Researchers working with AI coding agents reduced a resource benchmark for a key step in a potential quantum attack on the cryptography protecting Bitcoin and Ethereum by 86%, according to a paper posted Wednesday.
Put simply, they lowered the computing resources required for a calculation tied to uncovering a wallet’s private key, which could allow an attacker to steal the funds inside it. When quantum computers powerful enough to carry out a full attack will arrive, a milestone often called “Q-Day,” remains unclear.
Researchers say migration away from vulnerable cryptography has started
The paper states: “Although its timing remains uncertain, migration away from vulnerable cryptography is already under way.” It adds: “NIST has standardized post-quantum replacements, and the initial public draft of NIST IR 8547 proposes deprecating classical public-key algorithms at the 112-bit security level after 2030 and disallowing them after 2035.”
That means the timeline is still open, but work to move away from cryptographic systems exposed to quantum risk is already in motion. The National Institute of Standards and Technology, or NIST, has standardized post-quantum alternatives, and the initial public draft of NIST IR 8547 proposes phasing out classical public-key algorithms at the 112-bit security level after 2030 and banning them after 2035.
Benchmark cuts came out of the ECDSA.Fail competition
The findings came from ECDSA.Fail, an open competition launched by Eigen Labs in late May. More than 100 participants worked on circuits for secp256k1, the elliptic curve used to secure transaction signatures on Bitcoin and Ethereum.
The paper’s authors include researchers affiliated with Theta Labs, MultiVM Labs, Eigen Labs, Trail of Bits, StarkWare, and the Ethereum Foundation.
Researchers designed and tested a quantum circuit that performs a calculation needed to crack Bitcoin’s cryptography, cutting its resource score by 86%. The tests verified the circuit’s calculations. They did not crack a Bitcoin private key.
How the challenge measured the circuits
The challenge tracked how much quantum memory and computational work each circuit required. It did that by multiplying logical qubits by Toffoli gates, a costly kind of quantum operation invented by Tommaso Toffoli in 1980.
A lower score means the calculation needs fewer combined resources. In practical terms, that could make a future attack easier to execute from a resource standpoint.
By July 26, participants had reduced the score from 10.75 billion to 1.496 billion, an 86% drop. The leading design used 1,151 logical qubits and about 1.3 million Toffoli gates. According to the study, that score was roughly half of Google Quantum AI’s March benchmark, though differences in testing and counting methods prevent a direct comparison.
Paper describes ECDSA.Fail as a case study in “Open Autoresearch”
The researchers wrote: “Beyond the resulting circuits, ECDSA.Fail provides a case study of Open Autoresearch: a verifier-gated research process in which human participants and AI agents iteratively generate, implement, test, and share candidate improvements against a common measurable objective.”
In the paper’s framing, the project is not only about the final circuit designs. It also serves as an example of a verifier-gated research process where human participants and AI agents repeatedly produce, implement, test, and share candidate improvements against the same measurable target.
Crypto firms are also spending more on quantum defense research
The report comes as crypto companies increase investment in research aimed at defending against quantum attacks.
In July, Galaxy Digital committed up to $5 million to that work. Separately, nine firms, including BlackRock, Coinbase, and Strategy, pledged a combined $15 million over three years for broader Bitcoin security research, including quantum defenses.

