A groundbreaking collaboration involving over 100 researchers and AI coding agents has significantly reduced the estimated computational resources required for a vital process in a potential quantum attack on Bitcoin and Ethereum, halving the previous estimates published by Google in March, as detailed in a paper released on Wednesday.
This achievement stemmed from an open competition called ECDSA.Fail, initiated by blockchain infrastructure company Eigen Labs in late May. The endeavor resulted in the creation of a quantum circuit utilizing 1,151 logical qubits and approximately 1.3 million Toffoli gates. The overall score of around 1.5 billion is less than half of the approximately 3 billion disclosed by Google Quantum AI earlier this year, though the researchers noted that variations in testing protocols and measurement methods hinder a direct comparative analysis.
The circuit enhances point addition, a calculation that is repeatedly executed in Shor’s algorithm, the quantum technique capable of converting an exposed public key into its corresponding private key. A sufficiently advanced quantum machine could then authorize transactions as if it were the legitimate wallet owner. Both Bitcoin and Ethereum are based on secp256k1, the elliptic curve targeted in this study.
Significant Progress in Eight Weeks
The open challenge attracted participants from the Ethereum Foundation, StarkWare, Theta Labs, MultiVM Labs, Trail of Bits, and various other organizations. Over about eight weeks, contributors submitted more than 400 accepted improvements, with each successful submission serving as a foundation for the next participant’s contributions.
AI agents took charge of much of the implementation, conducting repeated tests and making minor optimizations, while human researchers guided the overall strategy and introduced larger design modifications. The paper does not quantify the extent of improvement derived from human versus AI contributions.
“Beyond the resulting circuits, ECDSA.Fail exemplifies Open Autoresearch: a verified research paradigm where human participants and AI agents iteratively generate, apply, test, and share enhancements against a common measurable goal,” the authors of the study noted.
The primary finding reflects data collected up to July 26. The paper also presents a design more attuned to how Shor’s algorithm would deploy the calculation, achieving a score of about 1.96 billion, still below Google’s reported figures. After the submission deadline, further improvements emerged: one design lowered the score to approximately 1.26 billion, while another reduced the logical qubit count to 813, requiring significantly more computational power.
Limitations of the Research
The researchers clarified that the circuit addresses only one essential calculation in a complete quantum attack. It does not encompass physical error correction, the complete Shor’s algorithm, or the hardware-specific costs linked to running on an actual quantum computer. Currently, no existing machine can use this research to compromise Bitcoin or Ethereum.
The research’s importance lies in a different implication: quantum hardware advancements are not necessary for the theoretical attack to progress. Researchers can also lower the computational requirements for executing the attack.
“This is not an urgent situation because an attack is imminent,” said lead author and Theta Labs CTO Jieyi Long. “The urgency arises from the fact that remedies require years to develop and cannot be retroactively applied.”
StarkWare co-founder and CEO Eli Ben-Sasson echoed this sentiment, suggesting that the recent halving of the cost to breach cryptography warrants a reevaluation of when quantum computers may pose a real threat.
Wider Context and Industry Reactions
This research arrives at a time when the U.S. Commerce Department has finalized CHIPS Act awards, granting up to $100 million each to Rigetti, D-Wave, and Quantinuum, while taking minority stakes in these companies. The funding aims to support the larger fault-tolerant machines necessary for a potential future attack.
The growing quantum threat to cryptocurrency has garnered increased attention from the industry. In July, Galaxy Digital committed up to $5 million toward quantum defense research, while nine firms, including BlackRock, Coinbase, and Strategy, pledged a combined $15 million over three years for broader security research concerning Bitcoin’s quantum defenses.
According to IonQ, a quantitative computing developer, a fault-tolerant system with around 20,000 physical qubits could compromise secp256k1 encryption in just 26 days. Coinbase’s advisory council estimated in June that roughly 7 million BTC resides in addresses with publicly exposed keys on-chain. Ethereum aims to transition to quantum-resistant cryptography by December 2029.
The researchers pointed out that the transition from at-risk cryptography is already in progress. NIST has standardized post-quantum alternatives, and an initial public draft of NIST IR 8547 proposes phasing out classical public-key algorithms with a 112-bit security level after 2030 and banning them post-2035.
The ECDSA.Fail challenge emerged following Google Quantum AI’s publication of a proof indicating the existence of a verified circuit in March, although the circuit itself remained confidential. Eigen Labs then established a public benchmark and leaderboard based on Google’s verification tool, inviting a broader research community to engage with the problem.
Key Metrics from the Research:
| Metric | Value |
|---|---|
| Initial challenge score (late May) | 10.75 billion |
| Headline result (July 26 cutoff) | 1.496 billion |
| Google Quantum AI March benchmark | ~3 billion |
| Leading circuit logical qubits | 1,151 |
| Leading circuit Toffoli gates | ~1.3 million |
| Post-deadline best score | ~1.26 billion |
| Post-deadline lowest qubit count | 813 |
Note: The paper cautioned that comparisons to Google’s benchmark are not entirely equivalent due to differences in interfaces and accounting methods.
The findings illustrate a crucial assertion for the cryptocurrency sector: the timeline for quantum threats does not solely hinge on hardware advancements. Algorithmic and software innovations can accelerate this threat even while quantum machines continue to be developed. With transition timelines extending over several years, researchers contend that proactive defense strategies must begin without waiting for a definitive announcement of the arrival of quantum threats.
