical superconducting qubits, runtime in minutes.

  5. 26,000 Atoms, A Few Days

    Cain and colleagues, neutral atom architecture, P-256.

Selected resource estimates for the 256-bit elliptic curve discrete logarithm problem. All are blueprints for machines that do not yet exist.

Fewer logical qubits, more gates. Chevignard, Fouque and Schrottenloher, in a paper for EUROCRYPT 2026, reduced the logical qubits for the P-256 discrete logarithm to 1,193, down from 2,124 in a 2020 estimate by Häner and colleagues. The cost is a far higher gate count: about 2 to the power 39 Toffoli gates in each of 22 independent runs, against roughly 2 to the power 30 in the earlier estimate.4 The result shows how qubit counts and gate counts trade against each other, which matters when reading headline numbers.

Google Quantum AI and collaborators. On 30 March 2026, Babbush, Zalcman, Gidney, Broughton, Khattar, Neven, Bergamaschi, Drake and Boneh published estimates for the 256-bit elliptic curve discrete logarithm problem that underpins most cryptocurrency signatures. They give two variants: fewer than 1,200 logical qubits with fewer than 90 million Toffoli gates, or fewer than 1,450 logical qubits with fewer than 70 million. On superconducting hardware with a 0.1 percent physical error rate and planar connectivity, they say the attack could run in minutes on fewer than 500,000 physical qubits.5

Neutral atoms. The same day, Cain and colleagues estimated that a reconfigurable neutral atom machine with 26,000 physical qubits could compute P-256 discrete logarithms in a few days under plausible assumptions, while RSA-2048 would take one to two orders of magnitude longer on the same design.6

Side By Side With RSA-2048

The RSA-2048 column below uses Gidney’s 2025 figures.7

RSA-2048256-bit Elliptic Curve
Logical qubits1,399 (Gidney, 2025)Under 1,200 to 1,450 (Babbush and colleagues, 2026); about 1,193 with far more gates (Chevignard and colleagues, 2026)
Toffoli gatesAbout 6.5 billion (Gidney, 2025)Under 70 to 90 million (Babbush and colleagues, 2026)
Physical qubits, superconducting surface codeUnder 1 million (Gidney, 2025)Under 500,000 (Babbush and colleagues, 2026)
Runtime at those sizesUnder a weekMinutes
Neutral atomsOne to two orders of magnitude slower than P-256 (Cain and colleagues, 2026)A few days with 26,000 atoms (Cain and colleagues, 2026)
Assumed physical error rate0.1 percent0.1 percent (superconducting estimates)
Published estimates as of October 2026. Different papers use different assumptions, so treat this as an order-of-magnitude comparison.

The striking row is the gate count. On these figures, the elliptic curve attack needs roughly seventy to ninety times fewer Toffoli gates than Gidney’s RSA-2048 construction. That gap goes a long way to explaining why the runtime falls from days to minutes on similar hardware, although the papers also differ in layout and qubit counts.

Fast Clocks, Slow Clocks And Why Runtime Matters

The Google paper distinguishes fast-clock architectures, such as superconducting and photonic machines, from slow-clock ones, such as neutral atoms and trapped ions.5 The distinction matters because the uses of a quantum attack differ.

For harvest now, decrypt later, runtime barely matters. An attacker reading a stored archive can wait days per key. For forging a signature in real time, runtime is everything. The Google authors argue that the first fast-clock machines could attack some cryptocurrency transactions in the short window between broadcast and confirmation.5 A slow-clock machine taking days per key could not, but it would still threaten long-lived public keys and recorded traffic.

What This Means For Organisations

The practical message does not depend on which estimate proves most accurate. Elliptic curve keys are not a safer choice than RSA against quantum attack, and on current evidence they are likely to fall first. Organisations that moved from RSA to ECC for efficiency have not reduced their quantum exposure.

That puts elliptic curve key exchange in TLS, VPNs and messaging at the front of the queue for post-quantum or hybrid key exchange, which addresses harvesting risk. It also puts long-lived ECDSA keys, such as those for code signing, device identity and digital assets, high on the list for migration to post-quantum signatures. The replacement algorithms are covered in the Post-Quantum Cryptography group.

Footnotes

  1. IETF, RFC 8446, “The Transport Layer Security (TLS) Protocol Version 1.3”, August 2018. rfc-editor.org ↩

  2. NIST, SP 800-57 Part 1 Revision 5, “Recommendation for Key Management: Part 1, General”, May 2020, table 2. nvlpubs.nist.gov ↩

  3. M. Roetteler, M. Naehrig, K. M. Svore and K. Lauter, “Quantum resource estimates for computing elliptic curve discrete logarithms”, arXiv 1706.06752, June 2017 (ASIACRYPT 2017). arxiv.org ↩

  4. C. Chevignard, P.-A. Fouque and A. Schrottenloher, “Reducing the Number of Qubits in Quantum Discrete Logarithms on Elliptic Curves”, IACR ePrint 2026/280 (EUROCRYPT 2026). eprint.iacr.org ↩

  5. R. Babbush and others (Google Quantum AI and collaborators), “Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities: Resource Estimates and Mitigations”, arXiv 2603.28846, 30 March 2026, revised 15 April 2026. arxiv.org ↩ ↩2 ↩3 ↩4

  6. M. Cain and others, “Shor’s algorithm is possible with as few as 10,000 reconfigurable atomic qubits”, arXiv 2603.28627, 30 March 2026. arxiv.org ↩ ↩2

  7. C. Gidney, “How to factor 2048 bit RSA integers with less than a million noisy qubits”, arXiv 2505.15917, 21 May 2025, table 5 and section 3.2. arxiv.org ↩

Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.