{"slug": "researchers-cut-quantum-resource-benchmark-20-fold-for-bitcoin-and-ethereum", "title": "Researchers cut quantum resource benchmark 20-fold for Bitcoin and Ethereum attack", "summary": "A Google Quantum AI, Ethereum Foundation, and Stanford collaboration published a March 30, 2026 whitepaper showing that fewer than 500,000 physical superconducting qubits could break the 256-bit elliptic curve cryptography securing Bitcoin and Ethereum, down from prior estimates of roughly 9 million — a 20-fold reduction. The paper's two circuit variants use 1,200 logical qubits with 90 million Toffoli gates or 1,450 logical qubits with 70 million Toffoli gates, running in roughly 9 to 23 minutes, and estimate a 41% success probability for an on-spend attack during Bitcoin's 10-minute block window. The researchers estimate approximately 6.9 million BTC, including 1.7 million from legacy Satoshi-era P2PK outputs, and roughly 20.5 million ETH are exposed via visible public keys, with admin keys governing about $200B in assets also at risk; co-author Dan Boneh advocated a measured migration to post-quantum signature schemes.", "body_md": "Photo: Rafael Minguet Delgado / Pexels\n\n# Researchers cut quantum resource benchmark 20-fold for Bitcoin and Ethereum attack\n\nA Google-led team cut the estimated physical qubits needed to crack crypto's core cryptography by roughly 20 times, putting the timeline for quantum threats closer than most expected.\n\nA collaboration between [Google](https://cryptobriefing.com/markets/alphabet/) Quantum AI, the Ethereum Foundation, and Stanford has published a whitepaper detailing optimized quantum circuits that could break the elliptic curve cryptography underpinning [Bitcoin](https://cryptobriefing.com/markets/bitcoin/) and [Ethereum](https://cryptobriefing.com/markets/ethereum/). The key finding: fewer than 500,000 physical superconducting qubits would be needed, down from prior estimates of roughly 9 million. That’s a 20-fold reduction in the hardware required to run what amounts to a skeleton key for blockchain wallets.\n\nThe paper, dated March 30, 2026, focuses on solving the 256-bit elliptic curve discrete logarithm problem, known as ECDLP-256. This is the math problem that keeps private keys private. Crack it, and you can derive anyone’s private key from their public key. The researchers used Shor’s algorithm targeting the secp256k1 curve, which is the specific flavor of elliptic curve cryptography that Bitcoin and Ethereum both rely on.\n\n## The numbers that matter\n\nThe paper presents two circuit variants. One operates with a maximum of 1,200 logical qubits and 90 million Toffoli gates. The other uses 1,450 logical qubits and 70 million Toffoli gates. Execution time for these circuits clocks in at roughly 9 to 23 minutes depending on the variant, running on a standard superconducting surface-code architecture. Previous academic benchmarks suggested you’d need a quantum computer with around 9 million physical qubits. This paper argues you’d need fewer than 500,000.\n\nThe resulting benchmark sits at less than half of Google’s previously reported level, though the two approaches use different accounting methods. In parallel, a separate study by researchers from Caltech and Oratomic has explored neutral-atom architectures, claiming physical qubit requirements as low as 10,000 to 26,000 for similar computations. The catch is runtime: those systems would take days rather than minutes.\n\n## What’s actually at risk\n\nThe paper identifies two distinct attack vectors. The first, called an “on-spend” attack, targets transactions while they’re being broadcast to the network. During Bitcoin’s average 10-minute block confirmation window, a sufficiently powerful quantum computer could theoretically intercept the revealed public key and derive the private key before the transaction is confirmed. The researchers estimate roughly a 41% success probability under certain conditions for this type of attack.\n\nThe second vector, an “at-rest” attack, goes after wallets whose public keys are already visible on the blockchain. The researchers estimate approximately 6.9 million BTC are sitting in wallets with exposed public keys. Around 1.7 million of those come from legacy Satoshi-era P2PK outputs, the earliest Bitcoin transaction format that broadcasts the full public key rather than a hash of it.\n\nOn the Ethereum side, roughly 20.5 million ETH face similar exposure. Administrative keys controlling smart contracts for stablecoins and other tokenized assets represent an additional vulnerability. The paper pegs the value of assets governed by these admin keys at around $200B.\n\nTo their credit, the researchers practiced responsible disclosure. They used zero-knowledge proofs to verify their claims without actually publishing the circuit designs.\n\n## Migration, not panic\n\nDan Boneh, a Stanford cryptographer and co-author of the paper, has advocated for a measured approach to migrating toward post-quantum signature schemes. No quantum computer currently in existence comes close to the 500,000 physical qubit threshold. Google’s most advanced publicly known quantum processor, Willow, operates with 105 qubits.\n\nFor holders, the practical takeaway is straightforward. Wallets that have never broadcast a transaction, and thus never exposed their public key, remain safe from at-rest attacks. The simplest defensive measure is using fresh addresses for every transaction and avoiding address reuse. The 6.9 million BTC and 20.5 million ETH at risk are largely in older wallets or those using outdated address formats.\n\n**Disclosure:** This article was edited by Editorial Team. For more information on how we create and review content, see our\n\n[Editorial Policy](https://cryptobriefing.com/editorial-policy/).", "url": "https://wpnews.pro/news/researchers-cut-quantum-resource-benchmark-20-fold-for-bitcoin-and-ethereum", "canonical_source": "https://cryptobriefing.com/quantum-attack-bitcoin-ethereum-benchmark/", "published_at": "2026-09-10 13:05:40+00:00", "updated_at": "2026-09-10 13:39:03.516986+00:00", "lang": "en", "topics": ["ai-research", "ai-safety"], "entities": ["Google Quantum AI", "Ethereum Foundation", "Stanford", "Bitcoin", "Ethereum", "Dan Boneh", "Caltech", "Oratomic"], "alternates": {"html": "https://wpnews.pro/news/researchers-cut-quantum-resource-benchmark-20-fold-for-bitcoin-and-ethereum", "markdown": "https://wpnews.pro/news/researchers-cut-quantum-resource-benchmark-20-fold-for-bitcoin-and-ethereum.md", "text": "https://wpnews.pro/news/researchers-cut-quantum-resource-benchmark-20-fold-for-bitcoin-and-ethereum.txt", "jsonld": "https://wpnews.pro/news/researchers-cut-quantum-resource-benchmark-20-fold-for-bitcoin-and-ethereum.jsonld"}}