Bitcoin and Ethereum Quantum Attack Step Estimate Cut Over 50%
Researchers have cut the estimated quantum cost of a key step in attacking Bitcoin and Ethereum by more than half, reporting an 86. 1% reduction in a benchmark for reversible secp256k1 point addition, a single component of Shor's algorithm and not an executable attack on either network.
The result comes from the ECDSA.Fail preprint, an open “autoresearch” competition organized by Eigen Labs to optimize elliptic-curve point addition, the arithmetic building block that Shor’s algorithm would need to recover a private key from a public key. The paper connects secp256k1 directly to the signatures that authorize Bitcoin and Ethereum transactions, which is why both networks appear in the framing. For related coverage, see Ethereum Quantum Staking Proposal: First Defense Step.
What Changed in the Quantum Attack Cost Estimate?
A Reduction of More Than Half in One Step
The best-scoring circuit at the paper’s July 26, 2026 cutoff uses 1,151 logical qubits and 1,299,453 average executed Toffoli gates, down from a challenge baseline of 2,715 logical qubits and 3,960,753 gates. The authors express that as an 86.1% reduction in the benchmark score.
Best-scoring circuit at the July 26, 2026 cutoff
1,151 logical qubits
1,299,453 average executed Toffoli gates
What the Cost Estimate Measures
The benchmark score is peak logical qubit width multiplied by average executed Toffoli count, and Section 5.2.1 reports an exact best score of 1,495,670,403. That single figure is what fell by 86.1% against the baseline; it is a logical-resource proxy, not a dollar cost, an attack duration, or a physical-qubit count.
Reported point-addition benchmark reduction
86.1%
Crucially, the paper says the score omits circuit depth, parallelism, routing, memory access and error-correction overhead. It does not establish an executable attack or a complete fault-tolerant resource estimate.
What the Finding Means for Bitcoin and Ethereum
Why Both Networks Are Named
Both Bitcoin and Ethereum authorize spending with ECDSA signatures over the secp256k1 curve, so any efficiency gain in reversible point addition is directly relevant to the theoretical machine that would break those signatures. That shared dependence is exactly why the migration debate has moved from theory to engineering, from Ethereum developers proposing a first step to shield staking from quantum attacks to Ripple preparing the XRP Ledger for the same class of risk.
One Step Versus the Complete Attack
The reduction applies to a key step, not the full attack. The headline benchmark should not be confused with whole-algorithm estimates: a separate Google-led whitepaper reports full 256-bit ECDLP alternatives of fewer than 1,200 logical qubits and fewer than 90 million Toffoli gates, or fewer than 1,450 logical qubits and fewer than 70 million gates, figures that cover an entire algorithm and cannot be compared directly with one point-addition gate count.
The ECDSA.Fail authors do report that their mixed-addition score sits more than 50% below the Google point-addition comparison score, but both the paper and Unchained caution that different interfaces and accounting conventions limit comparability, and the paper expressly disclaims formal dominance. None of this implies a present compromise, identical exposure across the two networks, or any reason for holders to move funds.
What Evidence Would Establish Practical Attack Feasibility?
The paper separately reports a coherent windowed-addition-compatible variant using 1,162 logical qubits and 1,684,161 average executed Toffoli gates, an authors’ result for a single-call interface rather than an independently reproduced full attack. For that variant they report an empirical success probability of 0.99809 over 100,000 random inputs and a retry-adjusted per-call proxy of roughly 1.961 billion, while reserving full-Shor claims until end-to-end assembly and evaluation.
Jieyi Long and coauthors write that the work improves a reversible point-addition primitive relevant to quantum attacks on elliptic-curve cryptography, but that it does not constitute an executable attack or a complete fault-tolerant resource estimate. Converting this benchmark into a feasibility claim would require a validated full-attack resource count, explicit physical-hardware assumptions, and a common-accounting proof against the Google baseline, none of which the preprint provides.
Industry voices read the trend differently. StarkWare CEO Eli Ben-Sasson argued that AI-assisted circuit optimization is narrowing the gap to a quantum attack, according to Unchained’s account of his X statement, while Long cautioned against reading too much into the Google comparison.
The response fits a broader pattern of pre-emptive hardening rather than panic. Bitcoin traded near $76,861 and Ethereum near $2,456 as the paper circulated, with no measured price reaction attributable to the research, and the migration work continues on multiple fronts, from Coinbase and Stanford hosting post-quantum developer sessions to the Ethereum Foundation’s targeted timeline for a quantum-resistant base layer. The signal from ECDSA.Fail is that the primitives are getting cheaper on paper, not that the required fault-tolerant machine exists.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.
