Google Quantum Paper Warns: Bitcoin Can Be Broken in 9 Minutes, Crypto Must Migrate

Google Quantum Paper Warns: Bitcoin Can Be Broken in 9 Minutes, Crypto Must Migrate

N
News Editor 01
2026-07-22 22:20:14
Google Quantum AI team estimates that a quantum computer with ~500k physical qubits can crack secp256k1 private keys in minutes. Three attack models defined: on-spend, at-rest, on-setup. Bitcoin, Ethereum face structural vulnerabilities. Full circuit withheld via ZK proof.
quantum computingBitcoinEthereumelliptic curve cryptographypost-quantum cryptography

A joint research paper from Google Quantum AI, UC Berkeley, the Ethereum Foundation, and Stanford has zeroed in on the secp256k1 elliptic curve used by Bitcoin and Ethereum, delivering a stark resource estimate for Shor's algorithm. The team says 1,200–1,450 logical qubits, 70–90 million Toffoli gates, and roughly 500,000 physical qubits (under a superconducting + surface code architecture) suffice to extract a private key in minutes—turning the quantum threat from theoretical talk into engineering specs.

Three Attack Vectors: On-Spend, At-Rest, On-Setup

The paper defines three distinct quantum attack models. On-spend attacks monitor the mempool: when a user broadcasts a transaction, the public key is exposed; the attacker runs Shor's algorithm to derive the private key and then broadcasts a counterfeit transfer before the original is confirmed. The crucial number: the online phase (after precomputation) takes only 9 minutes. Given Bitcoin's ~10-minute average block time, the on-spend success probability is about 41%. Attackers can use Replace-By-Fee (RBF) with extremely high fees—a scorched-earth strategy that makes the threat real even below 100% success. For other chains (Litecoin, Zcash, Dogecoin) with faster block times, the success rate drops drastically. At-rest attacks target funds whose public keys are already on-chain and dormant. No time pressure: a slow-clock CRQC can crack addresses over days or months. The paper estimates ~6.9 million BTC vulnerable at rest (P2PK, reused addresses, P2TR). On-setup attacks are the most insidious: a CRQC can reverse-engineer the toxic waste from a trusted setup (e.g., zkSNARK ceremonies), granting a permanent backdoor usable on classical hardware. The paper explicitly names Tornado Cash, Zcash's earlier Sapling pool, Ethereum's KZG commitments for data availability sampling, stablecoin admin keys (USDT/USDC), rollup verifier contracts, and bridge multisig wallets.

Bitcoin's Address Formats: P2PK Most Exposed, P2TR a Step Back

Bitcoin's UTXO model hosts seven standard address types, each with different quantum vulnerability. P2PK and P2MS are the worst—public keys are literally in the locking script. P2TR (Taproot) exposes the tweaked public key directly, making it a security regression from a quantum standpoint; in 2025, Taproot accounted for 21.68% of transaction outputs, moving ~16.8 million BTC. Even proposed upgrades like P2MR (BIP-360) cannot prevent on-spend attacks because any spending transaction inevitably reveals the public key. The paper's core takeaway: only post-quantum cryptography (PQC) can fully eliminate on-spend risk.

Ethereum's Structural Fragility: Five Layers of Risk

Ethereum's account model encourages persistent addresses, and once an EOA sends a transaction, its public key is permanently on-chain. The paper calculates that a fast-clock CRQC could crack the top 1,000 Ethereum accounts (holding ~20.5 million ETH) in 9 days. But individual accounts are just one layer. The paper's Table II enumerates five structural vulnerabilities: account (~20.5M ETH), admin (~2.5M ETH + $200B stablecoins/RWAs), code (L2 zkSNARKs, ~15M ETH), consensus (PoS validators' BLS signatures, ~37M ETH), and data availability (KZG commitments, ~15M ETH). A quantum attacker seizing a stablecoin admin key could mint unlimited tokens, collapsing the peg.

Notably, the paper does not publish the full attack circuit. Instead, the team used SP1 zkVM to generate a zero-knowledge proof attesting to the circuit's existence and correctness—a move borrowed from Coordinated Vulnerability Disclosure (CVD) in traditional security. This signals that quantum cryptanalysis has entered an era of responsible disclosure, where cutting-edge results will be partially withheld. The paper concludes with a clear timeline: from 2025 onward, all new crypto systems should default to quantum-resistant schemes, and existing ECDLP-based systems must migrate within 5–10 years.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.