A quantum attack long treated as a distant issue for Bitcoin just became more concrete. Quantum security startup Project Eleven said Friday that it awarded its 1 BTC Q-Day Prize to independent researcher Giancarlo Lelli after he broke a 15-bit elliptic curve key on publicly accessible quantum hardware, deriving a private key from its public counterpart.
At current prices cited in the report, the bounty is worth about $78,000. Project Eleven described the result as the largest public demonstration so far of an attack class that could eventually threaten Bitcoin, Ether, and most major blockchains. That does not mean Bitcoin is close to being broken today. It does mean the discussion is moving beyond theory papers and into experiments carried out on hardware available to outside researchers.
A 15-bit break is real, but still far from Bitcoin's 256-bit security
Elliptic curve cryptography is the mathematical foundation that allows a crypto wallet to prove control over funds without exposing its private key. Public keys can be visible. The private key is supposed to remain computationally unreachable. Quantum computers running Shor's algorithm challenge that model by attacking the logic behind those signatures. The technique was first proposed in 1994.
The gap between Lelli's result and Bitcoin's production security remains enormous. Bitcoin relies on 256-bit elliptic curve cryptography, while the prize-winning demonstration involved a 15-bit key with a search space of only 32,767 possibilities. The result should not be read as evidence that Bitcoin can now be cracked on-chain. The point of the bounty was narrower: to test whether quantum attacks against real cryptographic systems are starting to leave the white-paper stage.
Public record expanded 512 times in seven months
The previous public break was a 6-bit demonstration by Steve Tippeconnic in September 2025 using IBM's 133-qubit quantum computer. Lelli's 15-bit result expanded that scale by 512 times in just seven months.
A bit is the basic unit of information in a classical computer, while a qubit is its quantum equivalent. The absolute numbers are still small. The pace of progress is what stands out. Publicly accessible hardware is now part of the story, and that changes how developers and security researchers frame the risk.
Resource estimates for a full 256-bit attack are falling
Theoretical estimates are dropping as well. A Google Research paper published last month put the cost of a full attack on 256-bit security at fewer than 500,000 physical qubits, down from earlier estimates in the millions.
Project Eleven CEO Alex Pruden said the resource requirements for this kind of attack keep falling, and the practical barrier is falling with them. He also pointed to where the winning submission came from: not a national lab and not a private in-house quantum chip, but an independent researcher working on cloud-accessible hardware. That detail matters. It suggests the experimentation base is widening.
Addresses with exposed public keys face the sharpest concern
The most immediate concern centers on wallets whose public keys are already visible on-chain. Project Eleven estimates that about 6.9 million BTC sit in such addresses, roughly one-third of total supply. That figure includes Satoshi Nakamoto's estimated 1 million BTC, untouched since Bitcoin's earliest years.
If a quantum computer capable of breaking 256-bit elliptic curve cryptography ever arrives, those wallets could be worked through over time without waiting for fresh on-chain activity. Migration planning is already under discussion. Bitcoin developers have proposed options including BIP-360, which would add quantum-safe address types, while Ethereum, Tron, StarkWare, and Ripple have each published post-quantum transition plans.
Fifteen bits is not 256 bits. Even so, this is now one of the fastest-heating technical issues on the radar for Bitcoin developers and the broader crypto community.

