Blog · From the JoS QUANTUM team

Notes on quantum, in the real world.

Research, engineering write-ups, and perspectives on putting quantum algorithms to work in finance, security, and energy.

Terminal-style summary of quantum risk to Bitcoin and Ethereum: breaking ECDLP on secp256k1 needs 1,200 logical qubits and 90M Toffoli gates, ~6.9M BTC vulnerable including 1.7M in P2PK, 20.5M ETH exposed with the top 1,000 accounts crackable in under nine days, and a 41% on-spend attack window from a 9-minute attack against a 10-minute block
17 Jul 2026 · Research note · Part 2

Post-quantum security for Bitcoin and Ethereum: an account-type autopsy

Roughly 6.9 million BTC and 20.5 million ETH sit behind quantum-vulnerable keys. Which script and account types are exposed, why address reuse matters more than your address prefix, and what the 2026 Google–Ethereum Foundation whitepaper means for custody, stablecoins and tokenised assets.

Terminal-style summary of what quantum computers break: RSA, ECDSA and ECDH broken by Shor in polynomial time; AES-256 and SHA-256 intact because Grover is only quadratic; an ML-DSA signature is 2,420 bytes, 38× larger than ECDSA; FIPS 203, 204 and 205 final while FIPS 206 is still draft
17 Jul 2026 · Explainer · Part 1

Post-quantum cryptography: what actually breaks, and what replaces it

A quantum computer does not break “encryption” — it breaks one load-bearing part of it and leaves the rest nearly intact. Why Shor is catastrophic and Grover is not, why bigger keys don’t help, the NIST standards that replace ECDSA, and what they cost in bytes.

Terminal-style summary of Google Willow's surface-code memory: logical error 0.143% per cycle, error suppression Λ = 2.14 confirming below-threshold operation, 101 physical qubits per logical qubit, 1.1 µs cycle time, and an extrapolation to distance 27 and ~1,457 qubits for a 10⁻⁶ logical error rate
16 Jul 2026 · Explainer

Quantum error correction on superconducting hardware: the fast clock and its price

From first principles to a 2026 reality check — how error correction works, why the surface code fits a superconducting chip, what Willow actually demonstrated, and the leakage, drift, decoding and cosmic-ray problems still between it and a machine.

Terminal-style quantum amplitude-estimation run of the business-risk model: tail risk P(loss ≥ €50M), QAE estimate 0.146 vs exact 0.119, quadratic speedup error ~ 1/N, and the Grover × QAE quartic sensitivity analysis
15 Jul 2026 · Demo walkthrough

Inside the risk demo: estimating tail risk on a quantum computer

A guided tour of our interactive quantum risk model — how a network of business risks becomes a quantum circuit, how amplitude estimation reads the tail with a quadratic speedup over Monte Carlo, and how stacking Grover search makes the sensitivity analysis quartic.

Terminal-style estimate for RSA-2048: ~6,190 logical qubits, ~2.6 billion Toffoli gates, ~20 million physical qubits, ~8 hours runtime, projected breakable 2039–2041
10 Jul 2026 · Demo walkthrough

Inside the Shor demo: what it takes to break an RSA key

A guided tour of our interactive Shor estimator — what each number means (logical qubits, Toffoli gates, physical qubits, runtime), the scaling laws behind them, and how a key size becomes a projected break-year.

Chart: physical-qubit estimates to break RSA-2048 and ECC-256 collapsing across successive studies from 2019 to 2026
15 Jul 2026 · Research note

Why quantum error correction — not qubit count — decides when RSA and ECC fall

RSA and ECC will fall to how efficiently Shor’s algorithm compiles into fault-tolerant gates — not raw qubit count. A look at the collapsing resource estimates for RSA-2048 and ECC-256.