Google Quantum Paper Slashes Attack Cost: 500K Qubits to Crack Bitcoin in 9 Minutes

Google Quantum Paper Slashes Attack Cost: 500K Qubits to Crack Bitcoin in 9 Minutes

N
News Editor 01
2026-07-23 14:15:15
Google's Quantum AI paper shows breaking Bitcoin's ECC could need under 500K qubits—20x less than estimated. An exposed public key could be cracked in 9 minutes with 41% chance of beating confirmation. Some 6.9M BTC at risk; Ethereum preps, Bitcoin lags.
google quantum AIbitcoinelliptic curve cryptographyquantum threatethereum post-quantum

Google's Quantum AI team dropped a bombshell paper on Monday, showing that breaking the 256-bit elliptic curve cryptography protecting Bitcoin and Ethereum wallets could require fewer than 500,000 physical qubits—roughly a 20-fold reduction from earlier estimates in the millions. If a transaction exposes a public key, a quantum computer could recover the private key in about nine minutes, with a 41% chance of beating Bitcoin's 10-minute confirmation window.

Google's Paper Compresses the Timeline

The paper's impact isn't that quantum computers can break Bitcoin today—they can't—but that it dramatically shortens the expected timeline. Haseeb Qureshi, managing partner at Dragonfly, said on X: "We are no longer looking at mid-2030s; we could have quantum computers of this scale by the end of the decade. All blockchains need a transition plan ASAP. Post-quantum is no longer a drill." He noted an unusual detail: Google's team did not publish the actual quantum circuits, instead releasing a zero-knowledge proof to verify the circuits exist. "This is very atypical, showing Google thinks this is serious."

Justin Drake, an Ethereum Foundation researcher and late co-author of the paper, estimated at least a 10% chance that a quantum computer recovers a secp256k1 private key from an exposed public key by 2032. He described the optimized quantum circuit as "just 100 million Toffoli gates, surprisingly shallow," with a total runtime of roughly 1,000 seconds on a superconducting platform. "Low-hanging fruit is still being picked; at least one optimization came from a surprisingly simple observation. AI was not yet tasked to find optimizations." Drake suggested logical qubit counts "could plausibly go under 1,000 soonish."

6.9 Million BTC at Risk

The paper estimates that roughly 6.9 million bitcoin—about one-third of the total supply—sits in wallets where public keys have already been exposed. That includes 1.7 million BTC from the network's early years, including Satoshi Nakamoto's stash, as well as funds affected by address reuse. CoinDesk reported earlier Monday that Bitcoin's 2021 Taproot upgrade, designed for efficiency and privacy, also exposed public keys by default, now carrying quantum risk. CoinShares' February estimate pegged only about 10,200 BTC as concentrated enough to cause "appreciable market disruption" if stolen; Google's methodology counts all exposed keys regardless of balance size.

Security researcher Conor Deegan, whose work is cited in the paper, flagged that quantum computation acts as a one-time cost producing indefinitely reusable classical exploits. Ethereum's KZG trusted setup, Zcash's Sapling protocol, and Litecoin's MimbleWimble all embed elliptic curve hardness into fixed parameters that need breaking only once. "Deploying new cryptographic infrastructure on ECDLP curves is now indefensible given these resource estimates," Deegan said.

Ethereum's Eight-Year Head Start vs Bitcoin's Silence

Reactions split along familiar lines: Ethereum's preparations drew praise; Bitcoin's lack of urgency drew alarm. Investor McKenna (Arete managing partner) said: "Think of q-day as Y2K but real. People should give thanks to the Ethereum Foundation for being early and leading this research. The messy part is Bitcoin—the lack of urgency and consensus on what to do with vulnerable coins." Last week, the Ethereum Foundation launched pq.ethereum.org, showcasing eight years of post-quantum research, over 10 client teams shipping weekly devnets, and a multi-fork migration roadmap. Justin Drake is part of that same Ethereum team—a direct link between threat quantifiers and defense builders.

StarkWare co-founder Eli Ben-Sasson urged the Bitcoin community to "strengthen initiatives like BIP 360," a proposal for quantum-resistant wallet formats enabling voluntary migration. "Saying quantum computers are coming is not FUD. FUD is claiming Bitcoin can't adapt. It can adapt. Just need to start working on these solutions today." Bitcoin advocate Bit Paine offered a measured take: "I still think roughly 10 years is the more likely timeframe, but I assign an uncomfortably high likelihood that we see something disruptive within five years. High enough that action within the next one to two years is prudent."

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.