Mastodon Skip to content
LIVE - NYSE/-/- CRYPTO/OPEN/24/7
BTC$77,332▼ 0.05%ETH$2,531▲ 2.14%SOL$101.68▲ 1.68%TOTAL CRYPTO$2.66T▼ 2.07%S&P 5007,656.98▼ 0.92%NASDAQ26,333.04▼ 0.43%DOW52,573.29▼ 2.27%GOLD4,408.90▲ 0.59%WTI100.05▲ 20.25%BRENT104.61▲ 17.66%EUR/USD1.1602▲ 0.49%USD/JPY153.55▼ 3.52%DXY99.10▼ 0.73%
Crypto

Researchers Slash Quantum Attack Estimate on Bitcoin

More than 100 researchers and AI agents cut a quantum attack benchmark on Bitcoin's cryptography by 86% in two months, halving earlier cost estimates.

Pexels – Jonathan Borba

A crowdsourced challenge involving more than 100 researchers and their AI agents has cut the estimated resources needed for a quantum computer to break Bitcoin’s cryptography by more than half, according to a paper published on arXiv on September 9. The result does not mean anyone can steal bitcoin today, but it compresses the timeline that wallet operators and protocol developers have to prepare.

The effort, called ECDSA.Fail and run by Eigen Labs with Theta Labs, set participants the task of building the leanest possible reversible quantum circuit for one operation: elliptic curve point addition on secp256k1, the curve that secures Bitcoin and Ethereum signatures. Shor’s algorithm, the quantum method that breaks elliptic curve cryptography, runs this primitive thousands of times, so every saving in the primitive multiplies across the whole attack.

What actually dropped, and by how much

The benchmark scores each circuit by multiplying the number of logical qubits it needs by the average number of Toffoli gates it executes, a measure of the expensive quantum operations involved. Between late May and the July 26 data cutoff, participants reduced that score from 10.75 billion to 1.496 billion, a cut of 86.1%.

The winning design uses 1,151 logical qubits and roughly 1.3 million Toffoli gates per point addition. A separate submission optimized for qubit count pushed the requirement down to 825 logical qubits, the lowest publicly reported, at the cost of many more gates. A later entry brought the gate count below one million.

For context, the challenge’s initial textbook circuit scored 1.07 x 10^10. Google Quantum AI’s own March estimate for the same operation sat at around 3.0 to 3.2 billion under its private Pareto points. The community result came in at roughly half of Google’s figure, though the paper is careful to note that different counting conventions make this a numerical comparison rather than a claim of formal dominance.

Submissions were verified hard. Every circuit had to pass 9,024 randomized test cases, uncompute every ancilla qubit back to zero before freeing it, leave no residual phase kickback, and survive a forward-then-reverse identity check. A shortcut that skipped uncomputation to save gates would fail validation, not win. That discipline is what gives the leaderboard credibility as a measure of real progress rather than accounting tricks.

Why software progress moves the Q-Day clock

No quantum computer capable of breaking Bitcoin exists, and none is close. The point of the exercise is that the resource estimates themselves are moving, and they are moving through software optimization rather than hardware breakthroughs.

The pattern repeats across the field. A 2025 algorithmic advance cut the estimated cost of factoring RSA-2048 roughly twentyfold, from around 20 million physical qubits to under one million, with no change in hardware at all. A separate Google and Ethereum Foundation whitepaper put the cost of breaking Bitcoin’s secp256k1 curve at under half a million physical qubits. Earlier estimates had run into the hundreds of thousands of logical qubits or higher; a Caltech and Oratomic paper earlier this year argued a neutral-atom machine with 10,000 to 20,000 physical qubits could suffice under certain assumptions.

Two years of algorithmic work have roughly halved and then halved again the projected size of a cryptographically relevant quantum computer. Each revision shortens the estimated wait for what the industry calls Q-day, the moment a quantum machine can derive private keys from public ones.

How exposed are Bitcoin and Ethereum

Exposure differs between the two chains. Roughly 6 million BTC, about 30% of supply, sits in addresses where the public key is already visible on chain, mostly old outputs and reused addresses. Of that, about 2.3 million BTC, including coins believed tied to Satoshi-era mining, are irreducibly exposed because the owner would need to move them to a quantum-safe address, and many such coins may be unreachable. The remaining 3.7 million are migratable if owners act.

Ethereum’s at-rest exposure is broader. Between 50% and 65% of all ETH sits at used accounts with exposed public keys, a measurement-anchored figure rather than an analyst guess. But Ethereum is easier to migrate, and the Ethereum Foundation has moved first: it set a December 2029 deadline to make the network’s execution, consensus and data layers quantum-resistant, with a post-quantum public-key registry and a minimum viable post-quantum fallback planned along the way.

Bitcoin has no equivalent coordinated plan. Its governance model makes a protocol-level migration to post-quantum signatures a slow, contested process, which is why researchers keep emphasizing that the binding constraint is governance, not technology.

The people behind the numbers

Jieyi Long, lead author of the paper and chief technology officer of Theta Labs, framed the urgency as planning rather than panic. Credible, reproducible resource estimates are what let exchanges, custodians and protocol developers budget a migration, he told The Quantum Insider. The worry is not an imminent attack. It is that remediation takes years, not months, and the cost curve keeps bending downward.

The project is also a proof of method. Eigen Labs calls the approach Open Autoresearch: humans and AI coding agents publish evaluator-verified improvements to a public leaderboard, and the best circuit wins. The two-month, 86% reduction came from a distributed crowd working against an automated referee, not from a single lab’s breakthrough.

For anyone holding bitcoin in an address that has spent once, the practical advice has not changed: avoid address reuse, move long-dormant coins to fresh addresses when you eventually spend them, and watch for wallet-level post-quantum migration tooling. The math just got cheaper for the attacker. The defense still has time, but less of it than the 2024 estimates suggested.

SourcesarXiv preprint 2609.09582 (ECDSA.Fail, Sept. 9, 2026); Eigen Labs blog, Sept. 10, 2026; CoinDesk; The Quantum Insider; Decrypt; Ethereum Foundation protocol blog, Sept. 7, 2026
Share: X