Google’s Quantum AI team published a landmark whitepaper Tuesday that sharply compresses the estimated timeline for a quantum computer to break the cryptographic foundations of Bitcoin and Ethereum, triggering an industry-wide debate about how much runway remains before a potentially existential threat becomes actionable.
The core finding: the number of physical qubits needed to crack the 256-bit elliptic curve discrete logarithm problem — the mathematical backbone securing cryptocurrency wallets — has dropped roughly 20-fold compared to prior estimates, to fewer than 500,000 physical qubits. A separate paper published the same day by researchers at Caltech and quantum startup Oratomic pushed the threshold even lower, suggesting a neutral-atom quantum system with roughly 26,000 qubits could break that encryption in about 10 days. The Oratomic paper relies on quantum circuits developed by Google, and all nine of its authors hold equity in the company, a conflict the authors disclosed.
The practical implications are significant. Google’s paper outlines two attack vectors. The first is an “at-rest” attack targeting existing wallets with exposed public keys — a pool that includes an estimated 6.9 million BTC tied to early address formats and reused addresses, as well as coins exposed through Bitcoin’s Taproot upgrade, which makes public keys visible by default. The second, more alarming scenario is an “on-spend” attack: intercepting a live Bitcoin transaction in the mempool, deriving the private key before the transaction confirms, and redirecting the funds — potentially completable in around nine minutes under the paper’s model.
This story is an excerpt from the Unchained Daily newsletter.
Subscribe here to get these updates in your email for free
Google has set a 2029 target for migrating its own infrastructure to post-quantum cryptography (PQC) and urged all vulnerable blockchain communities to begin the same transition immediately. The company framed the disclosure as responsible: it coordinated with the U.S. government and developed a zero-knowledge proof mechanism to verify the vulnerability without publishing a step-by-step attack guide.
The crypto industry’s response was divided. Ethereum’s development community pointed to its existing post-quantum migration roadmap. On the Bitcoin side, voices including researcher Eli Ben-Sasson and analyst Bit Paine called for accelerated work on quantum-resistant proposals like BIP 360, while others — including Binance co-founder CZ — urged calm, noting that upgrading to quantum-resistant algorithms is technically feasible. The harder problem, as Google noted, is coordination: decentralized networks can’t push software updates the way banks or military systems can, and dormant wallets with exposed keys cannot be upgraded at all.
