An open challenge to optimize one component of a quantum attack on Bitcoin and Ethereum has produced a circuit with a much lower reported cost than the best public figure cited before it. A paper published on arXiv on Thursday describes a point-addition circuit for secp256k1, the elliptic curve used by both networks. The design needs 1,151 logical qubits and about 1.30 million Toffoli gates.
The paper uses a benchmark that multiplies qubits by gates into a single spacetime score, where lower is better. Over roughly two months of submissions, that score fell 86%, from 10.75 billion to about 1.496 billion. The paper said that result is more than 50% below the figure Google Quantum AI reported in March.
The authors said the result should not be read as a simple win over Google
One of the paper’s authors, Theta Technology chief technology officer Jieyi Long, cautioned against treating the challenge result as outright superior to Google’s findings. He pointed to differences in interfaces and accounting conventions between the two efforts.
Point addition is repeated many times inside Shor’s algorithm. A fault-tolerant quantum computer could use that algorithm to recover a private key from a public key that is already exposed onchain. The authors said cheaper circuits do not build that machine, and they stressed that this work is not an attack. Even so, it reduces the safety margin available to holders whose public keys are visible.
Visible public keys keep the issue in focus
Coinbase’s quantum advisory board estimated in June that roughly 7 million BTC sit in addresses with visible public keys.
StarkWare CEO Eli Ben-Sasson, whose team took part in the challenge, wrote on X that the quantum threat no longer depends only on hardware challenges. He said, 「AI agents are narrowing the gap to a quantum attack. This project proves it.」
A public leaderboard accelerated progress
Google’s March paper disclosed resource thresholds and a zero-knowledge proof that a qualifying circuit existed, but it did not publish the circuit itself. It did, however, release a verifier.
Eigen Labs turned that verifier into a public leaderboard on May 30. IEEE Spectrum later reported that the crowd matched Google’s displayed result within eight hours and beat its score in about 72 hours.
Submissions kept arriving after the paper’s July 26 cutoff. One design reached 952,707 Toffoli gates, and another came in at 813 logical qubits.
Ethereum’s post-quantum deadline remains December 2029
The Ethereum Foundation set December 2029 as its deadline for post-quantum security across the execution, consensus, and data layers. Google used the same target date when it moved its timeline forward in March.
Long wrote on X that migration across blockchains, wallets, custody systems, and smart contracts will take years. That is why the work starts before any machine exists that could run the attack.

