A team of researchers has successfully reduced the computational complexity estimate for a key phase of a future quantum attack on Bitcoin and Ethereum by more than 50% compared to the baseline set by Google. CoinDesk reports this significant finding.
Our very own CTO @jieyilong is the lead author on a paper that cuts the estimated quantum cost of the core operation in breaking Bitcoin and Ethereum's cryptography by more than half. https://t.co/2K3AzwuoBL
— Theta Network (@Theta_Network) September 10, 2026
More than 100 specialists and AI agents contributed to this research.
Estimation Reduced from 3 Billion to 1.5 Billion
Experts from the Ethereum Foundation, Theta Labs, StarkWare, and other organizations developed a quantum circuit for a critical operation within Shor's algorithm. This circuit requires 1,151 logical qubits and approximately 1.3 million Toffoli gates.
The researchers compared these requirements to the size of a quantum computer and the computation volume: a lower qubit count indicates a more compact quantum computer, while fewer gates suggest reduced computational workload.
The final estimate for the circuit was around 1.5 billion conditional units, which is over 50% lower than the approximately 3 billion reported by Google Quantum AI in March. However, the researchers caution that this comparison may not be fully accurate due to differences in interfaces and accounting methods.
An adapted version of the circuit, designed for more practical implementation in Shor's algorithm, yielded an estimate of about 1.96 billion.
AI Played a Role in Optimization
The researchers optimized the point addition operation on elliptic curves, which is repeatedly performed in Shor's algorithm.
Over 100 participants spent around eight weeks working on this task as part of the open challenge ECDSA.Fail, organized by Eigen Labs. During this time, they implemented more than 400 accepted improvements, each serving as a starting point for subsequent participants.
AI agents were actively utilized in the process, assisting with code writing, conducting numerous tests, and executing minor optimizations. Human participants primarily directed the research focus and made more substantial architectural changes. The authors did not separately assess the contributions of humans and AI to the final outcome.
This indicates that advancements in quantum attack preparations might not solely depend on the development of more powerful computers. Enhancements in algorithms and software optimizations can also reduce hardware requirements.
Significant Challenges Remain Before Bitcoin is Hacked
The researchers did not optimize the entire attack. The presented circuit covers only one of the main computational operations and does not include physical error correction, a complete calculation of Shor's algorithm, or various hardware costs that would arise in a real quantum computer.
As a result, current systems cannot leverage these findings to compromise Bitcoin or Ethereum.
Moreover, calculations continue to evolve. The research mentions a later design with an estimate of about 1.26 billion, while another variant reduces the requirement to 813 logical qubits but necessitates significantly more computations.
Bitcoin and Ethereum utilize secp256k1, a cryptographic scheme based on elliptic curves, which is the target of the discussed attack. A sufficiently powerful fault-tolerant quantum computer could theoretically use Shor's algorithm to derive a private key from a public key and sign transactions on behalf of the owner.
However, the authors of the study do not believe that a quantum attack on cryptocurrencies is imminent. They argue that the real challenge lies in transitioning to quantum-resistant cryptography, a process that could take years, and compromised keys cannot be retroactively secured.
It is worth noting that IonQ estimates that a fault-tolerant quantum computer with approximately 20,000 physical qubits would require 26 days to break the cryptography on secp256k1.
