Researchers Cut Bitcoin (BTC) Quantum Attack Resource Estimate by 86% in ECDSA.Fail Challenge

Over 100 researchers and AI agents cut the ECDSA.Fail quantum attack benchmark on Bitcoin's secp256k1 by 86%, from 10.75B to 1.496B, per a new paper.

(11:04 PM UTC)
4 min read
AI SummaryAI
  • ECDSA.Fail participants cut the quantum attack resource score 86%, from 10.75 billion to 1.496 billion.
  • The leading circuit used 1,151 logical qubits and about 1.3 million Toffoli gates.
  • IonQ estimates a 20,000-physical-qubit error-tolerant computer could break secp256k1 within 26 days.
  • Coinbase's advisory board estimates about 7 million BTC sits in addresses with exposed public keys.
d2mv6ykl

Quantum Attack Benchmark Falls 86%

More than 100 researchers, working alongside AI coding agents, have cut the estimated resource cost of a key step in a potential quantum attack on Bitcoin's cryptography by 86%, according to a paper posted Wednesday. The result comes from ECDSA.Fail, an open competition launched by Eigen Labs in late May that targets secp256k1, the elliptic curve securing transaction signatures on Ethereum and Bitcoin security broadly. Participants competed to minimize a resource score — the number of logical qubits multiplied by Toffoli gates, a costly quantum operation invented in 1980 — for a circuit performing the elliptic-curve point-addition arithmetic that Shor's algorithm would need to derive a wallet's private key. Logical qubits act as a circuit's working memory, so the score measures the combined quantum memory and computational work a future attacker would need. By the July 26 deadline, the leading design scored 1.496 billion, down from an opening mark of 10.75 billion, using 1,151 logical qubits and roughly 1.3 million Toffoli gates — about half of the benchmark Google Quantum AI published in March, though differences in testing and counting methods rule out a direct comparison. The verified tests confirmed the circuit's arithmetic; they did not crack an actual private key. Notably, the vulnerability sits in signature cryptography rather than the proof of work mining process that orders the ledger. Over roughly two months, participants stacked more than 400 improvement submissions, each becoming the next entrant's starting point, while AI agents handled code writing, verification and fine-grained optimization and humans steered research direction and major design decisions. The paper also reports a design tuned closer to full Shor's-algorithm implementation scoring around 1.96 billion, a later refinement near 1.26 billion, and post-deadline work pushing the Toffoli count to 952,707 or, in a separate design, the logical-qubit count to 813 at a sharply higher computational cost.

Migration Timelines and Exposed Coins

The competition traces back to a March publication from Google Quantum AI, which released a proof that a verified circuit exists while keeping the circuit itself private; Eigen Labs used that verification tool to build a public benchmark and leaderboard. Theta Labs CTO Jay Long published the findings on X on September 10. The paper's authors — affiliated with Theta Labs, MultiVM Labs, Eigen Labs, Trail of Bits, StarkWare and the Ethereum Foundation — write that migration away from vulnerable cryptography is already under way: the initial public draft of NIST IR 8547 proposes deprecating classical public-key algorithms at the 112-bit security level after 2030 and disallowing them after 2035. StarkWare co-founder and CEO Eli Ben-Sasson argued that with decryption costs halving within two months, every assumption about when quantum computers arrive needs revisiting. The threat horizon is not abstract: IonQ's estimate holds that an error-tolerant machine with roughly 20,000 physical qubits could break secp256k1 within 26 days, and Coinbase's advisory board estimated in June that about 7 million BTC sits in addresses with publicly exposed keys. Ethereum, by contrast, targets full quantum resistance by December 2029. Defense funding is scaling too — in July, Galaxy Digital committed up to $5 million to quantum-defense research, while nine firms including BlackRock, the manager of the largest spot Bitcoin ETF, Coinbase and Strategy pledged a combined $15 million over three years for broader Bitcoin security work, a push arriving alongside regulatory warnings on systemic exposure and coverage of BlackRock's 50/30/20 portfolio overhaul.

Q-Day Estimates Under Review

Our reading of the preprint: its authors state plainly that the optimized circuit covers only one major step, excluding physical error correction and the full Shor computation, so these results cannot decrypt Bitcoin today. But the direction matters. Long stressed that an attack is not imminent yet that defenses take years and cannot be applied retroactively — which makes the 86% compression in two months a planning problem, not a crisis. COINOTAG's view is that lead times for cryptographic migration, not raw qubit counts, now define the real deadline.

COINOTAG News Desk

COINOTAG News Desk

COINOTAG's editorial and research desk.

How our News Desk works
AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.