VERSE PRESS

Crypto News, Global First.

Quantum Researchers Cut Attack Cost on Bitcoin and Ethereum Cryptography by More Than Half

Researchers affiliated with the Ethereum Foundation, Theta Labs, and StarkWare published new quantum circuit optimizations on September 10 that reduce a key computational benchmark for attacking the cryptography behind Bitcoin and Ethereum by more than 50 percent compared to a Google baseline set six months ago.

|

The new results were submitted to ecdsa.fail, a public leaderboard run by Eigen Labs where researchers compete to minimize the resources needed to break secp256k1, the elliptic curve algorithm both Bitcoin and Ethereum use to authorize transactions. Submissions are validated by running 9,024 test cases and confirming that ancilla qubits return to a zero state, giving the leaderboard a level of technical rigor that distinguishes it from unreviewed preprints. Under the new figures, cracking secp256k1 would require roughly 1,151 logical qubits and 1.3 million Toffoli gates, combining for a "comprehensive score" of approximately 1.5 billion. That 1,151-qubit figure also represents a meaningful reduction on its own: Google's March 2026 whitepaper, co-authored with Stanford and the Ethereum Foundation, projected 1,200 to 1,450 logical qubits under a superconducting architecture and put the equivalent comprehensive score near 3 billion using fewer than 500,000 physical qubits. One important caveat: the two teams use different scoring methodologies, so the comparison is not a straightforward halving of qubit requirements. The new benchmark weights qubits and gate counts together rather than reporting raw qubit figures alone.

The operation being optimized is called point addition, the innermost computation inside Shor's algorithm when it is applied to the elliptic-curve discrete logarithm problem. Solving that problem is what would allow a sufficiently powerful quantum computer to derive a private key from a public key and forge transactions. This is not a theoretical abstraction. Roughly 7 million BTC, about 30 percent of total supply, sits in addresses where public keys are already visible on-chain, according to estimates from the Coinbase Independent Advisory Board and the Quantum Horizon paper (arXiv 2606.14484). Legacy pay-to-public-key addresses alone hold an estimated 1.7 million BTC across around 20,000 addresses. Of particular concern, approximately 2.3 million BTC is considered irreducibly exposed, meaning it cannot realistically be migrated to safer addresses before an attack could occur. On the Ethereum side, the Quantum Horizon paper estimated that 50 to 65 percent of circulating ETH sits in accounts where keys have already been revealed through prior transactions. Beyond those directly exposed holdings, a subtler threat compounds the risk: adversaries can capture encrypted blockchain data today and decrypt it once quantum hardware matures, a strategy known as "harvest now, decrypt later" that creates urgency well before any quantum computer capable of a direct attack is built.

The competitive dynamic accelerating this research matters as much as any single result. In May 2026, researcher André Schrottenloher publicly reproduced Google's March circuits, triggering an open optimisation race. Three major papers on the elliptic-curve discrete logarithm problem appeared in a single quarter, from institutions in France, China, and Google. Logical qubit estimates for a viable attack have dropped from around 2,330 in a 2017 academic baseline to the high-1,100s today, with theoretical minimums approaching 500 qubits. Justin Drake of the Ethereum Foundation told The Quantum Insider in July 2026 that "low-hanging fruit is still being picked, with at least one of the Google optimizations resulting from a surprisingly simple observation." The open leaderboard format accelerates the pace of public disclosure beyond what traditional peer review timelines typically allow.

None of this translates to an imminent threat. No quantum computer capable of running these circuits at the required scale exists today. The gap between theoretical resource estimates and actual hardware remains roughly 400 to 500 times on physical qubit counts alone, before accounting for the fault-tolerant architecture that sustained computation would require. The Quantum Horizon paper pegged the probability of a cryptographically relevant quantum computer at around 17 percent by 2035 and 30 percent by 2040. The Global Risk Institute places the figure somewhat higher, estimating a 28 to 49 percent probability within the next ten years, a range that reflects genuine uncertainty among experts about timing. The story here is a compressing runway, not an impending break. Significantly, the Quantum Horizon paper concludes that governance rather than technology is the binding constraint on migration: even where quantum-safe alternatives exist, coordinating adoption across a decentralized network may prove the harder problem.

The regional stakes are significant. India's securities regulator SEBI addressed quantum computing risk publicly on the same day the new benchmarks dropped. Speaking at Global Fintech Fest 2026 in Mumbai, SEBI Chairman Tuhin Kanta Pandey outlined a three-step framework covering cryptographic inventory, cryptographic agility, and proactive system replacement. SEBI's authority on the subject rests on more than a single speech: the regulator is a member of India's National Quantum Mission task-force and is contributing to IOSCO's ongoing work on quantum risk for securities regulators worldwide. SEBI is also running a tokenized corporate bond pilot, which makes post-quantum readiness a near-term operational concern rather than a distant planning exercise.

In sub-Saharan Africa, the Africa Quantum Consortium has published practical guidance in a report titled "Securing Africa's Digital Backbone" on deploying post-quantum cryptography under regional constraints, including SIM card memory limits and latency issues at rural payment terminals. Several African nations already maintain active quantum programs, among them South Africa, Rwanda, and Ghana, with Egypt, Morocco, and Tunisia advancing comparable initiatives. The "harvest now, decrypt later" threat is especially acute across the region, where governments and financial institutions are deploying long-lived records covering land registries, identity systems, and financial histories on blockchain platforms, making early cryptographic choices particularly consequential. That urgency is compounded by scale: roughly two-thirds of global mobile money volume, estimated at more than 2 trillion dollars in 2025, flows through sub-Saharan Africa, with approximately one in five adults there relying on mobile money as their only financial account. All of it runs on the same elliptic-curve cryptography these researchers are working to break.

Migration proposals exist but remain immature. Bitcoin's BIP-360 lacks an agreed activation mechanism, while BIP-361 faces a different obstacle: active community resistance. Ethereum's post-quantum roadmap targets 2030. An alternative approach, Quantum Safe Bitcoin, offers a hash-based path but carries an estimated transaction cost of $75 to $150, a figure that helps explain why adoption has stalled even where technical solutions are available. The Quip Network, an Ethereum layer-2 project, proposes reducing the window for a so-called "on-spend attack" down to roughly two blocks. In an on-spend attack, an adversary races to exploit a key during the seconds to minutes a transaction sits unconfirmed; Google's March 2026 paper estimated that a superconducting quantum computer could execute such an attack in 9 to 23 minutes, well within typical confirmation windows for many networks. Bitcoin developer Bit Paine framed the timeline pressure plainly: "We may not have much of a window between 'quantum is on a trajectory to disrupt Bitcoin' and 'secp256k1 is broken.'" The Coinbase Independent Advisory Board has been equally direct, stating that "the upgrade work shouldn't wait." The ecdsa.fail leaderboard, now a focal point for this research community, suggests that window is getting shorter with each new round of submissions.