On April 24, Project Eleven recognized Giancarlo Lelli with its Q-Day Prize for successfully deriving a 15-bit elliptic curve private key from its public counterpart using publicly available quantum hardware.
This marks the largest public exhibition of a quantum attack method that could eventually pose risks to Bitcoin, Ethereum, and any other systems relying on elliptic curve cryptography. Lelli was awarded one Bitcoin for his accomplishment.
It’s noteworthy that a researcher obtained Bitcoin by exploiting a simplified version of the mathematics that secures it.
The 15-bit key offers significantly less security than Bitcoin’s 256-bit elliptic curve, and currently, no publicly known quantum computer is capable of compromising actual Bitcoin wallets.
This development emerges at a time of increasing urgency, as Google recently revised its resource estimates for ECDLP-256, imposing a migration deadline of 2029 within the same month.
Understanding Lelli’s Method
Lelli employed a variation of Shor’s algorithm, a quantum computational technique aimed at solving the elliptic curve discrete logarithm problem, which underpins Bitcoin’s signature framework, to extract a private key from a public key within a search domain of 32,767.
The Q-Day Prize competition challenged participants to break the largest possible ECC key using a quantum computer, without relying on classical techniques or hybrid methods.
Lelli’s achievement of a 15-bit key was the farthest any contestant reached by the deadline, with Project Eleven noting it represented a 512-fold increase over Steve Tippeconnic’s 6-bit demonstration from September 2025.
The quantum computer utilized for this task was equipped with approximately 70 qubits, according to reports from Decrypt, with evaluation conducted by an independent panel that included experts from the University of Wisconsin-Madison and qBraid, as indicated by Project Eleven.
This outcome can be viewed as a tiny lock being picked using methods that could one day challenge the integrity of secure vaults. For now, the locksmiths have advanced, but the vault remains intact.
| Claim | Supporting Evidence | Importance |
|---|---|---|
| A quantum computer breached a 15-bit ECC key | According to Project Eleven, Giancarlo Lelli derived a 15-bit elliptic curve private key from a public key using publicly available quantum technology | This transforms the quantum threat from a theoretical concern to a concrete demonstration |
| Bitcoin itself was not compromised | The text specifies that no known quantum computer can currently break real Bitcoin wallets | This maintains the integrity of the article and avoids exaggerating the significance of the finding |
| The demonstration used a method relevant to Bitcoin | Lelli employed a version of Shor’s algorithm targeting the elliptic curve discrete logarithm challenge, foundational to Bitcoin’s signature scheme | This links the demonstration to actual cryptographic risks without suggesting equivalence |
| The demonstration adhered to strict guidelines | The Q-Day Prize necessitated contestants to break the largest ECC key using quantum computing without shortcuts | This emphasizes the significance of the finding as a quantum benchmark |
| The outcome surpassed previous public ECC demonstrations | Project Eleven characterized the 15-bit achievement as a 512-fold increase over Steve Tippeconnic’s 6-bit result from September 2025 | This underscores progress in public demonstrations |
| The disparity to Bitcoin’s 256-bit security is vast | It is noted that a 15-bit key does not approach Bitcoin’s 256-bit elliptic curve security | This key caveat assists readers in understanding the story accurately |
| The hardware involved was still minimal by actual attack standards | The quantum computer in question reportedly had around 70 qubits | This indicates that the achievement is significant as a milestone but not proof of imminent full-scale attacks |
| The overall narrative is one of caution, not alarm | Public demonstrations are getting progressively larger, resource estimates are declining, and migration deadlines are becoming clearer | The threat remains in the future, but the timeframe is increasingly harder to ignore |
This demonstration carries more weight than it would have six months ago, in part due to Google’s recent actions.
On March 31, Google released updated ECDLP-256 resource estimates for circuits that require fewer than 1,200 logical qubits and 90 million Toffoli gates, or fewer than 1,450 logical qubits and 70 million Toffoli gates.
These circuits were estimated to be executable on a superconducting quantum computer relevant to cryptography with under 500,000 physical qubits, representing nearly a 20-fold decrease from previous calculations.
On March 25, Google announced a 2029 target for its transition to post-quantum cryptography, explicitly linking this deadline with advancements in hardware, error correction, and resource assessments.
Cloudflare adopted the same 2029 target on April 7, referencing both Google’s study and a Caltech/Oratomic preprint that underscores the urgency for acceleration.
The preprint argued that neutral-atom architectures could implement Shor’s algorithm at cryptographically relevant scales with as few as 10,000 reconfigurable atomic qubits.
In a commentary on April 9, QuTech noted that even at 10,000 qubits, the architecture would still need nearly three years to decipher a single ECC-256 key, while an optimally efficient setup with 26,000 qubits could shorten the computation time to about 10 days.
Both projections rely on machines that currently do not exist, and the Caltech/Oratomic analysis remains an unverified preprint.
The key takeaway from these numbers is that some theoretical architectures now propose long-term hardware requirements significantly lower than what researchers believed just a year ago.
The timeline for public demonstrations is tightening, resource estimates are diminishing, and migration schedules are taking on real deadlines.

Current Vulnerabilities in Bitcoin Wallets
As per Project Eleven’s live tracker, 6,934,064 BTC are currently susceptible to quantum attacks.
The primary vulnerability lies in the fact that quantum attacks pose the highest risk when a public key is visible on-chain, which occurs with older address types, reused addresses, and partial transactions.
Numerous Bitcoin wallets have revealed their public keys through prior transactions. Google’s publication on March 31 heightened awareness of this issue, noting that advanced cryptographically-relevant quantum computers might even facilitate attacks on public mempool transactions, escalating risks from inactive wallets to active ones.
In response, Bitcoin governance has initiated BIP 360, proposing a new output format to eliminate Taproot’s quantum-vulnerable key-path spend. BIP 361 suggests a gradual phase-out of legacy signatures, which will push quantum-vulnerable outputs toward urgent migration.
The existence of these proposals confirms that Bitcoin is entering a migration phase. The larger challenge ahead lies in whether a decentralized network can reach a consensus on incentives, timelines, and the status of dormant or lost coins before urgency overtakes coordination efforts.
Future Paths
In an optimistic scenario, migration becomes standard practice before an emergency arises.
The 2029 targets set by Google and Cloudflare reset industry standards, leading wallet providers and exchanges to steer users away from long-exposure address models, and Bitcoin governance rallies around output modifications before any viable quantum computer surfaces.
In this case, the threat remains speculative while the pool of BTC at risk from exposed public keys diminishes as technologies advance.
Conversely, in a pessimistic scenario, the progression towards attacks begins to resemble engineering rather than science fiction, outpacing the response from governance.
More demonstrations of public key breaks emerge, estimates for hardware drop again, and the market begins to reassess the vulnerability of exposed UTXOs and idle coins.
The fallout in this scenario starts with diminished confidence, intra-governance disputes, and hurried migration planning under pressure. A decentralized system without centralized authority to enforce deadlines faces the most significant difficulties.
| Scenario | Key Changes | Ongoing Vulnerabilities | Market/Governance Consequences |
|---|---|---|---|
| Optimistic Scenario | Migration becomes standard practice prior to any crisis; wallet providers, exchanges, and developers begin minimizing public-key exposure | Older address formats, reused addresses, and some inactive wallets still carry risks until fully migrated | Trust remains intact as the ecosystem views quantum risks as an infrastructure upgrade rather than a crisis |
| Pessimistic Scenario | Demonstrations of public key breaks continue to improve while hardware/resource estimates decrease more rapidly than governance adapts | Exposed public keys, inactive coins, partial transactions, and active transactions stay vulnerable for an extended period | Markets begin re-evaluating exposed UTXOs, governance disputes escalate, and migration pressures mount |
| Measures for Reducing Risks Quickly | Enhanced wallet hygiene, fewer reused addresses, reduced public-key exposure, adoption of new output types, and phased retirement of legacy signatures | Coordination difficulties persist, particularly concerning lost coins and users who are slow to adapt | The network gains time and minimizes the number of coins at risk before cryptographically significant quantum machines become available |
| Factors Raising Urgency | Larger public demonstrations, lower hardware projections, quicker clock architectures, and more substantial evidence that on-spend or mempool attacks could soon be feasible | Any wallet with a visible public key grows increasingly vulnerable to future technological advances | The conversation shifts from “should we prepare?” to “how quickly can Bitcoin coordinate its efforts?” |
| External Deadlines of Importance | Google and Cloudflare set a 2029 target; the UK’s NCSC outlines milestones for 2028, 2031, and 2035 | Decentralized crypto networks naturally cannot move as swiftly as centralized companies | Bitcoin faces a tougher migration challenge because it relies on distributed consensus rather than a central command |
| Critical Implications | In the best case, Q-Day stays distant enough for migration to preempt the threat | In the worst case, technological advancements outstrip social and governance responses | The primary risk lies not just in the eventual key-breaking capacity but in whether the ecosystem can align before urgency surpasses coordination abilities |
The UK’s National Cyber Security Center has set migration milestones for 2028, 2031, and 2035, while both Google and Cloudflare are aiming for 2029.
The Ethereum Foundation emphasizes that transitioning a global decentralized protocol takes years and must begin before the risk becomes imminent.
The quantum threat to Bitcoin has now transitioned to public demonstrations, corporate migration timelines, and proposed protocol changes.
