Challenges
Datasets
Workspaces
Discussions
Leaderboard
Log inSign up
Challenges
Datasets
Workspaces
Discussions
Leaderboard
Blog
Job Board
Q3AS

© 2026 Aqora Quantum S.A.S.

TermsPrivacyLegal Notice
Research Papers

Research Papers

Share and discuss quantum computing research

last post 1h ago by aqora_bot
Aqora Botaqora_bot

1

Posted 1h ago

Computing 256-bit elliptic curve discrete logarithms in 26 days on a fault-tolerant trapped-ion quantum computer with 20,000 qubits

External link
Thomas Häner, Felix Tripier, Jacob Young, Michael Naehrig, Andrii Maksymov, Safwan Alam, Dmitri Maslov, Matthew Parrott, Yvette de Sereville, Jordan Sullivan, Mark Webster, Nicolas Delfosse, John Gamble, Martin Roetteler (Sep 09 2026).
Abstract: One of the strengths of our recently proposed Walking Cat Architecture for a trapped-ion quantum computer is that it is straightforward to extend and optimize for a specific application. As a proof-of-concept, here we present such optimizations for solving the 256256256-bit elliptic curve discrete logarithm problem (ECDLP) on secp256k1\mathtt{secp256k1}secp256k1, which is the elliptic curve used by blockchain technologies such as Bitcoin, using Shor's algorithm. We optimize the circuits from Schrottenloher's recent work and arrive at a logical quantum circuit for solving the ECDLP using about 145014501450 qubits and 40⋅10640\cdot 10^640⋅106 Toffoli gates, with a rigorous lower bound on the logical-level success probability that holds with confidence at least 1−2−1281-2^{-128}1−2−128. Using our compilation toolchain with manual optimization of the logical layout and integrated routing, we produce estimates for the logical measurement depth and the required number of physical qubits by compiling all components to measurement schedules that obey the architectural constraints. A key ingredient is a fast CCZ magic-state factory and a depth-one CCZ state injection, reducing the execution time of CCZ gates by a factor of 313131. We increase the logical-measurement parallelism using non-overlapping cat-based measurements in parallel, and we leverage the recently proposed logical CliNR protocol to speed up Clifford operations. To reduce the qubit overhead, we introduce a more efficient loss correction protocol, design a layout that allows us to recycle the CliNR ancilla qubits, and provision reusable cat-state resources according to the circuit's peak measurement parallelism. All results and optimizations combined, we conclude that a trapped-ion quantum computer based on our architecture can solve the ECDLP on secp256k1\mathtt{secp256k1}secp256k1 in approximately 25.7 days using 19,397 physical qubits with an estimated success probability of 63%63\%63%.
Arxiv: https://arxiv.org/abs/2609.05625

Order by:

Want to join this discussion?

Join our community today and start discussing with our members by participating in exciting events, competitions, and challenges. Sign up now to engage with quantum experts!

LoginSign up