source: The Quantum Insider
A team of more than 100 contributors has sharply reduced the estimated computing resources a future quantum machine would need to break the encryption protecting Bitcoin and Ethereum wallets, according to CoinDesk, which obtained the research paper ahead of publication on September 10.
The paper, posted to arXiv and involving contributors from the Ethereum Foundation, Theta Labs, StarkWare and several other organizations, describes a quantum circuit requiring 1,151 logical qubits and roughly 1.3 million Toffoli gates to perform a key arithmetic step used in Shor’s algorithm.
Logical qubits represent the machine’s working units. Toffoli gates measure the volume of computation it must carry out.
The combined score for those two figures comes to approximately 1.5 billion, more than 50% below the roughly 3 billion benchmark that Google Quantum AI published in March.
The paper notes the comparison is not perfectly direct because the two designs use different accounting methods.
What the Researchers Actually Optimized
The work focused on elliptic-curve point addition for the secp256k1 curve, which underpins the cryptographic system both Bitcoin and Ethereum rely on to keep private keys secure.
Rather than model an entire attack, the team refined this single arithmetic component of Shor’s algorithm. That distinction matters.
As The Quantum Insider reported, the project combined human scientists with AI agents and measured an 86.1% reduction from its own internal starting point, though the 50%-plus improvement relative to Google’s March figure is the comparison most relevant to the broader field.
No existing quantum computer can carry out this kind of attack. The research narrows estimates of what a future fault-tolerant machine would require, not what today’s hardware can do.
Which Assets Face Exposure
Crypto Briefing reported that a separate Google Quantum AI paper from March identified two categories of at-risk holdings.
Wallets where the full public key is already visible on-chain are vulnerable to an at-rest attack, and the March paper estimated roughly 6.9 million BTC sits in such addresses. On the Ethereum side, approximately 20.5 million ETH faces similar exposure.
A second threat, called an on-spend attack, targets transactions while they are being broadcast to the network.
During the roughly 10-minute Bitcoin block confirmation window, a fast enough quantum computer could theoretically derive a private key from the revealed public key before the transaction settles.
The Case for Acting Before Hardware Catches Up
Jieyi Long, lead author of the paper and co-founder and chief technology officer of Theta Labs, told The Quantum Insider that credible, reproducible resource estimates are essential for planning a migration to quantum-resistant cryptography.
Long noted that roughly a third of all Bitcoin already sits in addresses where the public key is visible. Fixing this cannot be done retroactively once a sufficiently powerful machine exists.
The collective effort across more than 100 contributors halved the cost estimate for the central arithmetic step, Long said, adding that the urgency stems not from any imminent attack but from the fact that the remediation process takes years.
Years. Not months.
Blockchain developers who want to understand the full scope of the cryptographic risk can follow the parallel track: Crypto Briefing noted a separate Caltech and Oratomic study explored neutral-atom architectures that might need only 10,000 to 26,000 physical qubits for similar computations, though those systems would take days rather than minutes to run.