A Bitcoin quantum attack just got a little easier on paper — and that is exactly why researchers are paying attention.
A new study from researchers linked to the Ethereum Foundation, Theta Labs, StarkWare and other organizations has cut the estimated computational work for a key part of a future quantum attack by more than half compared with a benchmark published by Google Quantum AI in March.
The result does not mean Bitcoin or Ethereum can be cracked today. It does, however, move an important number on the quantum clock.
The researchers designed a quantum circuit requiring 1,151 logical qubits and roughly 1.3 million Toffoli gates. In simple terms, one figure describes the machine size while the other represents how much work it must perform.
Their main design produced a score of about 1.5 billion — more than 50% below Google’s roughly 3 billion benchmark.
The comparison comes with a footnote. The two designs use different interfaces and accounting methods, so the numbers are not perfectly equivalent. A second version designed to more closely match how the calculation would actually be used inside Shor’s algorithm scored around 1.96 billion, still below Google’s result.
Why the Bitcoin quantum attack keeps getting cheaper
The researchers focused on point addition, a mathematical operation that Shor’s algorithm would repeat extensively when targeting the elliptic-curve cryptography used by cryptocurrencies.
Shor’s algorithm is designed to exploit sufficiently powerful quantum computers to derive a private key from an exposed public key. In a successful attack, that could allow someone to authorize transactions as though they controlled the wallet.
Bitcoin and Ethereum both rely on secp256k1, the specific cryptographic system targeted in this research.
The project was unusually collaborative. More than 100 people spent around eight weeks working through ECDSA.Fail, an open challenge created by Eigen Labs. The effort generated more than 400 accepted submissions, with each improvement giving the next participant a stronger starting point.
Artificial intelligence was part of that process, too.
AI coding agents were used extensively for implementation, testing and incremental optimization. Human researchers generally handled broader strategic decisions and larger architectural changes. The paper does not try to calculate exactly how much of the progress came from humans versus AI.
That distinction matters because quantum progress is not only about building better hardware.
A Bitcoin quantum attack also becomes more plausible when researchers discover ways to make the underlying algorithms more efficient. In other words, the machine does not necessarily need to get dramatically more powerful if the workload itself keeps shrinking.
Still, there is a significant amount missing from the new estimates.
The researchers did not build a complete attack. Their work covers one major component and does not include physical error correction, the full implementation of Shor’s algorithm or every hardware-specific cost involved in running the system on a real quantum computer.
No existing quantum computer can use this research to break Bitcoin or Ethereum.
And the number is already moving again. Because the headline result used a July cutoff, later designs reported in the research pushed the score down to roughly 1.26 billion. Another approach reduced the machine requirement to 813 logical qubits, although it demanded substantially more computation.
That is why the headline is less about an imminent Bitcoin breach than about how researchers measure the distance to one.
“None of this is urgent because an attack is imminent,” lead author and Theta Labs CTO Jieyi Long told CoinDesk. “It is urgent because the remedy takes years and cannot be applied retroactively.”
That last point is the uncomfortable part.
Cryptographic systems cannot simply be rewritten the moment a sufficiently powerful quantum computer arrives. Moving users, wallets, exchanges and networks to new defenses takes time, and some information exposed before the transition cannot simply be pulled back behind new security.
The research arrives as the quantum computing industry is also receiving fresh support from Washington. This week, the U.S. Commerce Department finalized CHIPS Act awards worth up to $100 million each for Rigetti, D-Wave and Quantinuum, alongside minority stakes in the three companies.
The funding is aimed at building larger fault-tolerant quantum machines — precisely the kind of systems that would eventually matter for attacks of this scale.
For now, Bitcoin’s cryptography remains intact. But the equation is becoming more interesting: researchers are not waiting for quantum hardware to catch up. They are also finding ways to make the attack require less of it.
