Open challenge cuts estimated cost of a key quantum attack step on Bitcoin and Ethereum

Open challenge cuts estimated cost of a key quantum attack step on Bitcoin and Ethereum

N
News Editor
2026-09-11 10:45:56
A public optimization challenge focused on one building block of a quantum attack on Bitcoin and Ethereum produced a secp256k1 point-addition circuit with a much lower reported cost than earlier public figures. A paper posted to arXiv on Thursday said the design requires 1,151 logical qubits and about 1.30 million Toffoli gates. Using a spacetime benchmark that multiplies qubits by gates, the score dropped 86% over roughly two months of submissions, from 10.75 billion to about 1.496 billion. The paper said that level is more than 50% below the result Google Quantum AI reported in March. At the same time, co-author Jieyi Long, chief technology officer at Theta Technology, said the challenge outcome should not be treated as strictly better than Google’s because the two efforts use different interfaces and accounting conventions. The work does not amount to a live attack, and the authors stressed that cheaper circuits do not create the fault-tolerant quantum computer needed to run Shor’s algorithm. Still, the paper narrows the margin for exposed holders. Coinbase’s quantum advisory board estimated in June that about 7 million BTC are held in addresses with visible public keys, while the Ethereum Foundation has set December 2029 as its deadline for post-quantum security across execution, consensus, and data layers.

An open challenge to optimize one component of a quantum attack on Bitcoin and Ethereum has produced a circuit with a much lower reported cost than the best public figure cited before it. A paper published on arXiv on Thursday describes a point-addition circuit for secp256k1, the elliptic curve used by both networks. The design needs 1,151 logical qubits and about 1.30 million Toffoli gates.

The paper uses a benchmark that multiplies qubits by gates into a single spacetime score, where lower is better. Over roughly two months of submissions, that score fell 86%, from 10.75 billion to about 1.496 billion. The paper said that result is more than 50% below the figure Google Quantum AI reported in March.

The authors said the result should not be read as a simple win over Google

One of the paper’s authors, Theta Technology chief technology officer Jieyi Long, cautioned against treating the challenge result as outright superior to Google’s findings. He pointed to differences in interfaces and accounting conventions between the two efforts.

Point addition is repeated many times inside Shor’s algorithm. A fault-tolerant quantum computer could use that algorithm to recover a private key from a public key that is already exposed onchain. The authors said cheaper circuits do not build that machine, and they stressed that this work is not an attack. Even so, it reduces the safety margin available to holders whose public keys are visible.

Visible public keys keep the issue in focus

Coinbase’s quantum advisory board estimated in June that roughly 7 million BTC sit in addresses with visible public keys.

StarkWare CEO Eli Ben-Sasson, whose team took part in the challenge, wrote on X that the quantum threat no longer depends only on hardware challenges. He said, 「AI agents are narrowing the gap to a quantum attack. This project proves it.」

A public leaderboard accelerated progress

Google’s March paper disclosed resource thresholds and a zero-knowledge proof that a qualifying circuit existed, but it did not publish the circuit itself. It did, however, release a verifier.

Eigen Labs turned that verifier into a public leaderboard on May 30. IEEE Spectrum later reported that the crowd matched Google’s displayed result within eight hours and beat its score in about 72 hours.

Submissions kept arriving after the paper’s July 26 cutoff. One design reached 952,707 Toffoli gates, and another came in at 813 logical qubits.

Ethereum’s post-quantum deadline remains December 2029

The Ethereum Foundation set December 2029 as its deadline for post-quantum security across the execution, consensus, and data layers. Google used the same target date when it moved its timeline forward in March.

Long wrote on X that migration across blockchains, wallets, custody systems, and smart contracts will take years. That is why the work starts before any machine exists that could run the attack.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.