Researcher Wins 1 Bitcoin Bounty After Breaking 15-Bit Elliptic Curve Key on Quantum Hardware

Researcher Wins 1 Bitcoin Bounty After Breaking 15-Bit Elliptic Curve Key on Quantum Hardware

N
News Editor 01
2026-07-22 10:08:14
Project Eleven awarded 1 BTC to independent researcher Giancarlo Lelli for breaking a 15-bit elliptic curve key on publicly accessible quantum hardware, the largest public demonstration so far of this attack class.
BitcoinQuantum ComputingElliptic Curve CryptographyBlockchain SecurityProject Eleven

A quantum attack long treated as a distant issue for Bitcoin just became more concrete. Quantum security startup Project Eleven said Friday that it awarded its 1 BTC Q-Day Prize to independent researcher Giancarlo Lelli after he broke a 15-bit elliptic curve key on publicly accessible quantum hardware, deriving a private key from its public counterpart.

At current prices cited in the report, the bounty is worth about $78,000. Project Eleven described the result as the largest public demonstration so far of an attack class that could eventually threaten Bitcoin, Ether, and most major blockchains. That does not mean Bitcoin is close to being broken today. It does mean the discussion is moving beyond theory papers and into experiments carried out on hardware available to outside researchers.

A 15-bit break is real, but still far from Bitcoin's 256-bit security

Elliptic curve cryptography is the mathematical foundation that allows a crypto wallet to prove control over funds without exposing its private key. Public keys can be visible. The private key is supposed to remain computationally unreachable. Quantum computers running Shor's algorithm challenge that model by attacking the logic behind those signatures. The technique was first proposed in 1994.

The gap between Lelli's result and Bitcoin's production security remains enormous. Bitcoin relies on 256-bit elliptic curve cryptography, while the prize-winning demonstration involved a 15-bit key with a search space of only 32,767 possibilities. The result should not be read as evidence that Bitcoin can now be cracked on-chain. The point of the bounty was narrower: to test whether quantum attacks against real cryptographic systems are starting to leave the white-paper stage.

Public record expanded 512 times in seven months

The previous public break was a 6-bit demonstration by Steve Tippeconnic in September 2025 using IBM's 133-qubit quantum computer. Lelli's 15-bit result expanded that scale by 512 times in just seven months.

A bit is the basic unit of information in a classical computer, while a qubit is its quantum equivalent. The absolute numbers are still small. The pace of progress is what stands out. Publicly accessible hardware is now part of the story, and that changes how developers and security researchers frame the risk.

Resource estimates for a full 256-bit attack are falling

Theoretical estimates are dropping as well. A Google Research paper published last month put the cost of a full attack on 256-bit security at fewer than 500,000 physical qubits, down from earlier estimates in the millions.

Project Eleven CEO Alex Pruden said the resource requirements for this kind of attack keep falling, and the practical barrier is falling with them. He also pointed to where the winning submission came from: not a national lab and not a private in-house quantum chip, but an independent researcher working on cloud-accessible hardware. That detail matters. It suggests the experimentation base is widening.

Addresses with exposed public keys face the sharpest concern

The most immediate concern centers on wallets whose public keys are already visible on-chain. Project Eleven estimates that about 6.9 million BTC sit in such addresses, roughly one-third of total supply. That figure includes Satoshi Nakamoto's estimated 1 million BTC, untouched since Bitcoin's earliest years.

If a quantum computer capable of breaking 256-bit elliptic curve cryptography ever arrives, those wallets could be worked through over time without waiting for fresh on-chain activity. Migration planning is already under discussion. Bitcoin developers have proposed options including BIP-360, which would add quantum-safe address types, while Ethereum, Tron, StarkWare, and Ripple have each published post-quantum transition plans.

Fifteen bits is not 256 bits. Even so, this is now one of the fastest-heating technical issues on the radar for Bitcoin developers and the broader crypto community.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.