Researchers have significantly reduced the estimated computing requirements for a key stage of a potential quantum attack on Bitcoin and Ethereum. A new paper shared with CoinDesk shows that a team of researchers and AI coding agents achieved a result more than 50% below a benchmark released by Google in March.
The research, conducted by contributors from the Ethereum Foundation, Theta Labs, StarkWare and other organizations, produced a quantum circuit requiring 1,151 logical qubits and roughly 1.3 million Toffoli gates.
Logical qubits can be viewed as an indication of the machine size required, while Toffoli gates represent the computational workload. Lowering either figure could make a future quantum attack easier to execute.
The researchers’ main circuit generated a score of approximately 1.5 billion, compared with about 3 billion in Google Quantum AI’s March benchmark. The paper cautions that the figures are not a perfect apples-to-apples comparison because the respective designs rely on different interfaces and accounting methods.
Another version of the circuit, modified to more closely match its eventual role within Shor’s algorithm, recorded a score of around 1.96 billion. That result also remained below Google’s benchmark.
Point addition becomes the focus
The research team concentrated on optimizing point addition, a calculation that must be performed repeatedly when Shor’s algorithm is used against elliptic-curve cryptography.
Shor’s algorithm is particularly relevant to cryptocurrencies because a sufficiently capable quantum computer could potentially use it to derive a private key from a public key that has been exposed. An attacker could then potentially sign transactions and make them appear to come from the legitimate wallet owner.
Both Bitcoin and Ethereum use secp256k1, the cryptographic system targeted by the researchers.
The optimization effort involved more than 100 contributors over approximately eight weeks through ECDSA.Fail, an open challenge created by Eigen Labs. Participants submitted more than 400 accepted solutions, with successful improvements becoming the foundation for additional research.
AI coding agents were heavily involved in implementing designs, running repeated tests and making incremental improvements. Human participants generally selected research approaches and carried out larger changes to the circuit architecture.
The researchers did not attempt to determine exactly how much of the overall improvement was attributable to humans versus AI.
The results nevertheless point to an important development in the quantum-security debate: progress does not necessarily require quantum computers themselves to become dramatically more powerful. Making the algorithms more efficient can reduce the amount of hardware required for a future attack.
A complete attack remains far away
Despite the lower estimates, the research does not demonstrate that Bitcoin or Ethereum can currently be broken by a quantum computer.
The circuit examined by the researchers represents only one major component of a potential attack. It does not account for physical error correction, the complete implementation of Shor’s algorithm or certain hardware-related costs associated with operating the computation on a real quantum machine.
No existing quantum computer is capable of using the research results to compromise Bitcoin or Ethereum.
The computational estimates have also continued to decline beyond the paper’s main July cutoff. One later design reduced the score to approximately 1.26 billion.
Another approach reduced the required machine size to 813 logical qubits, although that design demanded considerably more computation.
Jieyi Long, lead author of the paper and CTO of Theta Labs, told CoinDesk that the findings should not be interpreted as evidence that a quantum attack is about to happen. Instead, he stressed that the concern comes from the amount of time required to develop and deploy effective defenses.
The issue is becoming more relevant as governments and technology companies invest in increasingly capable quantum systems.
This week, the U.S. Commerce Department finalized CHIPS Act awards worth up to $100 million each for Rigetti, D-Wave and Quantinuum. The government is taking minority stakes in all three companies, with the funding intended to help develop larger fault-tolerant quantum computers.
For the cryptocurrency industry, the latest results do not signal an immediate threat to Bitcoin or Ethereum. They do, however, show that researchers are steadily lowering the computational requirements for the cryptographic calculations involved in a future quantum attack, reinforcing the need for blockchain networks to prepare defenses well before such machines become practical.































