Google’s quantum calendar marks 2029 as the year encryption dies
Mark your diaries: 2029 is when every password, wallet and private message you own becomes crackable. Google Quantum AI’s latest roadmap, quietly circulated last month, pinpoints that year as the crossover moment when a fault-tolerant machine hits the 1,200-logical-qubit threshold needed to dismantle the elliptic-curve shields protecting Bitcoin, WhatsApp and the global banking rails.
The forecast is colder than any hype cycle. Previous guesses floated 2035 or even 2040. Google’s engineers now call those estimates “academic nostalgia”. They base the new timeline on two hard numbers: 1,200 stable qubits plus 90 million Toffoli gates can brute-force a 256-bit secp256k1 key in under six months. Hardware curves show that milestone arriving in three and a half years, not two decades.
Why six months feels like tomorrow
Classical supercomputers would need the age of the universe to guess the same scalar. A mature quantum processor shrinks the chore to a semester. Once the machine is up, whoever controls it can empty any un-updated wallet, forge any TLS certificate and read any retro-captured diplomatic cable. The patch, unfortunately, is not a patch. Swapping today’s algorithms for post-quantum replacements means touching every chipset, browser, smart-contract opcode and NFC card reader on Earth.
Bitcoin Core devs are already quarrelling over quantum-resistant address formats, but the network’s ossification is legendary. A backwards-incompatible fork—mandatory for new signature schemes—requires 95% miner consensus. The last time that happened was SegWit in 2017, and it took two years of trench warfare. This time the clock runs in the opposite direction.
Banks are in a tighter spot. Chip cards, POS terminals and HSMs baked into Visa’s rails cannot be reflashed over Wi-Fi. Replacing them implies a physical recall comparable to the 2000s EMV rollout, except now the penalty for delay is instant insolvency. South Korean police learned this the hard way when a university lab demoed a 48-qubit rig and siphoned $4 million of seized crypto from an evidence wallet. The heist lasted four minutes; the paperwork will last longer.

The post-quantum mirage
NIST finally published its first batch of quantum-safe standards last summer—algorithms with names like Kyber and Dilithium that sound like sci-fi villains. They are heavier, slower and demand key sizes triple those of ECC. Embedding them in a smart-contact lens or an insulin pump is an engineering tantrum waiting to happen. Worse, nobody can guarantee the algorithms will survive the next round of cryptanalytic games. The uncomfortable truth: we are fleeing from a cliff while rebuilding the road beneath us.
Google, IBM and IonQ will sell you cloud cycles today, but they also sell the antidote—consulting packages to audit your own extinction. The business model is elegant: create the disease, then invoice for the placebo. Meanwhile, intelligence agencies are stockpiling old encrypted traffic on air-gappedarrays, patiently waiting for the qubit count to tick past 1,200. They call it “Y2Q”, and they have a shared Google calendar too.
Three years is shorter than a single console generation. It is the gap between Apple’s M1 and M3 chips, between two World Cups, between a presidential campaign and its re-election. In cryptography, that is the blink of an eye. Either the hardware stalls—an outcome physicists deem unlikely—or civilization undertakes the largest cryptographic migration in history while the clock runs backward. The bet is binary, and the house uses quantum dice.
