Estimates for the cost of a key computation in a potential quantum-computer attack targeting bitcoin and ethereum have fallen to less than half of previous levels. It is not yet at a level that can immediately hack cryptocurrency networks, but it is expected to amplify calls to bring forward the timing for the blockchain industry to shift its security in line with advances in quantum-computing technology.
On Sept. 11 local time, blockchain media outlet CoinPost reported that Jae-yi Long (지에이 롱), chief technology officer at blockchain company CitahLab, disclosed research results related to quantum security for bitcoin and ethereum on X on Sept. 10.
The research focused on optimising the computation required for a quantum-computer attack on secp256k1, a cryptographic method used by both bitcoin and ethereum. The researchers improved elliptic-curve point addition operations used in Shor's algorithm. They designed a circuit using 1,151 logical qubits and about 1.3 million Toffoli gates.
The results improved significantly through an open challenge that ran for about two months. The initial submission score was 10,750,000,000, but it was ultimately reduced to 1,496,000,000. The researchers explained that the figure is less than half the benchmark Google Quantum AI presented in March.
Multiple blockchain and quantum researchers took part in the study rather than a single institution. Blockchain infrastructure company Eigen Labs hosted the challenge, with more than 100 researchers participating from the Ethereum Foundation, StarkWare, CitahLab and others. Participants submitted more than 400 improvement proposals over about two months. The research proceeded in a competitive format in which one participant built on a prior participant's results for further optimisation.
AI agents were also used in the development process. The AI agents handled code writing and verification and detailed optimisation tasks, while researchers set the overall direction and changed circuit designs. Eigen Labs built an open benchmark and leaderboard based on Google's presentation of a proof demonstrating the existence of a verified circuit without disclosing the circuit itself. That enabled multiple researchers to compete to optimise toward the same goal.
The results should not be taken to mean bitcoin or ethereum encryption can soon be cracked. What was optimised was one core computational process within the full quantum attack. It did not include the full Shor's algorithm computation required for an actual attack or physical error-correction processes. The research team also drew a line, saying bitcoin or ethereum cannot be cracked using this result with current quantum-computing technology alone.
Even so, the industry's vigilance is growing as the cost of quantum attacks is falling faster than expected. In follow-up research, a design adjusted to a form closer to an actual implementation of Shor's algorithm produced a result of about 1,960,000,000 points, which was later further improved to about 1,260,000,000 points. After the submission deadline, a design also emerged that cut the number of Toffoli gates to 952,707. Another design reduced logical qubits to 813, but in that case total computation increased sharply.
As quantum computers become a reality, the threats cryptocurrencies could face are also being set out more concretely. IonQ estimated that if a fault-tolerant quantum computer with about 20,000 physical qubits is secured, secp256k1 encryption could be cracked in about 26 days.
In particular, cryptocurrencies whose public keys are already exposed on-chain could be more exposed to potential quantum-attack risks. Coinbase's advisory council estimated that, as of June, about 7,000,000 BTC is held in addresses with public keys exposed on-chain. Ethereum is also preparing for the quantum-computing threat. Ethereum aims to fully shift the network to a quantum-resistant system by December 2029.
In the industry, some point out that the time needed to change security systems starting now is more important than when quantum computers could actually carry out attacks. Long assessed that a quantum attack is not imminent, but stressed it requires a long time to respond and that it is difficult to change security systems after problems occur, making urgent preparations necessary. Eli Ben-Sasson (일라이 벤 사손), StarkWare's co-founder and CEO, also pointed out that the cost of cracking encryption fell by about half in just two months, and said existing assumptions about when quantum computers will become a reality should be reviewed.
The study is therefore read less as a signal that bitcoin and ethereum security has immediately collapsed and more as a case that forces the industry to recalculate its preparation time for quantum threats. With the scale of assets whose public keys are already exposed and Ethereum's transition timetable presented, quantum-resistant transition plans and the pace of real-world deployment are expected to become key points to watch.