Open Research Sprint Cuts Quantum Attack Cost on Bitcoin and Ethereum Signatures by Half
A crowd of more than 100 human and AI participants has produced the most resource-efficient publicly known quantum circuit for attacking the cryptography that secures Bitcoin and Ethereum, surpassing Google's undisclosed benchmark within three days of the repository going live.
Eigen Labs published the full results of the ECDSA.fail project on September 10, 2026, alongside a companion paper (arXiv:2609.09582) authored by Jieyi Long of Theta Labs, Theodore Pender of the Starknet Foundation, Zhao Huang of Brevis, and Manuel B. Santos of MultiVM Labs, and colleagues across multiple research institutions.
The primary circuit uses 1,151 logical qubits and an average of roughly 1.3 million Toffoli gate operations, yielding a combined spacetime score (qubits multiplied by Toffoli gates, or Q×T) of approximately 1.496 billion. That figure is more than 50 percent below the score Google Quantum AI reported in March 2026, and it represents an 86.1 percent reduction from the academic baseline set in 2017.
What the numbers mean
The Q×T metric measures how expensive a quantum computation is. Fewer qubits and fewer gate operations mean the attack becomes feasible on a smaller, cheaper, and sooner-available quantum machine. The circuit in question targets the secp256k1 elliptic curve, the mathematical foundation of ECDSA (Elliptic Curve Digital Signature Algorithm), which every standard Ethereum and Bitcoin wallet uses to authorize transactions. Any Ethereum account that has already sent at least one transaction has its public key permanently recorded on-chain. A quantum computer running Shor's algorithm could, in theory, work backward from that public key to recover the private key, giving an attacker full control of the funds. The ECDSA.fail result narrows the gap between "theoretical threat" and "practical threat" without closing it entirely. Analysts who overlay algorithmic cost curves with hardware roadmaps place the first plausible window for a cryptographically relevant quantum computer between 2027 and 2033, giving the distinction between theoretical and practical threat a concrete and near-term shape.
The researchers also produced a low-qubit variant using only 825 logical qubits at the paper's July 26 cutoff date, among the lowest publicly reported qubit counts for this class of circuit, though at the cost of a higher gate count.
How the result was achieved
Google's March 2026 paper described the attack using a zero-knowledge proof of correctness rather than publishing the actual circuit, a responsible-disclosure choice that left other researchers without a usable blueprint. Cryptographer André Schrottenloher filled part of that gap in early June 2026 with an open construction, and Eigen Labs researcher Gautham Anant had already built an initial benchmark in May. Once the public repository launched, participants closed the gap with Google's score in under eight hours and exceeded it within 72 hours.
By the paper's July 26 cutoff date, the platform had recorded 1,162 total submissions from 71 solvers, with more than 400 submissions promoted to the verified leaderboard.
A post-cutoff result using a ping-pong GCD algorithm brought the Q×T score down further to approximately 1.259 billion, pushing the average Toffoli gate count below one million for the first time.
The paper's authors describe the process as "open autoresearch": a public leaderboard with machine-checkable verification, preserved records of failed attempts that later solvers can build on, and a heterogeneous mix of human teams and AI agents working in parallel. "The public record shows that AI agents complemented human judgment, providing evidence for open autoresearch on efficiently evaluable, machine-checkable objectives," the authors write.
ECDSA.fail is one component of Yukon, Eigen Labs' open-autoresearch platform, which hosts challenges including SNARK.fast, precompile.fast, HeeschActive, and matrices.fast, and counts Stanford, UC Berkeley, Princeton, Carnegie Mellon, and the Ethereum Foundation among its partner institutions. That breadth positions open autoresearch as a scalable methodology rather than a one-off event.
Justin Drake, a researcher at the Ethereum Foundation and a contributor to the ECDSA.fail paper, called Google's March result "a momentous day for quantum computing and cryptography." His dual role as an Ethereum Foundation researcher and a project contributor signals direct institutional engagement from the Ethereum ecosystem with the post-quantum challenge.
Regional stakes
The compressed resource estimates carry direct relevance outside North America and Europe. India's market regulator SEBI has already embedded quantum resilience into its cybersecurity framework, requiring regulated entities to maintain cryptographic asset inventories and develop transition roadmaps. SEBI Chairman Tuhin Kanta Pandey has framed this as building a "cryptographic bill of materials" before any transition begins, a step the ECDSA.fail data makes more urgent.
India's DST published a national quantum-safe ecosystem plan in February 2026, covering defence, telecom, energy, and financial services.
In sub-Saharan Africa, the stakes are tied directly to financial inclusion. The region processed roughly $1.3 trillion of the world's $2 trillion in mobile money transactions in 2025, and approximately 20 percent of adults there rely on mobile money as their only financial account. ECDSA signatures secure those systems. Those systems also face the threat known as "harvest now, decrypt later," in which adversaries intercept and store encrypted communications today with the intent to decrypt them once a capable quantum computer becomes available. That risk is particularly acute across sub-Saharan Africa, where financial and government communications infrastructure has been recently deployed and carries many years of useful life ahead of it. A White House executive order issued in June 2026 cited this threat model as a key driver for accelerating post-quantum migration timelines.
The Africa Quantum Consortium has published guidance for central banks and mobile money operators on migrating to post-quantum standards, addressing practical constraints such as SIM card memory limits.
Ledger, a hardware wallet manufacturer, has watched these developments closely. Its CTO Charles Guillemet put the pressure plainly: "We need to migrate as quickly as possible. Even if we are not at all certain that a functional quantum computer will arrive soon, the question is no longer about certainty: it's about trust."
What comes next
Ethereum's post-quantum roadmap sets a 2029 deadline for core infrastructure. EIP-8141, which adds signature flexibility through account abstraction, is targeting the Hegotá network upgrade in the second half of 2026. Developers should note that switching to the leading post-quantum signature scheme (ML-DSA-87) increases signature size from roughly 64 bytes to about 4,627 bytes, a 72-fold jump with real consequences for gas costs and storage. The Ethereum Foundation's Post-Quantum Security team tracks ongoing work at pq.ethereum.org.
As the publisher of the ECDSA.fail research and the operator of EigenCloud (the product family encompassing EigenLayer, EigenDA, EigenCompute, EigenAI, and AgentKit), Eigen Labs held approximately $10.17 billion in total value locked as of September 2026, accounting for about 64.8 percent of the Ethereum restaking category per DefiLlama. The EIGEN token traded near $0.217 at time of publication, up roughly 17.7 percent over the prior 30 days but down approximately 96 percent from its December 2024 all-time high of $5.65.
The ECDSA.fail leaderboard remains open at ecdsafail.rocks. Researchers estimate the theoretical minimum for this class of circuit sits around 500 logical qubits. The primary Q×T-optimized circuit stands at 1,151 logical qubits, and a post-cutoff low-qubit variant has been reported at 813 qubits, meaning the current best results on both dimensions still leave meaningful room for further optimization. What is already clear is that migration planning cannot wait for a capable quantum computer to be publicly demonstrated. By the time such a machine exists, the window to act may have already closed.