IBM Quantum Cracks 15-Bit ECC Key, but Bitcoin Devs Prove It's Just Random Noise

IBM Quantum Cracks 15-Bit ECC Key, but Bitcoin Devs Prove It's Just Random Noise

N
News Editor 01
2026-07-08 22:40:25
Project Eleven awarded 1 BTC ($78,000) for cracking a 15-bit ECC key on IBM quantum hardware. Bitcoin developers reproduced the result with random bits, showing no quantum advantage. Bitcoin's 256-bit security remains intact.
quantum computingECCBitcoin securityProject Elevenrandom noise

On April 24, 2026, post-quantum startup Project Eleven awarded independent researcher Giancarlo Lelli 1 Bitcoin (worth approximately $78,000) for breaking a 15-bit elliptic curve cryptography (ECC) key on a publicly accessible IBM quantum computer. The company hailed the feat as the largest public demonstration of its kind to date. However, Bitcoin developers and cryptographers quickly dismissed the result, demonstrating that the quantum hardware contributed nothing beyond classical randomness.

The Quantum Advantage Debate: Noise or Breakthrough?

Project Eleven described Lelli's work as a 512-fold increase in search-space complexity over a prior 6-bit ECC break by engineer Steve Tippeconnic on IBM hardware in September 2025. CEO Alex Pruden framed the achievement as evidence that quantum attacks on ECC no longer require national labs or proprietary hardware. But former Bitcoin Core maintainer Jonas Schnelli analyzed Lelli's submission and concluded that the IBM circuit, running roughly 98,000 gates at about 99.5% per-gate fidelity, produced outputs statistically indistinguishable from random coin flips.

Schnelli reproduced the full key recovery in about 20 lines of Python using pure random bits, with no quantum hardware involved. His verdict: the quantum computer added no detectable signal over classical randomness. Coinkite founder Rodolfo Novak called the quantum claims “theater,” arguing on X that “the private key is classically solved before the quantum circuit even runs” and that the system “isn’t finding anything — it’s being told the answer.” Researcher Yuval Adam independently confirmed the finding by swapping Lelli’s IBM quantum backend for /dev/urandom, Linux’s classical random number generator, and recovering the target key identically.

The 15-bit curve carries a search space of only 32,767 possible private keys — small enough that a classical verifier checking candidates against the public key finds a match through near-random sampling at high probability. Bitcoin proponent Jimmy Song described the quantum computer as performing the same function as /dev/urandom. The X account TFTC noted in a widely read thread that every public Shor’s algorithm demonstration on ECC to date relies on classical pre-computation that effectively encodes the answer into the circuit before quantum hardware runs.

Project Eleven Responds: Incremental Progress, Not Q-Day

In a follow-up thread, Alex Pruden acknowledged that the result was not Q-Day and that NISQ-era experiments routinely depend on classical assistance. However, he argued the demo still represented incremental, reproducible progress on accessible public hardware, and that post-quantum migration planning remains a reasonable long-term priority. “Bottom line: This is incremental progress in a noisy, early field — not Q-Day,” Pruden wrote. “It highlights why we track resource reductions and why post-quantum migration planning matters for long-term security. Skepticism is healthy; moving goalposts isn’t.”

Critics also pointed to a conflict of interest in the prize structure. Project Eleven, backed by Coinbase Ventures, Castle Island Ventures, Variant, and Balaji Srinivasan, created the prize, judged submissions through three independent physicists, awarded the bounty, and then issued press releases warning that approximately 6.9 million BTC held in wallets with exposed public keys faced potential long-term risk. The company sells post-quantum cryptography tools.

Bitcoin Security: The Engineering Chasm Remains

The gap between Lelli’s result and any practical threat to Bitcoin is substantial. Bitcoin’s secp256k1 curve operates at 256-bit security. The distance from 15 bits to 256 bits represents a factor of 2^241 in computational difficulty. Even optimistic recent research, including a Google paper published in April 2026, estimates that breaking 256-bit ECC would require fewer than 500,000 physical qubits — a threshold that current quantum hardware falls far short of.

Projects like Sonic are redesigning their blockchain architectures to ease the transition to quantum-resistant cryptography, but the consensus among Bitcoin developers is that the security gap remains intact for the foreseeable future. The episode illustrates a tension that has persisted across quantum computing coverage: incremental hardware milestones generate headlines, but the distance between toy-scale demonstrations and production cryptographic systems remains an engineering gap without a near-term solution. Bitcoin’s security model depends on that gap, and developers say it remains intact.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.