An open challenge to optimize one component of a quantum attack on Bitcoin and Ethereum has produced a circuit far cheaper than the best figure previously reported. A paper published on arXiv Thursday describes a point-addition circuit for secp256k1, the elliptic curve both networks use, that needs 1,151 logical qubits and about 1.30 million Toffoli gates.
The benchmark multiplies qubits by gates into a single spacetime score, where lower is better. Over roughly two months of submissions, that score fell 86%, from 10.75 billion to about 1.496 billion, which is more than 50% below the result Google Quantum AI reported in March. One of the paper’s authors Theta technology chief Jieyi Long, however, cautioned against wholly taking the result of the challenge as superior to Google’s findings, citing differences in interfaces and accounting conventions.
This story is an excerpt from the Unchained Daily newsletter.
Subscribe here to get these updates in your email for free
Point addition is repeated many times inside Shor’s algorithm, which a fault-tolerant quantum computer could use to recover a private key from a public key already exposed onchain. Cheaper circuits do not build that machine, and the authors stress this is not an attack, but they shrink the margin holders are working with: Coinbase‘s quantum advisory board estimated in June that roughly 7 million BTC sit in addresses with visible public keys.
“The quantum threat no longer depends only on hardware challenges alone,” StarkWare CEO Eli Ben-Sasson, whose team took part, said on X. “Al agents are narrowing the gap to a quantum attack. This project proves it.”
Google’s March paper disclosed resource thresholds and a zero-knowledge proof that a qualifying circuit existed without publishing the circuit, but it did release a verifier. Eigen Labs turned that verifier into a public leaderboard on May 30, and IEEE Spectrum later reported that the crowd matched Google’s displayed result within eight hours and beat its score in about 72 hours. Submissions kept coming after the paper’s July 26 cutoff, with one design reaching 952,707 Toffoli gates and another 813 logical qubits.
The Ethereum Foundation set December 2029 as its deadline for post-quantum security across execution, consensus and data layers, a target Google also used when it pulled the timeline forward in March. Long wrote on X that migration across blockchains, wallets, custody systems and smart contracts will take years, which is why the work starts before any machine exists to run the attack.
Related Listen: One Type of Post-Quantum Cryptography Is Most Popular. Why Is Crypto Trying Out Three?
