# Researchers cut quantum resource benchmark 20-fold for Bitcoin and Ethereum attack

> Source: <https://cryptobriefing.com/quantum-attack-bitcoin-ethereum-benchmark/>
> Published: 2026-09-10 13:05:40+00:00

Photo: Rafael Minguet Delgado / Pexels

# Researchers cut quantum resource benchmark 20-fold for Bitcoin and Ethereum attack

A Google-led team cut the estimated physical qubits needed to crack crypto's core cryptography by roughly 20 times, putting the timeline for quantum threats closer than most expected.

A collaboration between [Google](https://cryptobriefing.com/markets/alphabet/) Quantum AI, the Ethereum Foundation, and Stanford has published a whitepaper detailing optimized quantum circuits that could break the elliptic curve cryptography underpinning [Bitcoin](https://cryptobriefing.com/markets/bitcoin/) and [Ethereum](https://cryptobriefing.com/markets/ethereum/). The key finding: fewer than 500,000 physical superconducting qubits would be needed, down from prior estimates of roughly 9 million. That’s a 20-fold reduction in the hardware required to run what amounts to a skeleton key for blockchain wallets.

The paper, dated March 30, 2026, focuses on solving the 256-bit elliptic curve discrete logarithm problem, known as ECDLP-256. This is the math problem that keeps private keys private. Crack it, and you can derive anyone’s private key from their public key. The researchers used Shor’s algorithm targeting the secp256k1 curve, which is the specific flavor of elliptic curve cryptography that Bitcoin and Ethereum both rely on.

## The numbers that matter

The paper presents two circuit variants. One operates with a maximum of 1,200 logical qubits and 90 million Toffoli gates. The other uses 1,450 logical qubits and 70 million Toffoli gates. Execution time for these circuits clocks in at roughly 9 to 23 minutes depending on the variant, running on a standard superconducting surface-code architecture. Previous academic benchmarks suggested you’d need a quantum computer with around 9 million physical qubits. This paper argues you’d need fewer than 500,000.

The resulting benchmark sits at less than half of Google’s previously reported level, though the two approaches use different accounting methods. In parallel, a separate study by researchers from Caltech and Oratomic has explored neutral-atom architectures, claiming physical qubit requirements as low as 10,000 to 26,000 for similar computations. The catch is runtime: those systems would take days rather than minutes.

## What’s actually at risk

The paper identifies two distinct attack vectors. The first, called an “on-spend” attack, targets transactions while they’re being broadcast to the network. During Bitcoin’s average 10-minute block confirmation window, a sufficiently powerful quantum computer could theoretically intercept the revealed public key and derive the private key before the transaction is confirmed. The researchers estimate roughly a 41% success probability under certain conditions for this type of attack.

The second vector, an “at-rest” attack, goes after wallets whose public keys are already visible on the blockchain. The researchers estimate approximately 6.9 million BTC are sitting in wallets with exposed public keys. Around 1.7 million of those come from legacy Satoshi-era P2PK outputs, the earliest Bitcoin transaction format that broadcasts the full public key rather than a hash of it.

On the Ethereum side, roughly 20.5 million ETH face similar exposure. Administrative keys controlling smart contracts for stablecoins and other tokenized assets represent an additional vulnerability. The paper pegs the value of assets governed by these admin keys at around $200B.

To their credit, the researchers practiced responsible disclosure. They used zero-knowledge proofs to verify their claims without actually publishing the circuit designs.

## Migration, not panic

Dan Boneh, a Stanford cryptographer and co-author of the paper, has advocated for a measured approach to migrating toward post-quantum signature schemes. No quantum computer currently in existence comes close to the 500,000 physical qubit threshold. Google’s most advanced publicly known quantum processor, Willow, operates with 105 qubits.

For holders, the practical takeaway is straightforward. Wallets that have never broadcast a transaction, and thus never exposed their public key, remain safe from at-rest attacks. The simplest defensive measure is using fresh addresses for every transaction and avoiding address reuse. The 6.9 million BTC and 20.5 million ETH at risk are largely in older wallets or those using outdated address formats.

**Disclosure:** This article was edited by Editorial Team. For more information on how we create and review content, see our

[Editorial Policy](https://cryptobriefing.com/editorial-policy/).
