Quantum Attack Resource Estimate Falls Sharply for Bitcoin, Ethereum Cryptography

Researchers cut a key Shor-algorithm circuit benchmark as post-quantum migration planning advances
TL;DR
- Researchers sharply reduced the estimated quantum resources needed for a key cryptographic operation relevant to attacks on Bitcoin and Ethereum.
- The work optimized elliptic-curve point addition used inside Shor’s algorithm, but it does not represent a complete or currently practical quantum attack.
- Researchers and industry participants said the result strengthens the case for beginning post-quantum migration well before capable hardware exists.
Trade smarter on Jupiter, Solana’s leading DEX built for fast execution and deep liquidity.
Swap tokens at competitive rates, route across multiple liquidity sources automatically, and access perpetuals, DCA, and advanced trading tools — all in one place!
Researchers disclosed on September 10, 2026, a major reduction in the estimated quantum-computing resources needed for a key operation that could be used in a future attack against the cryptography protecting Bitcoin and Ethereum. The optimized circuit targets elliptic-curve point addition on secp256k1, an operation repeatedly used inside Shor’s algorithm, while the researchers stressed that the work does not constitute a complete attack and does not show that existing quantum computers can break either network today.
The work centers on the computational step that would help Shor’s algorithm derive a private key from an exposed public key. A sufficiently capable quantum computer using such an attack could calculate the corresponding private key and generate a valid digital signature as though it were the legitimate wallet owner. Bitcoin and Ethereum both use secp256k1-based cryptography, making the optimization directly relevant to the security assumptions behind both networks.
Circuit optimization cuts the benchmark substantially
Researchers measured efficiency using logical qubits, representing the circuit’s working-memory requirement, and Toffoli gates, representing a major component of the computational workload. They combined the two by multiplying them into a resource-cost score, with a lower score indicating a more efficient circuit.
Researchers cautioned that the comparison with Google Quantum AI is not perfectly like-for-like because the designs use different interfaces, circuit definitions and resource-accounting conventions. The Google benchmark therefore serves as numerical context rather than proof of formal circuit superiority. The narrower conclusion is that one important attack component can be implemented with substantially fewer logical quantum resources than the earlier published benchmark suggested.
The public optimization effort ran for roughly two months, or about eight weeks, and generated more than 400 accepted submissions from over 100 participants. Contributors included researchers and developers affiliated with the Ethereum Foundation, Eigen Labs, StarkWare, Starknet Foundation, Theta Labs, Brevis, Sei Labs and Trail of Bits, along with academic researchers.
Eigen Labs launched ECDSA.Fail on May 30, 2026, after Google Quantum AI had made a verifier available for checking submitted circuits and calculating their resource costs. Google Quantum AI had published its own estimates in March 2026 and set 2029 as a target for migration toward post-quantum cryptography, while releasing a zero-knowledge proof showing that a qualifying circuit existed rather than publicly releasing the underlying circuit itself.
Each successful ECDSA.Fail improvement became the baseline for later submissions. AI agents were used heavily for implementation, repeated testing and incremental optimization, while human researchers generally chose research directions and made larger architectural changes. The paper did not quantify how much of the total improvement came from humans compared with AI systems.
The headline result used a July cutoff for challenge submissions, but researchers continued submitting improved designs afterward. Those later entries reduced either the overall resource score, the gate count or the logical-qubit requirement, demonstrating tradeoffs between minimizing machine size and minimizing computational workload.
Researchers stress that no practical attack exists today
The logical-qubit figures do not represent the number of physical qubits a real machine would need. A practical fault-tolerant quantum computer would require substantially more physical qubits to create and maintain reliable logical qubits through error correction.
The optimized circuits also do not account for physical quantum error correction, do not implement all of Shor’s algorithm and exclude some hardware-specific execution costs. No existing quantum computer can use the reported circuit to break Bitcoin or Ethereum today.
Theta Labs CTO Jieyi Long, the paper’s lead author, said the timing issue lies in how long migration could take rather than in an immediate attack. “None of this is urgent because an attack is imminent. It is urgent because the remedy takes years and cannot be applied retroactively.”
Coinbase’s Independent Advisory Board on Quantum Computing and Blockchain estimated in June 2026 that approximately 7 million BTC are held in addresses whose public keys are already visible onchain. The estimate includes bitcoin held in legacy address formats as well as coins whose public keys became visible through address reuse. The advisory board also emphasized that no current quantum computer can break blockchain cryptography today.
Ethereum is working toward full post-quantum security by December 2029 across its execution, consensus and data layers. The research therefore arrives while post-quantum migration planning is already underway across major blockchain infrastructure.
StarkWare co-founder and CEO Eli Ben-Sasson said he had “butterflies” when researchers on his team first showed him the results. “Cutting the cost of breaking Bitcoin’s cryptography in half, in two months means that everyone should sit up and take notice.”
Ben-Sasson also argued that improvements in attack algorithms should change assumptions about quantum-security timelines. “If the estimate of what it costs to break this cryptography is being cut in half, as it is in this paper, then every timeline anyone has quoted you for Q-Day needs to be cut too. You don’t get to keep the old comfortable number just because the computer isn’t built yet.”
The researchers themselves used a narrower framing than Ben-Sasson’s timeline warning. Their findings show that one key cryptographic operation became more resource-efficient, while hardware development, error correction and implementation of the full algorithm remain separate requirements for any practical attack.
Government investment in quantum hardware was also advancing during the same week. The U.S. Commerce Department finalized CHIPS Act awards worth up to $100 million each for Rigetti, D-Wave and Quantinuum while taking minority stakes in all three companies, representing potential commitments of up to approximately $300 million across the three firms.
This article has been refined and enhanced by ChatGPT.