Stanford’s Dan Boneh warns quantum computers could crack Bitcoin and Ethereum sooner than expected A revised estimate from Google Quantum AI, co-authored by Stanford professor Dan Boneh and Ethereum researcher Justin Drake, suggests that breaking the elliptic-curve cryptography securing Bitcoin and Ethereum may require only 1,200 to 1,450 logical qubits and tens of millions of Toffoli gates, far fewer than previously thought. This puts an estimated 6.9 million BTC and millions of ETH at risk, as Boneh urged the industry to prepare with surgical precision, advocating for hash-based signatures like SLH-DSA over lattice-based solutions. Photo: Markus Winkler / Pexels Stanford’s Dan Boneh warns quantum computers could crack Bitcoin and Ethereum sooner than expected A revised estimate from Google Quantum AI suggests breaking elliptic-curve cryptography may require far fewer qubits than previously thought, putting millions of BTC and ETH at risk. A paper published in March 2026 by Google Quantum AI, co-authored by Dan Boneh and Ethereum researcher Justin Drake, revises previous projections for how much quantum firepower would be needed to crack the elliptic-curve cryptography underpinning Bitcoin and Ethereum transactions. The new estimate: roughly 1,200 to 1,450 logical qubits and tens of millions of Toffoli gates could be sufficient to break the secp256k1 discrete logarithm problem. Earlier estimates often placed the requirement at several thousand logical qubits. When you send Bitcoin, your public key gets exposed on the network during the roughly 10-minute window before the transaction is confirmed in a block. A sufficiently powerful quantum computer could, in theory, derive the private key from that exposed public key and redirect the funds before the block is finalized. An estimated 6.9 million BTC sit behind already-revealed public keys, meaning those coins are vulnerable even without an active transaction. Millions of ETH face the same problem. During an August 2026 cryptocurrency lecture, Boneh stressed that the industry needs to start preparing now, but with surgical precision rather than panic. A rushed migration to quantum-resistant signatures, he argued, could introduce catastrophic bugs that would be worse than the quantum threat itself. Boneh previously supported lattice-based cryptographic solutions, but he is now advocating for hash-based signatures, specifically schemes like SLH-DSA also known as SPHINCS+ . Hash-based signatures are better suited to the constraints of existing blockchain infrastructure, making them a more realistic migration path for networks with billions of dollars in value already locked in. The signatures themselves are considerably larger than current elliptic-curve signatures, and there are wallet state management challenges that developers would need to solve. Boneh has also floated a mechanism for proving ownership of coins in a post-quantum world: a user could leave a cryptographic note on-chain today that would remain verifiable even after quantum computers render current signature schemes obsolete. If a quantum computer eventually cracks a wallet’s private key, the original owner could still prove they were the legitimate holder through a separate, quantum-resistant proof left on-chain beforehand. In theory, someone could open and verify that note 100 years from now. The 6.9 million BTC figure represents a meaningful percentage of Bitcoin’s total supply sitting in a potentially vulnerable state. Any concrete demonstration of quantum progress against elliptic-curve cryptography, even a partial one, could trigger significant repricing of risk across the entire crypto market. Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy https://cryptobriefing.com/editorial-policy/ .