<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Technology on kenji.blog</title><link>http://kenji.blog/en/categories/technology/</link><description>Recent content in Technology on kenji.blog</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>kenjinote</copyright><lastBuildDate>Fri, 11 Sep 2026 18:00:00 +0900</lastBuildDate><atom:link href="http://kenji.blog/en/categories/technology/index.xml" rel="self" type="application/rss+xml"/><item><title>What is Quantum Supremacy? Latest Trends from Google and IBM</title><link>http://kenji.blog/en/p/what-is-quantum-supremacy-google-ibm/</link><pubDate>Fri, 11 Sep 2026 18:00:00 +0900</pubDate><guid>http://kenji.blog/en/p/what-is-quantum-supremacy-google-ibm/</guid><description>&lt;img src="http://kenji.blog/p/what-is-quantum-supremacy-google-ibm/img/eyecatch.jpg" alt="Featured image of post What is Quantum Supremacy? Latest Trends from Google and IBM" />&lt;h2 id="1-introduction-the-dawn-of-quantum-computing-and-quantum-supremacy">1. Introduction: The Dawn of Quantum Computing and &amp;ldquo;Quantum Supremacy&amp;rdquo;
&lt;/h2>&lt;p>Quantum computing has the potential to solve complex problems that cannot be solved within a realistic timeframe by classical computers (the PCs and supercomputers we use daily) by applying quantum mechanics, the fundamental principle of physics, to information processing. For a long time, this field was primarily focused on theoretical research, but in recent years, rapid hardware advancements have intensified the race toward practical application.&lt;/p>
&lt;p>One of the most attention-grabbing keywords in this context is &amp;ldquo;Quantum Supremacy.&amp;rdquo; This refers to the moment when a quantum computer demonstrates overwhelming computational power over classical computers in a specific computational task. In this article, starting from the strict definition of quantum supremacy, we will provide a detailed technical and mathematical deep dive into the 2019 experiment by Google&amp;rsquo;s &amp;ldquo;Sycamore&amp;rdquo; processor—which was announced as the first in the world to reach this milestone—as well as IBM&amp;rsquo;s rebuttal and unique approach, and the latest roadmap towards &amp;ldquo;Quantum Error Correction (QEC)&amp;rdquo; and &amp;ldquo;Fault-Tolerant Quantum Computing (FTQC),&amp;rdquo; which represent the biggest barriers to true practical application.&lt;/p>
&lt;hr>
&lt;h2 id="2-theoretical-background-fundamentals-of-quantum-computing-and-complexity-classes">2. Theoretical Background: Fundamentals of Quantum Computing and Complexity Classes
&lt;/h2>&lt;p>To understand quantum supremacy, it is first necessary to understand the mathematical foundations of quantum computing and its position in computational complexity theory.&lt;/p>
&lt;h3 id="qubits-and-superposition">Qubits and Superposition
&lt;/h3>&lt;p>While the smallest unit of information in a classical computer is a bit (0 or 1), a quantum computer uses a qubit (Quantum bit). The state $|\psi\rangle$ of a single qubit is represented by a complex linear combination of the basis states $|0\rangle$ and $|1\rangle$.&lt;/p>
$$
|\psi\rangle = \alpha|0\rangle + \beta|1\rangle
$$
&lt;p>Here, $\alpha, \beta \in \mathbb{C}$, and they satisfy the normalization condition $|\alpha|^2 + |\beta|^2 = 1$. This property is called &amp;ldquo;Superposition.&amp;rdquo;&lt;/p>
&lt;h3 id="entanglement-and-tensor-product">Entanglement and Tensor Product
&lt;/h3>&lt;p>When there are multiple qubits, the state of the entire system is represented by the tensor product of the state spaces of the individual qubits. A system of $n$ qubits becomes a vector on a $2^n$-dimensional Hilbert space $\mathcal{H}^{\otimes n}$.&lt;/p>
$$
|\Psi\rangle = \sum_{x \in \{0, 1\}^n} c_x |x\rangle
$$
&lt;p>Here, $\sum |c_x|^2 = 1$. A state where qubits are not independent, and the state of one depends on the other, is called &amp;ldquo;Quantum Entanglement.&amp;rdquo; This gives quantum computers the potential to simultaneously process an exponentially vast state space.&lt;/p>
&lt;h3 id="computational-complexity-theory-definition-of-quantum-supremacy">Computational Complexity Theory Definition of Quantum Supremacy
&lt;/h3>&lt;p>In computational complexity theory, the class of problems that classical computers can solve efficiently (in polynomial time) is called &lt;strong>BPP&lt;/strong> (Bounded-error Probabilistic Polynomial time). On the other hand, the class of problems that quantum computers can solve efficiently is &lt;strong>BQP&lt;/strong> (Bounded-error Quantum Polynomial time).&lt;/p>
&lt;p>Demonstrating quantum supremacy means &amp;ldquo;executing a specific task on actual quantum hardware that is included in BQP but not in BPP (or is extremely likely not to be), and surpassing simulation by classical supercomputers in terms of time and resources.&amp;rdquo; It can be considered a historical attempt to falsify the extended Church-Turing thesis (&amp;ldquo;Any physically realizable computational model can be simulated by a probabilistic Turing machine in polynomial time&amp;rdquo;) through physical experiment.&lt;/p>
&lt;hr>
&lt;h2 id="3-2019-googles-demonstration-of-quantum-supremacy">3. 2019: Google&amp;rsquo;s Demonstration of Quantum Supremacy
&lt;/h2>&lt;p>In October 2019, the Google Quantum AI team announced in the scientific journal &lt;em>Nature&lt;/em> that they had achieved quantum supremacy using a 53-qubit superconducting processor called &amp;ldquo;Sycamore.&amp;rdquo;&lt;/p>
&lt;h3 id="architecture-of-the-sycamore-processor">Architecture of the Sycamore Processor
&lt;/h3>&lt;p>The Sycamore processor consists of 54 transmon superconducting qubits arranged in a 2D grid (53 were used in the experiment as one was malfunctioning). Tunable couplers are placed between adjacent qubits, realizing fast and highly accurate two-qubit gates (a hybrid of iSWAP and controlled-Z gates).&lt;/p>
&lt;div class="mermaid">graph TD
A["Quantum Algorithm Input"] --> B["Sycamore Processor (53 Qubits)"]
B --> C["Apply Random Quantum Gates"]
C --> D["Measure Quantum States (Bitstrings)"]
D --> E["Cross-Entropy Benchmarking (XEB)"]
E --> F["Verify Quantum Supremacy"]&lt;/div>
&lt;h3 id="random-circuit-sampling-rcs">Random Circuit Sampling (RCS)
&lt;/h3>&lt;p>The task Google chose was &amp;ldquo;Random Circuit Sampling.&amp;rdquo; This involves applying randomly chosen single-qubit gates and two-qubit gates over multiple cycles (depth $m$), and sampling from the probability distribution of bitstrings obtained by measuring the final state.&lt;/p>
&lt;p>The probability of a bitstring $x$ output from an ideal (noise-free) random quantum circuit is not a uniform distribution, but exhibits an interference fringe-like pattern called a Porter-Thomas distribution. To sample from this distribution on a classical computer requires simulating the entire state vector, and the computational complexity increases exponentially with respect to the number of qubits $n$ and the circuit depth $m$.&lt;/p>
&lt;h3 id="evaluating-fidelity-linear-cross-entropy-benchmarking-xeb">Evaluating Fidelity: Linear Cross-Entropy Benchmarking (XEB)
&lt;/h3>&lt;p>To prove that the experimental results were not just noise, but the results of actual quantum computation, Google used Linear Cross-Entropy Benchmarking (XEB). The ideal probability $P(x_i)$ of the circuit for the bitstring $x_i$ obtained in the experiment is calculated using a classical computer, and the fidelity $\mathcal{F}_{\text{XEB}}$ is obtained by the following formula:&lt;/p>
$$
\mathcal{F}_{\text{XEB}} = 2^n \langle P(x_i) \rangle_{i} - 1
$$
&lt;p>If $\mathcal{F}_{\text{XEB}}$ is 0, it means complete noise, and if it is 1, it means an ideal quantum processor without noise. The Sycamore processor achieved $\mathcal{F}_{\text{XEB}} \approx 0.002$ (0.2%) for a circuit with depth 20. At first glance, this seems low, but it is a statistically significant value above zero, representing an astonishing achievement of controlling a state space of $2^{53} \approx 9 \times 10^{15}$.&lt;/p>
&lt;p>The overall error rate was approximately modeled as the product of individual gate errors, measurement errors, etc.&lt;/p>
$$
\mathcal{F} \approx (1 - e_1)^{N_1}(1 - e_2)^{N_2} \cdots \approx \prod_{g \in 1Q} (1 - e_g) \prod_{g \in 2Q} (1 - e_g) \prod_{q} (1 - e_{RO})
$$
&lt;p>(* $e_g$ is the gate error, $e_{RO}$ is the measurement error)&lt;/p>
&lt;p>Google claimed that it would take a classical supercomputer (Summit) about 10,000 years to simulate this circuit. In contrast, Sycamore completed the sampling in just 200 seconds.&lt;/p>
&lt;hr>
&lt;h2 id="4-ibms-rebuttal-from-supremacy-to-utility">4. IBM&amp;rsquo;s Rebuttal: From &amp;ldquo;Supremacy&amp;rdquo; to &amp;ldquo;Utility&amp;rdquo;
&lt;/h2>&lt;p>Google&amp;rsquo;s announcement shocked the world, but IBM, which developed the world&amp;rsquo;s largest supercomputer &amp;ldquo;Summit&amp;rdquo; and is itself a leader in quantum computer development, immediately published a paper rebutting this claim.&lt;/p>
&lt;h3 id="improving-classical-simulation-via-tensor-network-contraction">Improving Classical Simulation via Tensor Network Contraction
&lt;/h3>&lt;p>The core of IBM&amp;rsquo;s rebuttal was that &amp;ldquo;the optimization of algorithms and resources on the classical computer side was insufficient.&amp;rdquo; Google assumed a state vector simulator that directly calculates the time evolution of the Schrödinger equation and came up with the 10,000-year estimate. However, IBM pointed out that the simulation time could be dramatically reduced by using a method called a &amp;ldquo;Tensor Network.&amp;rdquo;&lt;/p>
&lt;p>In a tensor network, the gate operations of a quantum circuit are represented as operations on multi-dimensional arrays (tensors), and the order of network &amp;ldquo;contraction&amp;rdquo; is optimized. Furthermore, they claimed that by fully utilizing Summit&amp;rsquo;s massive 250 PB of storage (hierarchical disk and memory), a higher-precision simulation would be possible in just &amp;ldquo;2.5 days&amp;rdquo; while maintaining the entire state vector.&lt;/p>
&lt;h3 id="quantum-advantage-and-quantum-utility">Quantum Advantage and Quantum Utility
&lt;/h3>&lt;p>Triggered by this debate, the trend in the entire industry shifted from merely adhering to &amp;ldquo;executing artificial tasks impossible for classical computers (Supremacy)&amp;rdquo; to a phase of &amp;ldquo;demonstrating a practical advantage over classical approaches in useful real-world problems (Quantum Advantage),&amp;rdquo; and further to &amp;ldquo;quantum computers functioning as new tools for scientific discovery (Quantum Utility).&amp;rdquo;&lt;/p>
&lt;p>IBM itself avoided the word &amp;ldquo;Supremacy&amp;rdquo; and advocated &amp;ldquo;Quantum Volume&amp;rdquo; and &amp;ldquo;CLOPS (Circuit Layer Operations Per Second)&amp;rdquo; as comprehensive performance metrics for quantum processors, promoting development that emphasizes a balance between hardware scale and quality.&lt;/p>
&lt;div class="mermaid">timeline
title "The Evolution of Quantum Milestones"
2019 : "Google Sycamore (53Q)" : "Quantum Supremacy announcement"
2019 : "IBM Rebuttal" : "Summit supercomputer simulation in 2.5 days"
2021 : "IBM Eagle (127Q)" : "Breaking the 100-qubit barrier"
2022 : "IBM Osprey (433Q)" : "Advancing processor scale"
2023 : "Google Surface Code" : "Scaling error correction (d=3 to d=5)"
2023 : "IBM Quantum Utility" : "Complex spin model simulation on 127Q"
2024 : "Beyond" : "Logical Qubits and Error Mitigation era"&lt;/div>
&lt;hr>
&lt;h2 id="5-the-next-frontier-error-mitigation-and-quantum-error-correction-qec">5. The Next Frontier: Error Mitigation and Quantum Error Correction (QEC)
&lt;/h2>&lt;p>Current quantum computers are called &amp;ldquo;NISQ (Noisy Intermediate-Scale Quantum),&amp;rdquo; and they are susceptible to noise (errors due to interactions with the external environment or imperfect control). When performing long computations, the results get buried in noise. There are broadly two approaches to overcoming this problem: &amp;ldquo;Error Mitigation&amp;rdquo; and &amp;ldquo;Quantum Error Correction.&amp;rdquo;&lt;/p>
&lt;h3 id="error-mitigation">Error Mitigation
&lt;/h3>&lt;p>Error mitigation is a method to remove the effects of noise from the expected values of calculation results through classical post-processing without changing the quantum hardware. In 2023, IBM achieved a precision that surpassed state-of-the-art approximate tensor network methods in a time evolution simulation of a complex Ising model by combining its 127-qubit &amp;ldquo;Eagle&amp;rdquo; processor with error mitigation techniques such as &amp;ldquo;Zero-Noise Extrapolation (ZNE),&amp;rdquo; thereby demonstrating &amp;ldquo;Quantum Utility.&amp;rdquo;&lt;/p>
&lt;h3 id="quantum-error-correction-qec-and-logical-qubits">Quantum Error Correction (QEC) and Logical Qubits
&lt;/h3>&lt;p>However, to ultimately run any arbitrary complex algorithm (e.g., Shor&amp;rsquo;s factoring algorithm or complex quantum chemistry calculations), error mitigation alone is insufficient, and &amp;ldquo;Quantum Error Correction (QEC),&amp;rdquo; which dynamically detects and corrects errors, is essential.&lt;/p>
&lt;p>The mainstream approach for QEC is the &amp;ldquo;Surface Code.&amp;rdquo; This is a method where multiple physical qubits (data qubits) are arranged in a 2D grid, and measurement qubits (ancilla qubits) are placed between them to continuously perform parity checks called &amp;ldquo;Stabilizers.&amp;rdquo;&lt;/p>
&lt;div class="mermaid">graph LR
Q1["Data Qubit (Data)"] --- M1["Measure X Stabilizer (Ancilla)"]
Q2["Data Qubit (Data)"] --- M1
Q3["Data Qubit (Data)"] --- M2["Measure Z Stabilizer (Ancilla)"]
Q4["Data Qubit (Data)"] --- M2
M1 --> EC["Error Syndrome Decoding (Classical)"]
M2 --> EC
EC --> LQ["Logical Qubit State Update"]&lt;/div>
&lt;h4 id="the-threshold-theorem-and-distance-d">The Threshold Theorem and Distance $d$
&lt;/h4>&lt;p>A &amp;ldquo;Threshold Theorem&amp;rdquo; exists in quantum error correction. When the error rate $p$ of physical qubits is below a certain threshold $p_{th}$ (around 1% for the surface code), increasing the code distance $d$ (allocating more physical qubits to a single logical qubit) can exponentially reduce the logical error rate $p_L$.&lt;/p>
&lt;p>The approximate formula for the logical error rate is expressed as follows:&lt;/p>
$$
p_L \approx \Lambda \left( \frac{p}{p_{th}} \right)^{\frac{d+1}{2}}
$$
&lt;p>Here, $\Lambda$ is a constant. If $p &lt; p_{th}$, increasing $d$ makes $p_L$ smaller. However, if $p > p_{th}$, increasing physical qubits conversely accumulates noise, worsening the logical error rate.&lt;/p>
&lt;h4 id="googles-2023-milestone-demonstrating-error-reduction-by-scaling-distance">Google&amp;rsquo;s 2023 Milestone: Demonstrating Error Reduction by Scaling Distance
&lt;/h4>&lt;p>In February 2023, Google published a monumental paper in &lt;em>Nature&lt;/em>. They became the first in the world to demonstrate that when expanding the distance of the surface code from $d=3$ (using 17 physical qubits) to $d=5$ (using 49 physical qubits) using their 3rd generation Sycamore processor, the logical error rate slightly decreased from 3.028% to 2.914%.&lt;/p>
&lt;p>This means they have stepped into the region where $p &lt; p_{th}$, showing that the most important Proof of Concept towards FTQC—where performance improves as more physical qubits are added—has been completed.&lt;/p>
&lt;hr>
&lt;h2 id="6-roadmap-and-prospects-for-ftqc-fault-tolerant-quantum-computing">6. Roadmap and Prospects for FTQC (Fault-Tolerant Quantum Computing)
&lt;/h2>&lt;p>While adopting different architectures and approaches, Google and IBM are engaged in fierce development competition towards the ultimate goal of FTQC (Fault-Tolerant Quantum Computing).&lt;/p>
&lt;h3 id="ibms-approach-modularization-and-heavy-hex-lattices">IBM&amp;rsquo;s Approach: Modularization and Heavy-Hex Lattices
&lt;/h3>&lt;p>IBM is focusing on scaling up processors in parallel with drastically reducing error rates. While challenging the limits of single chips with &amp;ldquo;Eagle (127Q),&amp;rdquo; &amp;ldquo;Osprey (433Q),&amp;rdquo; and &amp;ldquo;Condor (1121Q),&amp;rdquo; they announced a modular architecture called &amp;ldquo;Quantum System Two.&amp;rdquo; In addition, for the qubit coupling topology, they have adopted a &amp;ldquo;Heavy-Hex lattice&amp;rdquo; that reduces unnecessary crosstalk and increases stability. IBM&amp;rsquo;s strategy is a hybrid approach that gradually introduces QEC while pursuing utility through advanced error mitigation in the short term.&lt;/p>
&lt;h3 id="googles-approach-improving-logical-qubit-quality">Google&amp;rsquo;s Approach: Improving Logical Qubit Quality
&lt;/h3>&lt;p>Google&amp;rsquo;s strategy places greater emphasis on extremely lowering the error rate of a single logical qubit (e.g., down to $10^{-6}$) rather than rapidly increasing the number of physical qubits. Upon achieving this, they aim for a large-scale system that runs thousands to tens of thousands of physical qubits in parallel by establishing technologies for transferring quantum states between modules (Quantum Interconnects).&lt;/p>
&lt;p>Implementing protocols to fault-tolerantly execute non-Clifford gates, such as Magic State Distillation, will also be a major technical hurdle in the future. To run a practical Shor&amp;rsquo;s algorithm and crack a 2048-bit RSA cipher, it is said that thousands of logical qubits with an error rate of $10^{-8}$ or less are required, equating to millions to tens of millions of physical qubits, meaning the journey is still long.&lt;/p>
&lt;hr>
&lt;h2 id="7-conclusion">7. Conclusion
&lt;/h2>&lt;p>&amp;ldquo;Quantum Supremacy&amp;rdquo; was an important milestone in the history of quantum computers that physically proved the theoretical potential of computing machines. Google&amp;rsquo;s 2019 demonstration and IBM&amp;rsquo;s constructive rebuttal pushed the entire industry from mere theoretical proof into an era of genuine engineering towards the pursuit of actual Utility and, ultimately, Fault-Tolerant Quantum Computing (FTQC).&lt;/p>
&lt;p>Currently, we are witnessing a transitional phase from noisy NISQ devices to logical qubit devices equipped with error correction. In the next five to ten years, new discoveries in materials science, revolutions in the drug discovery process, and breakthroughs in optimization problems will likely become a reality alongside the evolution of this quantum hardware.&lt;/p>
&lt;p>We must keep a close eye on the movements of Google, IBM, and researchers worldwide who are shaping the future of computer science.&lt;/p></description></item><item><title>How Will Blockchain and Cryptocurrencies Change in the Post-Quantum Era?</title><link>http://kenji.blog/en/p/post-quantum-blockchain-and-crypto/</link><pubDate>Fri, 11 Sep 2026 17:00:00 +0900</pubDate><guid>http://kenji.blog/en/p/post-quantum-blockchain-and-crypto/</guid><description>&lt;img src="http://kenji.blog/p/post-quantum-blockchain-and-crypto/img/eyecatch.jpg" alt="Featured image of post How Will Blockchain and Cryptocurrencies Change in the Post-Quantum Era?" />&lt;h2 id="1-introduction-the-footsteps-of-the-post-quantum-era-and-the-crisis-of-blockchain">1. Introduction: The Footsteps of the Post-Quantum Era and the Crisis of Blockchain
&lt;/h2>&lt;p>Since the birth of Bitcoin by Satoshi Nakamoto in 2009, blockchain technology has grown to become the foundation of financial systems and applications worldwide as a &amp;ldquo;decentralized and tamper-proof ledger.&amp;rdquo; This robust security is supported by modern cryptographic technologies: &lt;strong>Public Key Cryptography&lt;/strong> and &lt;strong>Cryptographic Hash Functions&lt;/strong>.&lt;/p>
&lt;p>These cryptographic technologies guarantee security based on the mathematical &amp;ldquo;computational difficulty&amp;rdquo; that classical computers (the PCs and supercomputers we currently use) cannot decipher even if they took time equivalent to the lifespan of the universe.&lt;/p>
&lt;p>However, this premise is about to be fundamentally overturned by the rapid development and practical application of &lt;strong>Quantum Computers&lt;/strong>, the frontier of physics and information science. Quantum computers, which utilize quantum mechanics specifics such as &amp;ldquo;Superposition&amp;rdquo; and &amp;ldquo;Entanglement,&amp;rdquo; demonstrate computational power that overwhelms conventional classical computers in specific mathematical problems, a phenomenon known as &amp;ldquo;Quantum Supremacy.&amp;rdquo;&lt;/p>
&lt;p>In this article, we will thoroughly and deeply delve into what specific threats blockchain technology faces from quantum computers, the latest trends in &lt;strong>Post-Quantum Cryptography (PQC)&lt;/strong> that serve as a solution, and the transition scenarios for crypto asset networks from a technical and mathematical perspective.&lt;/p>
&lt;hr>
&lt;h2 id="2-basics-of-quantum-computers-and-two-major-threats-to-blockchain">2. Basics of Quantum Computers and Two Major Threats to Blockchain
&lt;/h2>&lt;p>Current blockchain systems are primarily composed of the following two cryptographic elements, each of which is exposed to different threats from quantum algorithms.&lt;/p>
&lt;div class="mermaid">graph TD
A["Astonishing computational power of quantum computers"] --> B["Shor's Algorithm"]
A --> C["Grover's Algorithm"]
B --> D["Collapse of Public Key Cryptography (ECDSA/RSA/DSA)"]
C --> E["Impact on Cryptographic Hash Functions (SHA-256)"]
D --> F["Identification of others' private keys and transaction forgery"]
E --> G["PoW mining dominance and attacks on certain addresses"]
F --> H["Fatal and direct threat to blockchain"]
G --> I["Threat manageable by algorithm adjustments (e.g., key length extension)"]
style H fill:#ff9999,stroke:#cc0000,stroke-width:2px;
style I fill:#ffff99,stroke:#cccc00,stroke-width:2px;&lt;/div>
&lt;h3 id="21-basics-of-elliptic-curve-cryptography-ecdsa-and-computational-difficulty">2.1. Basics of Elliptic Curve Cryptography (ECDSA) and Computational Difficulty
&lt;/h3>&lt;p>Many blockchains, including Bitcoin and Ethereum, employ the &lt;strong>Elliptic Curve Digital Signature Algorithm (ECDSA)&lt;/strong> as their digital signature algorithm. Specifically, Bitcoin uses an elliptic curve with the parameter &lt;code>secp256k1&lt;/code>.&lt;/p>
&lt;p>The security of elliptic curve cryptography relies on the computational difficulty of the &lt;strong>Elliptic Curve Discrete Logarithm Problem (ECDLP)&lt;/strong>.
An elliptic curve is defined by the following equation in the Weierstrass normal form:&lt;/p>
$$
y^2 \equiv x^3 + ax + b \pmod{p}
$$
&lt;p>In Bitcoin&amp;rsquo;s &lt;code>secp256k1&lt;/code>, $a = 0, b = 7$, and $p$ is a very large prime number.
Let $G$ be the base point (reference point) on this curve, and $k$ be the private key, which is a randomly chosen massive 256-bit integer. The public key $K$ is then obtained by adding the base point $k$ times (scalar multiplication).&lt;/p>
$$
K = k \times G = \underbrace{G + G + \dots + G}_{k \text{ times}}
$$
&lt;p>Calculating the private key $k$ (finding the discrete logarithm) from the exposed public key $K$ and base point $G$ using classical computers requires an exponential computational time of $\mathcal{O}(\sqrt{p})$, even when using the best classical algorithms like Pollard&amp;rsquo;s rho algorithm. For a 256-bit key, it takes about $2^{128}$ operations, a level that cannot be solved even if current supercomputers are run for billions of years.&lt;/p>
&lt;h3 id="22-collapse-by-shors-algorithm">2.2. Collapse by Shor&amp;rsquo;s Algorithm
&lt;/h3>&lt;p>However, &lt;strong>Shor&amp;rsquo;s Algorithm&lt;/strong>, published by Peter Shor in 1994, completely destroyed this premise. Shor&amp;rsquo;s algorithm was originally proposed to solve the prime factorization problem (the foundation of RSA cryptography) in polynomial time, but it can also be applied to the discrete logarithm problem and the elliptic curve discrete logarithm problem.&lt;/p>
&lt;p>The core of Shor&amp;rsquo;s algorithm lies in rapidly finding the &amp;ldquo;Period&amp;rdquo; of a function using the &lt;strong>Quantum Fourier Transform (QFT)&lt;/strong>.&lt;/p>
$$
\text{Classical computational complexity} = \mathcal{O}(2^{n/2}) \quad (\text{where } n \text{ is the bit length})
$$
$$
\text{Quantum algorithm computational complexity} = \mathcal{O}(n^3)
$$
&lt;p>In this way, Shor&amp;rsquo;s algorithm dramatically reduces exponential time to &lt;strong>Polynomial Time&lt;/strong>. If a quantum computer with sufficient logical qubits is completed, it will be possible to determine the private key $k$ from the public key $K$ exposed on the network in minutes or seconds. This allows attackers to easily obtain the private keys of others&amp;rsquo; wallets and take full control of their funds.&lt;/p>
&lt;h4 id="221-step-by-step-explanation-of-ecdlp-decryption-by-shors-algorithm">2.2.1 Step-by-Step Explanation of ECDLP Decryption by Shor&amp;rsquo;s Algorithm
&lt;/h4>&lt;p>Let&amp;rsquo;s look at the internal process of how a quantum computer solves the Elliptic Curve Discrete Logarithm Problem (ECDLP) step by step.&lt;/p>
&lt;p>Problem setting: In $K = k \times G$, $G$ and $K$ are known, and we want to find the unknown integer $k$ (private key). Let the order of the elliptic curve be $N$.&lt;/p>
&lt;p>&lt;strong>Step 1: Creation of a superposition state&lt;/strong>
First, prepare two quantum registers and apply a Hadamard Gate to each to create a superposition state of all possible integer combinations.
&lt;/p>
$$
|\psi_1\rangle = \frac{1}{N} \sum_{x=0}^{N-1} \sum_{y=0}^{N-1} |x\rangle |y\rangle |0\rangle
$$
&lt;p>&lt;strong>Step 2: Application of the quantum oracle (evaluation of the function)&lt;/strong>
Next, using a quantum circuit (oracle) that performs point addition on the elliptic curve, compute the function $f(x, y) = x \times G + y \times K$ in the third register.
&lt;/p>
$$
|\psi_2\rangle = \frac{1}{N} \sum_{x=0}^{N-1} \sum_{y=0}^{N-1} |x\rangle |y\rangle |x \times G + y \times K\rangle
$$
&lt;p>
The important point here is that since $K = k \times G$, we can rewrite it as $f(x, y) = (x + y \cdot k) \times G$.&lt;/p>
&lt;p>&lt;strong>Step 3: Measurement of the third register&lt;/strong>
When the third register is measured, it collapses to a point $R$ on the elliptic curve. As a result, the first and second registers collapse to a superposition state of pairs $(x, y)$ that satisfy $x + y \cdot k \equiv c \pmod{N}$ (where $c$ is a constant).
&lt;/p>
$$
|\psi_3\rangle = \frac{1}{\sqrt{N}} \sum_{y=0}^{N-1} |c - y \cdot k \pmod{N}\rangle |y\rangle
$$
&lt;p>&lt;strong>Step 4: Application of the Quantum Fourier Transform (QFT)&lt;/strong>
This state has a periodicity related to the period $k$. By applying the Inverse QFT here, phase interference is induced, converting the period information into amplitudes.&lt;/p>
&lt;p>&lt;strong>Step 5: Measurement and classical post-processing&lt;/strong>
When the first and second registers are measured, a value containing information about $k$ is obtained with high probability. By applying classical number theory algorithms such as Continued Fractions to the measured value, the unknown private key $k$ can be completely determined.&lt;/p>
&lt;p>The number of quantum gates required for this entire process is $\mathcal{O}(\log^3 N)$, uncovering the private key at ultra-high speeds completely incomparable to the $\mathcal{O}(\sqrt{N})$ search by classical computers.&lt;/p>
&lt;h3 id="23-grovers-algorithm-and-its-impact-on-hash-functions">2.3. Grover&amp;rsquo;s Algorithm and its Impact on Hash Functions
&lt;/h3>&lt;p>Another threat is &lt;strong>Grover&amp;rsquo;s Algorithm&lt;/strong>, proposed by Lov Grover in 1996. This significantly impacts hash functions (e.g., SHA-256).&lt;/p>
&lt;p>In blockchain, hash functions are used to ensure data integrity, generate addresses, and serve as the foundation for &lt;strong>PoW (Proof of Work) mining&lt;/strong> in Bitcoin. Reversing a hash function (preimage computation) can be seen as an &amp;ldquo;unstructured database search problem&amp;rdquo; to find the input value $x$ such that $H(x) = y$ for a specific output value $y$.&lt;/p>
&lt;p>For classical computers, finding the correct answer out of $N$ possibilities requires an average of $\frac{N}{2}$ trials and a worst-case of $N$ trials. That is, the computational complexity is $\mathcal{O}(N)$.
However, Grover&amp;rsquo;s algorithm uses a quantum technique called &amp;ldquo;Amplitude Amplification.&amp;rdquo; By iteratively amplifying the probability amplitude of the correct state from among all possibilities in a superposition state, it reduces the search time to its square root.&lt;/p>
$$
\text{Computational complexity of Grover's Algorithm} = \mathcal{O}(\sqrt{N})
$$
&lt;p>For SHA-256, since $N = 2^{256}$, a classical brute-force search requires about $2^{256}$ trials. But using Grover&amp;rsquo;s algorithm, it only takes $\sqrt{2^{256}} = 2^{128}$ trials. This means that a 256-bit hash function&amp;rsquo;s security strength is &lt;strong>effectively halved to 128 bits&lt;/strong> against quantum computers.&lt;/p>
&lt;h4 id="231-will-sha-256-survive-quantum-supremacy-in-hashing">2.3.1. Will SHA-256 Survive? (Quantum Supremacy in Hashing)
&lt;/h4>&lt;p>Even if the security is halved, &amp;ldquo;128-bit security&amp;rdquo; remains extremely robust. The $2^{128}$ operations is an astronomical number even from the current technological level, requiring a timescale of the lifespan of the universe.
Therefore, it is widely believed that &lt;strong>&amp;ldquo;SHA-256 maintains practical security against quantum computers.&amp;rdquo;&lt;/strong> If it becomes necessary to increase the security margin in the future, simply doubling the hash output length (e.g., migrating from SHA-256 to SHA-512) will preserve classical 256-bit security in the quantum world.&lt;/p>
&lt;p>In conclusion, the quantum threat to hash functions is &amp;ldquo;minor and manageable,&amp;rdquo; whereas the threat to public key cryptography (ECDSA) is &amp;ldquo;fatal.&amp;rdquo;&lt;/p>
&lt;hr>
&lt;h2 id="3-specific-impact-analysis-on-current-crypto-assets-bitcoin-ethereum">3. Specific Impact Analysis on Current Crypto Assets (Bitcoin, Ethereum)
&lt;/h2>&lt;p>In a world where ECDSA decryption by quantum computers is possible, what specific vulnerabilities will crypto asset networks face? Here, we provide a detailed analysis using Bitcoin&amp;rsquo;s mechanism as an example, from the perspective of &lt;strong>&amp;ldquo;the timing of public key exposure.&amp;rdquo;&lt;/strong>&lt;/p>
&lt;h3 id="31-address-generation-and-the-privacy-of-public-keys">3.1. Address Generation and the &amp;ldquo;Privacy&amp;rdquo; of Public Keys
&lt;/h3>&lt;p>Bitcoin addresses (P2PKH: Pay-to-Public-Key-Hash or P2WPKH: Pay-to-Witness-Public-Key-Hash) use a public key hashed multiple times rather than the public key itself.&lt;/p>
$$
\text{Bitcoin Address} = \text{Base58Check}(\text{RIPEMD160}(\text{SHA256}(\text{Public Key})))
$$
&lt;p>As mentioned earlier, since hash functions are resistant to quantum attacks (Grover&amp;rsquo;s algorithm), reversing the original &amp;ldquo;public key&amp;rdquo; from the &amp;ldquo;address&amp;rdquo; (which is a hash value) is impossible even for a quantum computer.
In other words, for &lt;strong>&amp;ldquo;unused addresses (those that have never sent funds),&amp;rdquo;&lt;/strong> the public key is not exposed on the blockchain at all, and only the hash value is recorded. Therefore, as long as the public key is unknown, there is no target to execute Shor&amp;rsquo;s algorithm, and the private key cannot be identified. Wallets in this state can be said to be Quantum-safe.&lt;/p>
&lt;h3 id="32-fatal-vulnerability-during-transaction-transmission-front-running-attack">3.2. Fatal Vulnerability During Transaction Transmission (Front-running Attack)
&lt;/h3>&lt;p>The problem arises when users send funds.
When broadcasting (sending) a transaction to the network, the user must &lt;strong>include their public key in the transaction data along with the digital signature and expose it to the entire network&lt;/strong> for verification.&lt;/p>
&lt;div class="mermaid">sequenceDiagram
participant User as "User (Alice)"
participant Mempool as "Mempool (Unconfirmed Transaction Pool)"
participant QuantumAttacker as "Quantum Attacker"
participant Miner as "Miner (Block Generation)"
User->>Mempool: Send transaction (including public key + signature)
Mempool-->>QuantumAttacker: Intercept public key on the network
note right of QuantumAttacker: Execute Shor's algorithm in minutes&lt;br/>(Calculate private key from public key)
QuantumAttacker->>QuantumAttacker: Generate a new signature using Alice's private key
QuantumAttacker->>Mempool: Broadcast fraudulent transfer with a higher miner fee
Miner->>Miner: Prioritize fraudulent transaction with higher fee (Gas) into a block
Miner-->>User: Recorded on blockchain (Alice loses funds)&lt;/div>
&lt;p>Once the public key is sent to the Mempool (the waiting area for unconfirmed transactions), that data is shared with nodes worldwide. If an attacker possesses an ultra-fast quantum computer, they can steal funds through the following process:&lt;/p>
&lt;ol>
&lt;li>Intercept a legitimate user&amp;rsquo;s (Alice&amp;rsquo;s) transaction from the Mempool and &lt;strong>extract the public key&lt;/strong>.&lt;/li>
&lt;li>Execute Shor&amp;rsquo;s algorithm and &lt;strong>calculate the private key from the public key within minutes (before the block is confirmed)&lt;/strong>.&lt;/li>
&lt;li>Using the obtained private key, &lt;strong>create a fake transaction&lt;/strong> sending Alice&amp;rsquo;s funds to the attacker&amp;rsquo;s address.&lt;/li>
&lt;li>Set a &lt;strong>much higher miner fee&lt;/strong> for this fake transaction than Alice&amp;rsquo;s original transaction and send it to the network.&lt;/li>
&lt;/ol>
&lt;p>Miners prioritize transactions with higher fees into blocks according to economic incentives. As a result, the attacker&amp;rsquo;s fraudulent transfer is confirmed first, and Alice&amp;rsquo;s legitimate transfer is discarded as a &amp;ldquo;Double Spend&amp;rdquo; due to insufficient balance.
This series of events is called a &lt;strong>Front-running Attack&lt;/strong>, and in a world where quantum computers are commercialized, it will cause a terrifying situation where funds are stolen by hackers the moment someone presses the send button.&lt;/p>
&lt;h3 id="33-the-crisis-of-reused-addresses-and-old-addresses-p2pk">3.3. The Crisis of Reused Addresses and Old Addresses (P2PK)
&lt;/h3>&lt;p>An even more serious problem is that addresses that have sent funds at least once in the past (such as when reused as change addresses) already have their public keys permanently recorded on the blockchain. These are in danger of having their private keys calculated and balances stolen at any time, without even waiting to send a transaction.&lt;/p>
&lt;p>Additionally, in the &lt;strong>P2PK (Pay-to-Public-Key)&lt;/strong> format, which was mainstream around 2009-2010 and includes Satoshi Nakamoto&amp;rsquo;s early mining rewards (over 1 million BTC), the public key itself was recorded directly on the blockchain as the address instead of a hash. These massive amounts of dormant Bitcoins would be the easiest targets for quantum computers, and if stolen all at once and dumped on the market, could cause a massive price crash.&lt;/p>
&lt;hr>
&lt;h2 id="4-transition-scenarios-to-post-quantum-cryptography-pqc">4. Transition Scenarios to Post-Quantum Cryptography (PQC)
&lt;/h2>&lt;p>To avoid such a &amp;ldquo;Q-Day (the day quantum computers break cryptography)&amp;rdquo; catastrophe, the cryptography and blockchain communities are planning a transition to &lt;strong>Post-Quantum Cryptography (PQC)&lt;/strong>, which is difficult even for quantum algorithms to decrypt.
The National Institute of Standards and Technology (NIST) has been progressing with the standardization process of PQC for many years, and after several rounds of rigorous evaluation, some promising cryptographic schemes have been selected as final standards.&lt;/p>
&lt;p>We will explain in detail the major PQC algorithms that are drawing attention as digital signature alternatives for blockchains, along with their mathematical mechanisms.&lt;/p>
&lt;h3 id="41-hash-based-signatures">4.1. Hash-Based Signatures
&lt;/h3>&lt;p>Hash-based signatures are a cryptographic scheme whose security relies solely on a very simple and robust foundation: the &amp;ldquo;collision resistance of hash functions.&amp;rdquo; Since the safety of hash functions against quantum computers has already been proven (as mentioned above, a 128-bit security margin is sufficient), this is a highly reliable approach.
Representative examples include &lt;strong>Lamport Signatures&lt;/strong>, WOTS (Winternitz One-Time Signature) which extended it, and the NIST standardization candidate &lt;strong>SPHINCS+&lt;/strong> (now called SLH-DSA under FIPS 205).&lt;/p>
&lt;h4 id="411-mathematical-details-of-lamport-signatures-one-time-signature">4.1.1. Mathematical Details of Lamport Signatures (One-Time Signature)
&lt;/h4>&lt;p>Let&amp;rsquo;s look at the mechanism of Lamport signatures in more mathematical detail.
Let the hash function be $H: \{0, 1\}^* \to \{0, 1\}^{256}$.&lt;/p>
&lt;p>&lt;strong>[Key Generation]&lt;/strong>
Alice (sender) generates 256 pairs of private keys using a True Random Number Generator (TRNG).
&lt;/p>
$$
\text{sk}_{i,0} \in \{0, 1\}^{256}, \quad \text{sk}_{i,1} \in \{0, 1\}^{256} \quad (1 \le i \le 256)
$$
&lt;p>
Thus, the private key $\text{sk}$ consists of a total of 512 256-bit strings (Size: $512 \times 32 = 16,384$ bytes).&lt;/p>
&lt;p>Next, she computes the public key $\text{pk}$. Each private key component is individually hashed.
&lt;/p>
$$
\text{pk}_{i,0} = H(\text{sk}_{i,0}), \quad \text{pk}_{i,1} = H(\text{sk}_{i,1})
$$
&lt;p>
The public key is also $16,384$ bytes. This is published to the blockchain network.&lt;/p>
&lt;p>&lt;strong>[Signature Generation]&lt;/strong>
To sign a transaction data $M$, Alice first calculates its hash value.
&lt;/p>
$$
h = H(M) \in \{0, 1\}^{256}
$$
&lt;p>
Let the $i$-th bit of the hash value $h$ be $h_i \in \{0, 1\}$.
Alice&amp;rsquo;s signature $\sigma$ is a set of private key components corresponding to each bit $h_i$.
&lt;/p>
$$
\sigma = (\text{sk}_{1, h_1}, \text{sk}_{2, h_2}, \dots, \text{sk}_{256, h_{256}})
$$
&lt;p>
In other words, if the message hash bit is &lt;code>0&lt;/code>, $\text{sk}_{i,0}$ is revealed, and if &lt;code>1&lt;/code>, $\text{sk}_{i,1}$ is revealed. The signature size is $256 \times 32 = 8,192$ bytes.&lt;/p>
&lt;p>&lt;strong>[Signature Verification]&lt;/strong>
The miner (verifier) verifies using the received transaction $M$, signature $\sigma = (s_1, s_2, \dots, s_{256})$, and the public key $\text{pk}$.
They recalculate the hash of the transaction $h = H(M)$, and check whether hashing each $s_i$ matches the corresponding element $\text{pk}_{i, h_i}$ of the public key.
&lt;/p>
$$
H(s_i) \overset{?}{=} \text{pk}_{i, h_i} \quad (\text{for all } 1 \le i \le 256)
$$
&lt;p>This process is mathematically extremely simple, and it is impossible to forge a signature unless a quantum computer can reverse $H$. However, once signed, half of the private key is exposed to the network, so if another message is signed with the same key pair, the exposed private keys combine to give the attacker room for forgery, creating a strong restriction that it can only be used &amp;ldquo;One-Time.&amp;rdquo;
To make this practical, technologies like &lt;strong>XMSS&lt;/strong>, which bundles many one-time keys into a single root public key using a Merkle tree, and the stateless &lt;strong>SPHINCS+&lt;/strong> have been developed, but they have the drawback of signature sizes reaching tens of kilobytes.&lt;/p>
&lt;h3 id="42-lattice-based-cryptography">4.2. Lattice-Based Cryptography
&lt;/h3>&lt;p>Currently, the most anticipated mainstream of PQC, adopted as NIST&amp;rsquo;s main standard specification (FIPS 204: ML-DSA / formerly CRYSTALS-Dilithium, and Falcon, etc.), is &lt;strong>Lattice-Based Cryptography&lt;/strong>.&lt;/p>
&lt;p>The security of lattice cryptography depends on mathematically proven hard problems such as the &amp;ldquo;Shortest Vector Problem (SVP) in multi-dimensional lattices&amp;rdquo; or the &amp;ldquo;Learning With Errors (LWE) problem.&amp;rdquo; No algorithm has been found to solve lattice problems efficiently even using quantum computers.&lt;/p>
&lt;p>&lt;strong>Mathematical Model of LWE (Learning With Errors):&lt;/strong>
The basic idea of the LWE problem is to dramatically increase the difficulty of a problem by intentionally adding &amp;ldquo;small noise (errors)&amp;rdquo; to a system of linear equations.
Let the secret vector be $\mathbf{s} \in \mathbb{Z}_q^n$.
There is a massive randomly chosen public matrix $\mathbf{A} \in \mathbb{Z}_q^{m \times n}$ and an intentionally added small noise vector $\mathbf{e} \in \mathbb{Z}_q^m$.
The public key $\mathbf{b}$ is calculated as follows:&lt;/p>
$$
\mathbf{b} = \mathbf{A}\mathbf{s} + \mathbf{e} \pmod{q}
$$
&lt;p>Even if matrix $\mathbf{A}$ and vector $\mathbf{b}$ (public key) are public, reversing them to find the private key $\mathbf{s}$ becomes extremely difficult due to the presence of the noise $\mathbf{e}$. Without the noise, it could be solved by simple Gaussian elimination, but with the noise, the search space in all dimensions explodes, providing robust security against both classical and quantum computers.
In actual algorithms used in blockchain and elsewhere (like Dilithium), &lt;strong>Ring-LWE (or Module-LWE)&lt;/strong>, which expands this over polynomial rings, is used to reduce key sizes and speed up computations.&lt;/p>
&lt;ul>
&lt;li>&lt;strong>Pros&lt;/strong>: Compared to hash-based signatures, public key and signature sizes are relatively small (a few kilobytes), and signature generation/verification computation speeds are extremely fast (equivalent to or better than ECDSA).&lt;/li>
&lt;li>&lt;strong>Cons&lt;/strong>: The mathematical structure is complex, and because the historical verification period is short, the risk of a new decryption algorithm being discovered in the future is not zero.&lt;/li>
&lt;/ul>
&lt;hr>
&lt;h2 id="5-technical-challenges-in-migrating-blockchains-to-pqc">5. Technical Challenges in Migrating Blockchains to PQC
&lt;/h2>&lt;p>Just because PQC algorithms (like Dilithium and SPHINCS+) exist doesn&amp;rsquo;t mean they can be introduced to Bitcoin or Ethereum tomorrow. There are several heavy challenges unique to decentralized systems.&lt;/p>
&lt;h3 id="51-signature-size-bloat-and-the-collapse-of-scalability">5.1. Signature Size Bloat and the Collapse of Scalability
&lt;/h3>&lt;p>The biggest barrier to introducing PQC is the significant bloat in data size.
While the current ECDSA signature size is about 70 bytes, the lattice-based Dilithium (ML-DSA) has a signature size of about 2,420 to 4,595 bytes (depending on the security level), and a public key size exceeding 1,300 bytes. For the hash-based SPHINCS+, the signature alone reaches tens of thousands of bytes.&lt;/p>
&lt;p>If Bitcoin introduces PQC with the current block size limit (about 4MB weight including SegWit), the number of transactions that can be stored in one block will drastically decrease. Network throughput (TPS: Transactions Per Second) would fall devastatingly, and transaction congestion would become normal.
To solve this, a massive increase in block size is necessary, but this would increase the storage and network bandwidth requirements for full nodes, making it difficult for individuals to operate nodes, resulting in the dilemma of causing &lt;strong>centralization of the network&lt;/strong>.&lt;/p>
&lt;div class="mermaid">pie title "Comparison of Signature Data Sizes in Blockchain (Conceptual Diagram)"
"ECDSA (approx. 70 Bytes)" : 2
"Dilithium ML-DSA (approx. 2,500 Bytes)" : 58
"SPHINCS+ (approx. 17,000 Bytes)" : 40&lt;/div>
&lt;p>&lt;em>(Note: Transaction data bloat due to PQC introduction is a fatal bottleneck for scalability)&lt;/em>&lt;/p>
&lt;h3 id="52-impact-on-the-ethereum-virtual-machine-evm-and-precompiled-contracts">5.2. Impact on the Ethereum Virtual Machine (EVM) and Precompiled Contracts
&lt;/h3>&lt;p>In a Turing-complete smart contract platform like Ethereum, the introduction of PQC demands a fundamental upgrade to the EVM (Ethereum Virtual Machine).
In the current EVM, a precompiled contract &lt;code>ecrecover&lt;/code> (address: &lt;code>0x01&lt;/code>) is provided for ECDSA signature verification, optimized to perform signature verification at a very low gas cost (3000 Gas).&lt;/p>
&lt;p>However, the verification process of new lattice-based cryptographic algorithms like Dilithium and Falcon involves complex polynomial and matrix operations. Implementing this using only existing EVM Opcodes could consume millions to tens of millions of gas for just one signature verification. This is a level that would deplete the current block gas limit (about 30 million Gas) with a single transaction.&lt;/p>
&lt;p>To avoid this, it is necessary to incorporate a new Precompiled Contract for PQC verification (e.g., assigning DilithiumVerify to &lt;code>0x10&lt;/code>) into the EVM itself through a network hard fork. This requires a long-term process where core developers of each Ethereum client (Geth, Nethermind, Erigon, etc.) collaborate to optimally implement lattice cryptography verification logic at the language level (C++, Go, Rust, etc.) and conduct security audits.&lt;/p>
&lt;h3 id="53-difficulties-in-consensus-building-through-hard-forks">5.3. Difficulties in Consensus Building Through Hard Forks
&lt;/h3>&lt;p>Changing the underlying signature algorithm inherently requires a &lt;strong>Hard Fork&lt;/strong> that updates the entire network protocol. However, in communities like Bitcoin that emphasize &amp;ldquo;not changing rules, being decentralized,&amp;rdquo; the consensus-building process is politically very difficult. From the time a BIP (Bitcoin Improvement Proposal) for migrating to PQC is proposed until it is implemented, years of discussion and testing will be required.&lt;/p>
&lt;hr>
&lt;h2 id="6-when-will-q-day-arrive-a-roadmap-for-transition">6. When Will &amp;ldquo;Q-Day&amp;rdquo; Arrive? A Roadmap for Transition
&lt;/h2>&lt;p>When will &amp;ldquo;Q-Day (the day a quantum computer completely decrypts 256-bit elliptic curve cryptography)&amp;rdquo; arrive?
Although opinions are divided even among researchers, many experts predict that large-scale quantum computers with at least thousands to tens of thousands of stable logical qubits (error-corrected qubits with noise tolerance) will emerge &lt;strong>&amp;ldquo;from the mid-2030s to the 2040s.&amp;rdquo;&lt;/strong> However, depending on breakthroughs in hardware architecture or the discovery of more efficient quantum algorithms, the possibility of this arriving sooner (around 2030) cannot be ruled out.&lt;/p>
&lt;p>The roadmap the crypto asset ecosystem must take before it&amp;rsquo;s too late is as follows:&lt;/p>
&lt;h3 id="phase-1-hybrid-signatures-and-account-abstraction-present-to-around-2028">Phase 1: Hybrid Signatures and Account Abstraction (Present to around 2028)
&lt;/h3>&lt;p>The current blockchain scene, particularly Ethereum developers (like Vitalik Buterin), is considering &lt;strong>&amp;ldquo;Hybrid Signatures&amp;rdquo;&lt;/strong> that combine ECDSA and PQC (hash-based signatures or lattice cryptography). This approach attaches both the existing secure ECDSA signature and a PQC signature to a transaction, maintaining security even if one of them is broken.
Additionally, by utilizing Account Abstraction (ERC-4337), efforts are underway to implement and support PQC signatures on an opt-in basis (only for users who want it) on smart contract wallets without waiting for a protocol-level hard fork.&lt;/p>
&lt;h3 id="phase-2-utilizing-zero-knowledge-proofs-zk-rollups-2025-onwards">Phase 2: Utilizing Zero-Knowledge Proofs (ZK-Rollups) (2025 onwards)
&lt;/h3>&lt;p>The trump card expected to solve PQC&amp;rsquo;s biggest weakness, &amp;ldquo;signature data bloat,&amp;rdquo; is the utilization of &lt;strong>ZK-Rollups (Zero-Knowledge Proofs)&lt;/strong>, a Layer 2 technology.
Instead of writing massive PQC signature data directly to Layer 1 (the main chain), numerous PQC transactions are verified and aggregated on Layer 2. Then, using ZK-SNARKs or ZK-STARKs, they are compressed into a single extraordinarily small &amp;ldquo;Proof&amp;rdquo; and recorded on Layer 1.
Note that since some SNARKs configurations (like Groth16) are themselves vulnerable to quantum attacks, adopting &lt;strong>ZK-STARKs&lt;/strong>, which rely solely on quantum-resistant hash functions, is key.&lt;/p>
&lt;h3 id="phase-3-protocol-level-hard-forks-around-2030">Phase 3: Protocol-Level Hard Forks (Around 2030)
&lt;/h3>&lt;p>Once NIST&amp;rsquo;s PQC standardization is fully established, and industry-standard libraries are available and well-tested, it is expected that a hard fork completely transitioning the default signature scheme to PQC will be implemented on major chains like Bitcoin and Ethereum. During this transition period, a massive announcement urging users to &amp;ldquo;move funds from old wallets to new PQC-compatible wallets&amp;rdquo; will take place.&lt;/p>
&lt;h3 id="pioneering-project-examples">Pioneering Project Examples
&lt;/h3>&lt;p>Some blockchain projects have anticipated this quantum threat and have been developed with quantum resistance from their initial stages.&lt;/p>
&lt;ul>
&lt;li>&lt;strong>QRL (Quantum Resistant Ledger)&lt;/strong>: An early blockchain that natively implemented a hash-based PQC called XMSS (eXtended Merkle Signature Scheme) at the protocol level.&lt;/li>
&lt;li>&lt;strong>Algorand / Cellframe&lt;/strong>: A group of projects actively exploring the integration of lattice cryptography, possessing a flexible cryptographic layer modular architecture anticipating future PQC updates.&lt;/li>
&lt;/ul>
&lt;hr>
&lt;h2 id="7-conclusion-the-future-of-crypto-assets-and-protecting-our-wealth">7. Conclusion: The Future of Crypto Assets and Protecting Our Wealth
&lt;/h2>&lt;p>The arrival of the &amp;ldquo;Post-Quantum Era&amp;rdquo; goes beyond mere science fiction fantasy; it is already looming before us as a concrete technical challenge to real-world cryptographic systems.&lt;/p>
&lt;p>The two swords of quantum computers, Shor&amp;rsquo;s algorithm and Grover&amp;rsquo;s algorithm, threaten public key cryptography and hash functions, respectively, which are the foundations of current blockchains. In particular, the vulnerability of ECDSA is fatal, and to avoid the risk of fund theft through front-running attacks, transitioning to Post-Quantum Cryptography (PQC) is an absolutely unavoidable path.&lt;/p>
&lt;p>However, the technology sector and blockchain community are not just twiddling their thumbs waiting for destruction. The selection and standardization of PQC algorithms like lattice cryptography and hash-based signatures are steadily progressing, and a path to overcoming PQC&amp;rsquo;s biggest hurdle, &amp;ldquo;data size bloat,&amp;rdquo; is beginning to emerge by utilizing Zero-Knowledge Proofs (ZK-STARKs) and Layer 2 scaling technologies.&lt;/p>
&lt;p>There is no need for everyday crypto asset users and investors to panic right now and sell all their funds. However, it is important to have the following basic literacy and sense of self-defense:&lt;/p>
&lt;ul>
&lt;li>&lt;strong>Avoid address reuse&lt;/strong>: Thoroughly avoid keeping funds long-term in &amp;ldquo;used addresses (addresses that have sent funds even once, exposing their public key on the blockchain)&amp;rdquo; from a security perspective, not just a privacy one.&lt;/li>
&lt;li>&lt;strong>Pay attention to technology trends&lt;/strong>: Keep an antenna up for discussions on major networks&amp;rsquo; PQC transitions and hard fork news (like Bitcoin&amp;rsquo;s BIPs and Ethereum&amp;rsquo;s EIPs), so that you can appropriately transition your wallet when necessary.&lt;/li>
&lt;/ul>
&lt;p>The history of blockchain is also a history of continuous upgrades and resilience against new technological threats. Just as it has overcome scalability issues and environmental problems (like the transition from PoW to PoS), the entire ecosystem will surely seek solutions and adapt to this unprecedented quantum threat.
We look forward to a future where the new human wisdom of quantum computers and the trusted technology of decentralized ledgers do not collapse through collision, but rather sublimate into a higher-dimension, robustly fused system.&lt;/p>
&lt;hr>
&lt;p>&lt;em>References &amp;amp; Related Links:&lt;/em>&lt;/p>
&lt;ul>
&lt;li>National Institute of Standards and Technology (NIST) - Post-Quantum Cryptography Standardization Project&lt;/li>
&lt;li>Shor, P. W. (1994). Algorithms for quantum computation: discrete logarithms and factoring.&lt;/li>
&lt;li>Grover, L. K. (1996). A fast quantum mechanical algorithm for database search.&lt;/li>
&lt;li>Buterin, V. (2024). How to hard-fork to save most users&amp;rsquo; funds in a quantum emergency.&lt;/li>
&lt;/ul></description></item><item><title>Quantum Annealing vs Gate Model Explained Clearly</title><link>http://kenji.blog/en/p/quantum-annealing-vs-gate-model-explained/</link><pubDate>Fri, 11 Sep 2026 12:00:00 +0900</pubDate><guid>http://kenji.blog/en/p/quantum-annealing-vs-gate-model-explained/</guid><description>&lt;img src="http://kenji.blog/p/quantum-annealing-vs-gate-model-explained/img/eyecatch.jpg" alt="Featured image of post Quantum Annealing vs Gate Model Explained Clearly" />&lt;h1 id="quantum-annealing-vs-gate-model-explained-clearly">Quantum Annealing vs Gate Model Explained Clearly
&lt;/h1>&lt;p>Quantum computing is a next-generation computational technology that utilizes quantum mechanical principles (superposition and entanglement) to dramatically speed up solving specific problems that would take conventional classical computers (including traditional supercomputers) an enormous amount of time to compute.&lt;/p>
&lt;p>Currently, as approaches to realizing quantum computers, there are broadly two mainstream paradigms: &lt;strong>&amp;ldquo;Quantum Annealing&amp;rdquo;&lt;/strong> and the &lt;strong>&amp;ldquo;Quantum Gate Model&amp;rdquo;&lt;/strong>. These two methods differ significantly in their foundational physical approaches, the computational tasks they excel at, and the hardware challenges in their implementation.&lt;/p>
&lt;p>In this article, we will thoroughly compare and explain these two models from a very detailed and technical perspective, covering their physical principles, mathematical models (Ising model, QUBO, unitary transformation, etc.), current technical limitations, and specific use cases.&lt;/p>
&lt;hr>
&lt;h2 id="1-basics-of-quantum-computing-fundamental-differences-from-classical-computers">1. Basics of Quantum Computing: Fundamental Differences from Classical Computers
&lt;/h2>&lt;p>Classical computers process information as &amp;ldquo;Bits&amp;rdquo; that take either a &amp;ldquo;0&amp;rdquo; or &amp;ldquo;1&amp;rdquo; state. On the other hand, quantum computers use &amp;ldquo;Qubits&amp;rdquo;. Due to the quantum mechanical principle of &amp;ldquo;Superposition&amp;rdquo;, a qubit can probabilistically hold both 0 and 1 states simultaneously.&lt;/p>
&lt;p>Furthermore, by utilizing a phenomenon called &amp;ldquo;Entanglement&amp;rdquo;, the states of multiple qubits become strongly correlated with each other, such that an operation on one qubit instantly affects the entire system. This enables parallel-processing-like computation (quantum parallelism).&lt;/p>
&lt;p>However, quantum states are extremely vulnerable to external noise (such as heat and electromagnetic waves), and &amp;ldquo;Decoherence&amp;rdquo;—where the state breaks down and returns to a classical state—is a major challenge. The difference in approaches to this noise problem leads to the major differences in the design philosophies of annealing and the gate model.&lt;/p>
&lt;hr>
&lt;h2 id="2-details-of-quantum-annealing">2. Details of Quantum Annealing
&lt;/h2>&lt;p>Quantum annealing is a dedicated computational architecture specialized primarily in solving &lt;strong>&amp;ldquo;combinatorial optimization problems&amp;rdquo;&lt;/strong>. Based on the theory proposed in 1998 by Hidetoshi Nishimori and Tadashi Kadowaki of the Tokyo Institute of Technology, it became widely known when Canada&amp;rsquo;s D-Wave Systems commercialized it for the first time in the world.&lt;/p>
&lt;h3 id="21-physical-mechanism-transverse-field-ising-model-and-quantum-fluctuation">2.1. Physical Mechanism: Transverse-Field Ising Model and Quantum Fluctuation
&lt;/h3>&lt;p>Quantum annealing utilizes the property of physical systems in nature to settle into the &amp;ldquo;lowest energy state (ground state)&amp;rdquo; for computation.&lt;/p>
&lt;p>In the classical approach, &amp;ldquo;Simulated Annealing&amp;rdquo;, thermal fluctuations are used to escape local optimal solutions (local minima). On the other hand, quantum annealing uses &amp;ldquo;Quantum Fluctuation&amp;rdquo; to slip through energy barriers via &amp;ldquo;Quantum Tunneling&amp;rdquo;, searching for the global optimal solution (global minimum) more efficiently.&lt;/p>
&lt;p>The time evolution of a quantum annealing system is described by the following Hamiltonian (an operator representing the total energy of the system) $H(t)$.&lt;/p>
$$ H(t) = A(t) H_0 + B(t) H_P $$
&lt;p>Here, $t$ is time, $A(t)$ is a gradually decreasing function, and $B(t)$ is a gradually increasing function.&lt;/p>
&lt;ul>
&lt;li>&lt;strong>$H_0$ (Initial Hamiltonian)&lt;/strong>: Represents the transverse field and generates quantum fluctuation.
$$ H_0 = - \sum_{i} \sigma_i^x $$
($\sigma_i^x$ is the Pauli-X matrix, representing a bit flip.)&lt;/li>
&lt;li>&lt;strong>$H_P$ (Problem Hamiltonian)&lt;/strong>: An Ising Model representing the optimization problem to be solved.&lt;/li>
&lt;/ul>
&lt;p>In the initial state ($t=0$), $A(0)$ is at its maximum, and the system is in the ground state of $H_0$ (a state where all states are equally superposed). From there, over time, the transverse field is slowly weakened while simultaneously strengthening the interaction of the problem Hamiltonian.&lt;/p>
&lt;h3 id="22-adiabatic-quantum-computation">2.2. Adiabatic Quantum Computation
&lt;/h3>&lt;p>What is important in this process is the &lt;strong>&amp;ldquo;Adiabatic Theorem&amp;rdquo;&lt;/strong>. According to the adiabatic theorem, if a system is changed &amp;ldquo;sufficiently slowly (adiabatically)&amp;rdquo;, the system will always remain in the ground state of the Hamiltonian at that instant.&lt;/p>
&lt;p>In other words, when $A(t) \to 0$ and $B(t) \to 1$ ultimately, the system will have reached the ground state of $H_P$, which is the &lt;strong>&amp;ldquo;exact solution of the optimization problem&amp;rdquo;&lt;/strong>.&lt;/p>
&lt;div class="mermaid">graph TD
A["Hamiltonian H_0 (Initial State)"] -->|"Adiabatic change (Sufficiently slow)"| B["Always maintain ground state"]
A -->|"Non-adiabatic change (Too fast / Thermal noise)"| C["Transition to excited state (Error)"]
B --> D["Hamiltonian H_P (Global optimal solution)"]
C --> E["Trapped in local optimal solution"]
D --> F["Readout of the solution"]
E --> F&lt;/div>
&lt;h3 id="23-mapping-from-qubo-to-the-ising-model">2.3. Mapping from QUBO to the Ising Model
&lt;/h3>&lt;p>To solve real-world problems with a quantum annealer, the problem needs to be formulated in the &lt;strong>QUBO (Quadratic Unconstrained Binary Optimization)&lt;/strong> format.&lt;/p>
&lt;p>The objective function of QUBO is defined as follows:
&lt;/p>
$$ \min_{x \in \{0,1\}^n} \sum_{i} Q_{ii} x_i + \sum_{i &lt; j} Q_{ij} x_i x_j $$
&lt;p>
Here, $x_i \in \{0, 1\}$ are binary variables, and $Q$ is a weight matrix.&lt;/p>
&lt;p>Since the hardware (like D-Wave) deals with physical spins (up/down), it is necessary to convert the variables into an Ising model using $\sigma_i \in \{-1, +1\}$. The conversion formula is as follows:
&lt;/p>
$$ x_i = \frac{1 - \sigma_i}{2} \quad \text{or} \quad \sigma_i = 1 - 2x_i $$
&lt;p>Substituting this into the QUBO equation and rearranging yields the Hamiltonian $H_P$ of the Ising model:
&lt;/p>
$$ H_P = - \sum_{i&lt;j} J_{ij} \sigma_i^z \sigma_j^z - \sum_{i} h_i \sigma_i^z $$
&lt;ul>
&lt;li>$J_{ij}$: Interaction between spins (coupling coefficient). The coupling strength between physical qubits.&lt;/li>
&lt;li>$h_i$: Local magnetic field (bias) for each spin.&lt;/li>
&lt;/ul>
&lt;h3 id="24-quantum-annealing-hardware-and-challenges-d-wave-example">2.4. Quantum Annealing Hardware and Challenges (D-Wave Example)
&lt;/h3>&lt;p>D-Wave&amp;rsquo;s quantum processors are implemented using Superconducting Quantum Interference Devices (SQUIDs). The coupling between physical qubits depends on the hardware wiring, and it is not fully connected (a state where all bits are interconnected).
It has evolved from the initial &amp;ldquo;Chimera graph&amp;rdquo; to the &amp;ldquo;Pegasus graph&amp;rdquo; and &amp;ldquo;Zephyr graph&amp;rdquo;, and while connectivity has improved, it remains limited.&lt;/p>
&lt;p>Therefore, a process called &lt;strong>&amp;ldquo;Minor Embedding&amp;rdquo;&lt;/strong> is required, which maps a problem with a complex graph structure onto the physical graph. As a result, one logical variable is represented by multiple physical qubits (a chain), which leads to the challenge of reducing the effective number of usable qubits and degrading computational accuracy.&lt;/p>
&lt;hr>
&lt;h2 id="3-details-of-the-quantum-gate-model">3. Details of the Quantum Gate Model
&lt;/h2>&lt;p>The quantum gate model is a quantum mechanical extension of classical computer logic gates (AND, OR, NOT, etc.), and it is an architecture that enables &lt;strong>&amp;ldquo;Universal Quantum Computation&amp;rdquo;&lt;/strong>. Many companies, such as IBM, Google, Rigetti, and IonQ, have adopted this method.&lt;/p>
&lt;h3 id="31-unitary-transformation-and-state-vector">3.1. Unitary Transformation and State Vector
&lt;/h3>&lt;p>In the quantum gate model, the state of the entire system of qubits is represented as a &amp;ldquo;State Vector&amp;rdquo; $|\psi\rangle$. The state of one qubit is expressed as a linear combination of the basis states $|0\rangle$ and $|1\rangle$ as follows:
&lt;/p>
$$ |\psi\rangle = \alpha |0\rangle + \beta |1\rangle $$
&lt;p>
Here, $\alpha$ and $\beta$ are complex probability amplitudes, satisfying $|\alpha|^2 + |\beta|^2 = 1$. Geometrically, this state is visualized as a point on the &amp;ldquo;Bloch Sphere&amp;rdquo;.&lt;/p>
&lt;p>The steps of quantum computation are described as the application of a &lt;strong>Unitary Operator $U$&lt;/strong> to the state vector. A unitary matrix has the property $U^\dagger U = I$ (the product with its Hermitian conjugate is the identity matrix) and represents a reversible operation corresponding to the time evolution of the Schrödinger equation in quantum mechanics.
&lt;/p>
$$ |\psi_{t+1}\rangle = U_t |\psi_t\rangle $$
&lt;h3 id="32-basic-quantum-gates-and-circuit-model">3.2. Basic Quantum Gates and Circuit Model
&lt;/h3>&lt;p>Quantum computing algorithms are designed as a sequence of quantum gates (quantum circuits).&lt;/p>
&lt;ul>
&lt;li>&lt;strong>Pauli Gates (X, Y, Z)&lt;/strong>: 180-degree rotations around each axis on the Bloch sphere. The X gate corresponds to a classical NOT gate.&lt;/li>
&lt;li>&lt;strong>Hadamard Gate (H)&lt;/strong>: Transforms $|0\rangle$ into $\frac{|0\rangle + |1\rangle}{\sqrt{2}}$, creating a superposition state.
$$ H = \frac{1}{\sqrt{2}} \begin{pmatrix} 1 &amp; 1 \\ 1 &amp; -1 \end{pmatrix} $$&lt;/li>
&lt;li>&lt;strong>CNOT Gate (Controlled-NOT)&lt;/strong>: A 2-qubit gate. It applies an X gate to the target bit only when the control bit is $|1\rangle$. This generates quantum entanglement.&lt;/li>
&lt;/ul>
&lt;p>Any quantum algorithm can be approximately expressed by a combination of a small number of 1-qubit gates and CNOT gates (universal gate set).&lt;/p>
&lt;div class="mermaid">graph LR
Q0["Qubit 0: |0>"] --> H1["Hadamard Gate (H)"]
Q1["Qubit 1: |0>"] --> I1["Identity Operation (I)"]
H1 --> C1["Control Bit (Control)"]
I1 --> T1["Target Bit (Target)"]
C1 -. "Entanglement" .- T1
C1 --> M0["Measurement"]
T1 --> M1["Measurement"]
M0 --> Result["Classical Result (0 or 1)"]
M1 --> Result&lt;/div>
&lt;h3 id="33-error-correction-and-the-road-from-nisq-to-ftqc">3.3. Error Correction and the Road from NISQ to FTQC
&lt;/h3>&lt;p>The biggest challenge for the quantum gate model is &amp;ldquo;decoherence&amp;rdquo;, where quantum states are destroyed by noise. The deeper the computation steps (gate depth), the more errors accumulate.&lt;/p>
&lt;p>To perform ideal computations, &lt;strong>Quantum Error Correction&lt;/strong> is essential. For example, in methods like the &amp;ldquo;Surface Code&amp;rdquo;, multiple physical qubits are bundled together to form a single error-free &amp;ldquo;Logical Qubit&amp;rdquo;. However, creating one logical qubit requires thousands to tens of thousands of physical qubits, resulting in massive overhead.&lt;/p>
&lt;p>The stage we are currently at is the era of &lt;strong>NISQ (Noisy Intermediate-Scale Quantum)&lt;/strong> devices, which have tens to hundreds of qubits without error correction. Many breakthroughs are still needed to achieve &lt;strong>FTQC (Fault-Tolerant Quantum Computing)&lt;/strong> with complete error correction.&lt;/p>
&lt;hr>
&lt;h2 id="4-summary-of-technical-and-mathematical-comparison">4. Summary of Technical and Mathematical Comparison
&lt;/h2>&lt;p>We will compare the fundamental differences between the two architectures.&lt;/p>
&lt;table>
&lt;thead>
&lt;tr>
&lt;th style="text-align:left">Comparison Item&lt;/th>
&lt;th style="text-align:left">Quantum Annealing&lt;/th>
&lt;th style="text-align:left">Quantum Gate Model&lt;/th>
&lt;/tr>
&lt;/thead>
&lt;tbody>
&lt;tr>
&lt;td style="text-align:left">&lt;strong>Computational Model&lt;/strong>&lt;/td>
&lt;td style="text-align:left">Adiabatic quantum computation (continuous time evolution of a Hamiltonian)&lt;/td>
&lt;td style="text-align:left">Unitary transformation (sequence of discrete gate operations)&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td style="text-align:left">&lt;strong>Suitable Problems&lt;/strong>&lt;/td>
&lt;td style="text-align:left">Combinatorial optimization problems (QUBO, Ising model)&lt;/td>
&lt;td style="text-align:left">Universal (quantum chemistry simulation, prime factorization, search, etc.)&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td style="text-align:left">&lt;strong>Expressive Power&lt;/strong>&lt;/td>
&lt;td style="text-align:left">Heuristic optimization (approximate solutions)&lt;/td>
&lt;td style="text-align:left">Equivalent to a universal quantum Turing machine (all computations possible in theory)&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td style="text-align:left">&lt;strong>Implementation Examples&lt;/strong>&lt;/td>
&lt;td style="text-align:left">D-Wave Systems&lt;/td>
&lt;td style="text-align:left">IBM, Google, Quantinuum, IonQ, etc.&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td style="text-align:left">&lt;strong>Noise Tolerance&lt;/strong>&lt;/td>
&lt;td style="text-align:left">Relatively strong (since it stays near the ground state, some thermal noise is acceptable)&lt;/td>
&lt;td style="text-align:left">Extremely weak (slight noise causes phase shifts and destroys calculation results)&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td style="text-align:left">&lt;strong>Scalability&lt;/strong>&lt;/td>
&lt;td style="text-align:left">Scale of thousands to tens of thousands of qubits (depends on physical structure. Logical bit formation is difficult)&lt;/td>
&lt;td style="text-align:left">Scale of hundreds of qubits (millions needed for FTQC)&lt;/td>
&lt;/tr>
&lt;/tbody>
&lt;/table>
&lt;p>Quantum annealing is suited for solving optimization problems as a &amp;ldquo;special-purpose coprocessor&amp;rdquo;, complementing the limits of classical computers. On the other hand, the quantum gate model is a quantum version of a &amp;ldquo;general-purpose computer&amp;rdquo;, ultimately aiming for computational power that surpasses classical computers (quantum supremacy), but building the hardware is extremely difficult.&lt;/p>
&lt;hr>
&lt;h2 id="5-current-limitations-and-challenges">5. Current Limitations and Challenges
&lt;/h2>&lt;h3 id="limitations-of-quantum-annealing">Limitations of Quantum Annealing
&lt;/h3>&lt;ol>
&lt;li>&lt;strong>Connectivity&lt;/strong>: Due to the aforementioned minor embedding, the required number of physical qubits increases exponentially as the problem size grows.&lt;/li>
&lt;li>&lt;strong>Precision of Coefficients&lt;/strong>: The physical errors when setting analog parameters such as $J_{ij}$ and $h_i$ on the hardware directly affect the quality of the solution.&lt;/li>
&lt;li>&lt;strong>Temperature and Non-adiabatic Transitions&lt;/strong>: Since the system temperature is not absolute zero, there is a probability of deviating from the optimal solution due to thermal excitation.&lt;/li>
&lt;/ol>
&lt;h3 id="limitations-of-the-quantum-gate-model">Limitations of the Quantum Gate Model
&lt;/h3>&lt;ol>
&lt;li>&lt;strong>Coherence Time&lt;/strong>: The time a quantum state can be maintained is only on the order of a few microseconds to milliseconds, severely limiting the number of gates (circuit depth) that can be executed during that time.&lt;/li>
&lt;li>&lt;strong>Gate Fidelity&lt;/strong>: The operational error rate of 2-qubit gates (like CNOT) is not yet low enough (generally around 99.x%). For FTQC to be realized, this needs to be raised to over 99.99%.&lt;/li>
&lt;li>&lt;strong>Quantum Volume&lt;/strong>: Scaling not just the sheer number of qubits, but the effective computational capability (quantum volume) factoring in connectivity and error rates is currently the biggest challenge.&lt;/li>
&lt;/ol>
&lt;hr>
&lt;h2 id="6-specific-use-cases-and-algorithms">6. Specific Use Cases and Algorithms
&lt;/h2>&lt;p>Let&amp;rsquo;s look at the specific application areas where each method excels.&lt;/p>
&lt;h3 id="61-use-cases-for-quantum-annealing">6.1. Use Cases for Quantum Annealing
&lt;/h3>&lt;ul>
&lt;li>&lt;strong>Logistics and Routing&lt;/strong>: Optimizing delivery routes for numerous vehicles (a variation of the traveling salesperson problem). Real-time route searching considering traffic congestion.&lt;/li>
&lt;li>&lt;strong>Financial Engineering&lt;/strong>: Portfolio optimization. Searching for combinations of stocks that maximize return while minimizing risk.&lt;/li>
&lt;li>&lt;strong>Machine Learning&lt;/strong>: Feature Selection. Extracting combinations of variables that contribute most to prediction from massive datasets.&lt;/li>
&lt;li>&lt;strong>Manufacturing&lt;/strong>: Job-shop scheduling problems in factories (which machine should process which parts in what order to be the fastest).&lt;/li>
&lt;/ul>
&lt;h3 id="62-use-cases-for-the-quantum-gate-model">6.2. Use Cases for the Quantum Gate Model
&lt;/h3>&lt;ul>
&lt;li>&lt;strong>Quantum Chemistry Simulation&lt;/strong>: Simulating molecular energy states and chemical reactions with high precision.&lt;/li>
&lt;li>&lt;strong>Prime Factorization (Shor&amp;rsquo;s Algorithm)&lt;/strong>: An algorithm that factors huge composite numbers in polynomial time. When this is put into practical use, current public-key infrastructure like RSA encryption will be broken, making the transition to Post-Quantum Cryptography (PQC) an urgent issue.&lt;/li>
&lt;li>&lt;strong>Database Search (Grover&amp;rsquo;s Algorithm)&lt;/strong>: When searching for target data from an unsorted database, classical computers require $O(N)$ steps, but Grover&amp;rsquo;s algorithm can search in $O(\sqrt{N})$ steps.&lt;/li>
&lt;/ul>
&lt;h3 id="63-hybrid-algorithms-in-the-nisq-era-vqe-and-qaoa">6.3. Hybrid Algorithms in the NISQ Era: VQE and QAOA
&lt;/h3>&lt;p>To overcome the limitations of shallow quantum circuits in NISQ devices, &amp;ldquo;Variational Quantum Algorithms&amp;rdquo; that combine the advantages of quantum and classical computers are attracting attention.&lt;/p>
&lt;ul>
&lt;li>&lt;strong>VQE (Variational Quantum Eigensolver)&lt;/strong>: An algorithm to find the ground state energy of a molecule. It prepares a quantum state using a parameterized quantum circuit (Ansatz) and measures the energy expectation value $\langle \psi(\theta) | H | \psi(\theta) \rangle$. Using this expectation value as an objective function, a classical optimization algorithm (like gradient descent) is used to update the parameters $\theta$. By repeating this until convergence, the accurate energy state of the molecule is obtained.&lt;/li>
&lt;li>&lt;strong>QAOA (Quantum Approximate Optimization Algorithm)&lt;/strong>: An algorithm that solves combinatorial optimization problems using the quantum gate model. It approximates the adiabatic time evolution of quantum annealing into discrete gate operations via &amp;ldquo;Trotterization&amp;rdquo;, and obtains an approximate solution by alternately applying Hamiltonians. QAOA is expected to be a prominent method for solving optimization problems on gate-model computers.&lt;/li>
&lt;/ul>
&lt;div class="mermaid">graph TD
User["User Problem"] --> Formulation{"Nature of Problem"}
Formulation -- "Combinatorial Optimization" --> QA_Path["Quantum Annealing / Ising Machine"]
QA_Path --> QUBO["QUBO Formulation"]
QUBO --> DWave["Execute on D-Wave"]
Formulation -- "Chemical / General Computation" --> Gate_Path["Quantum Gate Model"]
Gate_Path --> Circuit["Quantum Circuit Design (VQE / QAOA)"]
Circuit --> IBMGoogle["Execute on IBM / Google Quantum Hardware"]&lt;/div>
&lt;hr>
&lt;h2 id="7-conclusion">7. Conclusion
&lt;/h2>&lt;p>Both quantum annealing and the quantum gate model are similar in that they utilize the mysterious properties of quantum mechanics as computational resources, but their approaches and ultimate goals are vastly different.&lt;/p>
&lt;ul>
&lt;li>&lt;strong>Quantum Annealing&lt;/strong> is a &amp;ldquo;specialized heuristic engine&amp;rdquo; aimed at delivering practical results early for specific real-world problems like combinatorial optimization. Proof-of-Concept (PoC) experiments by various companies are already underway.&lt;/li>
&lt;li>&lt;strong>The Quantum Gate Model&lt;/strong> is a &amp;ldquo;general-purpose quantum computer&amp;rdquo; with the potential to fundamentally overturn the paradigm of computer science, from exact simulations of physics and chemistry to decryption. However, it requires long-term research and development to overcome the massive wall of error correction.&lt;/li>
&lt;/ul>
&lt;p>In the future, it is believed that a &lt;strong>&amp;ldquo;Heterogeneous Computing&amp;rdquo;&lt;/strong> environment will be built, with classical supercomputers (HPC) at the core, calling upon annealing machines for optimization tasks and gate-model quantum computers for quantum chemistry calculations.&lt;/p>
&lt;p>Although quantum computing is a technology still in development, it is making rapid progress in both hardware and algorithms day by day. Understanding the mathematics of the Ising model and the basics of quantum circuits will be a great weapon for the coming quantum-native era.&lt;/p>
&lt;hr>
&lt;p>&lt;em>This article is a comprehensive guide covering everything from the foundational concepts of quantum computing to the latest hardware trends. Please continue to watch for future research developments.&lt;/em>&lt;/p></description></item><item><title>The Day Quantum Computers Become Practical: The Current State in 2026</title><link>http://kenji.blog/en/p/quantum-computing-2026-current-status/</link><pubDate>Fri, 11 Sep 2026 06:00:00 +0900</pubDate><guid>http://kenji.blog/en/p/quantum-computing-2026-current-status/</guid><description>&lt;img src="http://kenji.blog/p/quantum-computing-2026-current-status/img/eyecatch.jpg" alt="Featured image of post The Day Quantum Computers Become Practical: The Current State in 2026" />&lt;h2 id="1-introduction-where-quantum-computing-stands-in-2026">1. Introduction: Where Quantum Computing Stands in 2026
&lt;/h2>&lt;p>As of 2026, quantum computing has made a decisive shift from a &amp;ldquo;theoretical dream&amp;rdquo; to an &amp;ldquo;engineering reality.&amp;rdquo; As the limitations of &lt;strong>NISQ (Noisy Intermediate-Scale Quantum)&lt;/strong> devices—which were mainstream until a few years ago—became clear, research institutions and tech giants around the world shifted their focus toward realizing &amp;ldquo;FTQC (Fault-Tolerant Quantum Computing).&amp;rdquo;&lt;/p>
&lt;p>In this article, we will delve deep into the current state of quantum computers, incorporating the latest breakthroughs of 2026. In particular, we will detail quantum error correction (surface codes), the difference between physical and logical qubits, advancements in topological quantum computing, and the frontlines of superconducting and ion-trap architectures.&lt;/p>
&lt;hr>
&lt;h2 id="2-fundamentals-of-quantum-states-and-fidelity">2. Fundamentals of Quantum States and Fidelity
&lt;/h2>&lt;p>The qubit, the fundamental unit of a quantum computer, differs from a classical bit (0 or 1) in that it can exist in a superposition of 0 and 1. The state of a single qubit is represented as a vector on a Hilbert space as follows:&lt;/p>
$$
|\psi\rangle = \alpha|0\rangle + \beta|1\rangle
$$
&lt;p>Here, $\alpha$ and $\beta$ are complex probability amplitudes that satisfy the following normalization condition:&lt;/p>
$$
|\alpha|^2 + |\beta|^2 = 1
$$
&lt;p>An extremely important metric for measuring the performance of quantum computation is &lt;strong>Fidelity&lt;/strong>. The fidelity $F$ between an ideal quantum state $|\psi\rangle$ and an actual density matrix $\rho$ that has degraded into a mixed state due to noise is defined as follows:&lt;/p>
$$
F(\rho, |\psi\rangle) = \langle \psi | \rho | \psi \rangle
$$
&lt;p>As of 2026, the fidelity of 2-qubit gates (e.g., CNOT and CZ gates) has stably surpassed the &lt;strong>99.99%&lt;/strong> barrier (the so-called &amp;ldquo;four nines&amp;rdquo;) in superconducting architectures. This significantly exceeds the threshold for error correction using surface codes (about 99%), making it one of the biggest breakthroughs toward practical application.&lt;/p>
&lt;hr>
&lt;h2 id="3-the-limits-of-the-nisq-era-and-the-paradigm-shift-to-ftqc">3. The Limits of the NISQ Era and the Paradigm Shift to FTQC
&lt;/h2>&lt;p>The late 2010s to the early 2020s was the era of NISQ (Noisy Intermediate-Scale Quantum)—devices with tens to hundreds of qubits without error correction. However, NISQ had clear limitations.&lt;/p>
&lt;p>As the circuit depth increases, errors accumulate exponentially, making it impossible to obtain meaningful computation results. The overall success probability $P_{success}$ at a circuit depth $D$ decays with respect to the single-gate fidelity $f$ and the number of gates $N$ as follows:&lt;/p>
$$
P_{success} \approx f^N
$$
&lt;p>If $f = 0.99$ and 1000 gates are applied, $0.99^{1000} \approx 4.3 \times 10^{-5}$, and the result is almost entirely buried in random noise. For this reason, in 2026, resources are heavily concentrated on generating &lt;strong>Logical Qubits&lt;/strong> rather than directly scaling up NISQ algorithms (like VQE and QAOA).&lt;/p>
&lt;hr>
&lt;h2 id="4-quantum-error-correction-and-logical-qubits-the-forefront-of-surface-codes">4. Quantum Error Correction and Logical Qubits: The Forefront of Surface Codes
&lt;/h2>&lt;p>Quantum Error Correction (QEC) is a technology that encodes multiple &amp;ldquo;physical qubits&amp;rdquo; to create a single &amp;ldquo;logical qubit,&amp;rdquo; detecting and correcting errors. The most promising approach currently is the &lt;strong>Surface Code&lt;/strong>.&lt;/p>
&lt;h3 id="41-structure-of-the-surface-code">4.1 Structure of the Surface Code
&lt;/h3>&lt;p>In a surface code, qubits are arranged in a 2-dimensional grid. Data qubits (which hold the actual information) and measurement qubits (for syndrome measurement) are arranged in a checkerboard pattern.&lt;/p>
&lt;div class="mermaid">graph TD
A["Data Qubit (D1)"] --- B["Measure Qubit (M1)"]
B --- C["Data Qubit (D2)"]
C --- D["Measure Qubit (M2)"]
D --- E["Data Qubit (D3)"]
B --- F["Data Qubit (D4)"]
D --- G["Data Qubit (D5)"]
style A fill:#e1f5fe,stroke:#039be5
style C fill:#e1f5fe,stroke:#039be5
style E fill:#e1f5fe,stroke:#039be5
style F fill:#e1f5fe,stroke:#039be5
style G fill:#e1f5fe,stroke:#039be5
style B fill:#fff3e0,stroke:#fb8c00
style D fill:#fff3e0,stroke:#fb8c00&lt;/div>
&lt;p>Bit-flip (X errors) and phase-flip (Z errors) are constantly monitored using the stabilizer operators $S_x$ and $S_z$.&lt;/p>
$$
S_x = \prod_{i \in \text{star}} X_i, \quad S_z = \prod_{j \in \text{plaquette}} Z_j
$$
&lt;p>A significant advancement in 2026 is that the &amp;ldquo;Break-even point&amp;rdquo; has been completely surpassed. In other words, the noise removed by error correction has become greater than the noise introduced by the extra circuitry required for it, allowing the lifespan of a logical qubit to exceed that of a physical qubit by orders of magnitude.&lt;/p>
&lt;h3 id="42-the-quantum-error-correction-cycle">4.2 The Quantum Error Correction Cycle
&lt;/h3>&lt;p>Error correction functions as a continuous feedback loop.&lt;/p>
&lt;div class="mermaid">sequenceDiagram
participant D as "Data Qubits"
participant M as "Ancilla/Measure Qubits"
participant C as "Classical Controller"
loop "Syndrome Extraction Cycle (approx 1 microsec)"
D->>M: "Entangle (CNOT/CZ)"
M->>C: "Measure State (Syndrome)"
C->>C: "Decode Syndrome (e.g. Minimum Weight Perfect Matching)"
C-->>D: "Apply Pauli Correction (if necessary)"
end&lt;/div>
&lt;p>Currently, the technology to execute this classical decoding process (syndrome analysis) in nanoseconds using FPGAs or dedicated ASICs has been established, and real-time error correction has entered the practical stage.&lt;/p>
&lt;hr>
&lt;h2 id="5-evolution-of-hardware-architectures-2026-edition">5. Evolution of Hardware Architectures (2026 Edition)
&lt;/h2>&lt;p>Quantum hardware in 2026 is evolving primarily along three axes: &amp;ldquo;Superconducting,&amp;rdquo; &amp;ldquo;Ion-Trap,&amp;rdquo; and &amp;ldquo;Topological.&amp;rdquo;&lt;/p>
&lt;h3 id="51-integration-of-superconducting-qubits">5.1 Integration of Superconducting Qubits
&lt;/h3>&lt;p>The superconducting approach is a field led by companies like IBM and Google, with Transmon qubits using Josephson junctions being the mainstream. In 2026, megachips integrating thousands to ten thousand physical qubits on a single chip became a reality.&lt;/p>
&lt;p>Notably, &lt;strong>Quantum Interconnects (module-to-module quantum communication)&lt;/strong> have been established. Quantum teleportation between chips using microwave photons has been implemented at a commercial level, making it possible to bypass the size limitations of a single dilution refrigerator.&lt;/p>
&lt;h3 id="52-2d-scaling-and-optical-interconnects-for-ion-traps">5.2 2D Scaling and Optical Interconnects for Ion Traps
&lt;/h3>&lt;p>The ion-trap architecture (led by Quantinuum, IonQ, etc.) uses the internal energy states of ions suspended in a vacuum as qubits. Compared to superconducting methods, they boast extremely long T1/T2 coherence times and have the advantage of all-to-all connectivity.&lt;/p>
&lt;p>The 2026 breakthrough involved expanding the QCCD (Quantum Charge Coupled Device) architecture into two dimensions and generating high-speed entanglement between multiple traps using photonic interconnects. This drastically improved the slow gate speeds and scalability issues that were weaknesses of the ion-trap method.&lt;/p>
&lt;h3 id="53-topological-quantum-computing-controlling-anyons">5.3 Topological Quantum Computing: Controlling Anyons
&lt;/h3>&lt;p>&lt;strong>Topological quantum computing&lt;/strong>, long considered theoretical, has finally entered the phase of experimental demonstration in 2026. This approach, promoted by Microsoft and others, uses non-Abelian anyons called &amp;ldquo;Majorana Zero Modes.&amp;rdquo;&lt;/p>
&lt;p>Quantum gates are executed through an operation called &amp;ldquo;Braiding,&amp;rdquo; which involves swapping the positions of anyon particles.&lt;/p>
$$
|\psi_{final}\rangle = B_{ij} |\psi_{initial}\rangle
$$
&lt;p>Here, $B_{ij}$ is the braiding operator. Because the topological approach relies on the global topology of the &amp;ldquo;knots&amp;rdquo; rather than the local state of particles to store information, it is inherently robust against environmental noise (hardware-level fault tolerance). In 2026, the world&amp;rsquo;s first generation of high-fidelity topological logical qubits was confirmed, drawing attention as a powerful shortcut to FTQC.&lt;/p>
&lt;hr>
&lt;h2 id="6-roadmap-to-practical-application-and-future-outlook">6. Roadmap to Practical Application and Future Outlook
&lt;/h2>&lt;p>To truly demonstrate &lt;strong>Quantum Advantage&lt;/strong>, where quantum computers overwhelm classical computers (supercomputers) in fields like &amp;ldquo;chemical computation,&amp;rdquo; &amp;ldquo;materials science,&amp;rdquo; and &amp;ldquo;financial modeling,&amp;rdquo; thousands of logical qubits are required.&lt;/p>
&lt;div class="mermaid">gantt
title "Quantum Computing Roadmap (Revised 2026)"
dateFormat YYYY
axisFormat %Y
section "NISQ Era"
"Noisy Qubits (&lt;1000)" :done, 2018, 2024
section "Early FTQC"
"Break-even Point Demonstration" :done, 2024, 2026
"Hundreds of Logical Qubits" :active, 2026, 2028
section "Full-Scale FTQC"
"1000+ Logical Qubits (Commercial App)" : 2028, 2030
"Universal Fault-Tolerant Quantum Computer" : 2030, 2035&lt;/div>
&lt;h3 id="61-current-challenges-and-the-future">6.1 Current Challenges and the Future
&lt;/h3>&lt;p>The biggest challenges as of 2026 are the cooling capacity of the massive cryostats (dilution refrigerators) needed to maintain ultra-low temperatures, and the wiring (I/O bottleneck) connecting room-temperature control equipment to the cryogenic quantum chips. In response, the development of Cryo-CMOS controller chips that operate in cryogenic environments is advancing rapidly.&lt;/p>
&lt;h3 id="conclusion">Conclusion
&lt;/h3>&lt;p>2026 will likely be recorded in the history of quantum computing as &amp;ldquo;the first year of logical qubit scaling.&amp;rdquo; With the demonstration of error correction algorithms, the modularization of hardware, and rapid progress in the topological approach, &amp;ldquo;the day they become practical&amp;rdquo; is no longer a tale of the distant future but a concrete milestone to look forward to within the next few years. For developers and companies in the quantum algorithm space, now is the time to seriously invest in quantum-native problem solving.&lt;/p>
&lt;hr>
&lt;p>&lt;em>This article was written based on the latest quantum computing research papers and industry trends as of 2026.&lt;/em>&lt;/p></description></item></channel></rss>