Quantum Research Cuts Bitcoin and Ethereum Attack Cost by More Than Half

Daily Feed
Quantum Research Cuts Bitcoin and Ethereum Attack Cost by More Than Half

A new research effort says it has cut the estimated cost of a quantum subroutine relevant to Bitcoin and Ethereum cryptography by more than half compared with a benchmark published by Google Quantum AI in March.

  • 1.5 billion resource score, down from about 3 billion
  • 1, 151 logical qubits and roughly 1.3 million Toffoli gates
  • Still not a practical break of Bitcoin or Ethereum today
  • Quantum-resistant migration could take years, according to lead author Jieyi Long

The work involved researchers from the Ethereum Foundation, Theta Labs, StarkWare, and others. It focuses on point addition, a repeated operation inside Shor's algorithm breaks Bitcoin and Ethereum security. That matters because Shor's algorithm is the quantum tool most often cited as a threat to public-key cryptography. If a sufficiently powerful fault-tolerant quantum computer ever runs it at scale, it could theoretically derive a private key from an exposed public key.

That is the long-game risk. Not tomorrow. Not next quarter. And not the kind of headline that means your coins are suddenly gone because some lab shaved a number on a slide deck.

Bitcoin uses secp256k1 cryptography, and Ethereum uses the same curve for externally owned accounts and related signing systems. In plain English, that curve helps prove you control a wallet without revealing your private key. If a public key is exposed and an attacker can compute the matching private key, that attacker could authorize transactions they should never be able to make.

The researchers say their circuit reaches a combined resource score of about 1.5 billion, which they describe as more than 50% below Google Quantum AI’s March benchmark of roughly 3 billion. But there’s a catch worth underlining. The comparison is not exact, because the two designs use different interfaces and accounting methods.

That caveat matters. Quantum benchmarking is not a clean boxing match where both sides wear the same gloves. A lower score can signal real progress, but it does not automatically mean the underlying attack is suddenly close to working in the real world.

The team also published a second version of the circuit, closer to how Shor's algorithm would actually perform the calculation, with a score of about 1.96 billion. And the optimization kept moving after that. One later design reduced the score to about 1.26 billion, while another lowered the requirement to 813 logical qubits but with substantially greater computational demands.

Logical qubits are the error-corrected qubits used for actual computation. They are not the raw noisy qubits current machines have in abundance. That distinction is the whole ballgame, because the physical hardware needed to support logical qubits is far larger than the logical-qubit count suggests. Quantum hype loves to skip that part. The hardware does not.

The research also shows how AI is being used in serious cryptography work without pretending it’s a magic wand. More than 100 participants worked with AI coding agents for roughly eight weeks through ECDSA.Fail, a project created by Eigen Labs. The effort generated more than 400 accepted submissions. AI agents were mainly used for coding, testing, and incremental optimization, while human researchers handled the broader strategy and major design changes.

That is probably the sane version of AI-assisted research. Machines grind through repetitive work, humans still have to think. The model is useful, not mystical. Nobody gets to outsource reality.

Jieyi Long, the lead author and CTO of Theta Labs, kept the message grounded. He said “an attack is not imminent” and added that moving blockchain networks to quantum-resistant cryptography “could take years.”

That is the right way to frame it. This is a warning sign, not a breach.

The actual attack path still has big missing pieces. The circuit described here covers only one major component of a potential quantum attack. It does not include physical error correction, the complete Shor algorithm, or the hardware-specific costs that would show up in a real implementation. In other words: the math is getting cheaper, but the machine still does not exist in the form needed to turn theory into theft.

That distinction matters for readers who want a straight answer. No, this does not mean Bitcoin or Ethereum are close to being broken. It does mean long-term security planning is not optional. If blockchain networks keep assuming cryptography stays hard forever, they are borrowing confidence from a future that may not pay it back.

There is also a broader policy backdrop. The U.S. Commerce Department recently finalized CHIPS Act awards of up to $100 million each for Rigetti, D-Wave, and Quantinuum. That does not prove quantum attacks on crypto are around the corner. It does show the field is still getting serious institutional backing, which is exactly why this kind of research keeps landing on the radar.

For Bitcoin users and developers, the practical takeaway is not panic. It is preparation. Quantum-resistant migration will not be a simple patch pushed overnight. It would likely require wallet upgrades, protocol changes, exchange coordination, and careful planning across a messy global ecosystem. The hard part is not only the cryptography. It is getting thousands of actors to move at roughly the same time without stepping on a rake.

Key questions and takeaways

  • Did this research break Bitcoin or Ethereum?
    No. It reduced the estimated cost of one quantum subroutine relevant to secp256k1 cryptography, but it does not amount to a practical attack on either network today.
  • Why does the 1.5 billion figure matter?
    It suggests meaningful progress in quantum circuit efficiency, and the researchers say it is more than 50% below a March benchmark from Google Quantum AI. The comparison is not exact, though, so it should not be treated as a clean apples-to-apples victory lap.
  • What makes secp256k1 relevant here?
    It is the elliptic-curve cryptography used in Bitcoin, and also in Ethereum account signing systems. If a sufficiently advanced quantum computer could derive a private key from an exposed public key, funds could be at risk.
  • Are quantum computers strong enough now?
    No. The missing pieces are huge: error correction, stable hardware at scale, and a full end-to-end implementation of Shor's algorithm. The gap between a better circuit and a real attack is still massive.
  • Why would migration to quantum-resistant cryptography take so long?
    Because this is not just a software update. It would require network upgrades, wallet support, exchange coordination, and careful rollout across a very messy ecosystem.
  • What should users do today?
    Not panic, but do not ignore the issue either. Long-term holders, wallet providers, and protocol teams should keep an eye on quantum-safe upgrade plans and public-key exposure risks.

Quantum computing is still inching forward, and that is enough to matter. The honest read is simple: Bitcoin and Ethereum are not broken, but the industry cannot afford to pretend quantum risk is someone else’s problem forever. The two bad takes are panic and dismissal, and both are lazy.

Further reading

A few related pieces for readers who want the security angle, the market context, and a couple of deeper rabbit holes.

Share this article

Powered by ADBYTES

Advertise smarter.

Adbytes.Media is a transparent advertising network where advertisers reach real audiences and publishers, affiliates & everyday members earn ADBYTES tokens. Join the community and start earning today.

Back to Blog