Quantum Attack Estimate for Bitcoin and Ethereum Falls by 86%

The estimated cost of a quantum attack on the cryptography under Bitcoin and Ethereum fell sharply on Thursday, on paper. A technical paper published that morning describes an optimized quantum circuit for elliptic-curve point addition on secp256k1, the curve both networks use to sign transactions. The winning design needs 1,151 logical qubits and 1,299,453 Toffoli gates, down from 2,715 qubits and 3,960,753 gates at the start of the exercise. On the challenge's own score that is a cut of 86%. The authors say it is not an attack.
Where the arithmetic stops agreeing
The component counts are identical in every account. The score is not. The challenge multiplies logical qubits by Toffoli gates, which puts the winning entry at about 1.496 billion. The Block gives the starting point as 10.75 billion, and that is what the component counts produce. The Quantum Insider, writing up the same paper, describes the baseline as roughly 2.7 billion while also stating the reduction as 86.1%. Both cannot be right, and the outlet does not reconcile them. We could not establish which figure the paper itself prints.
Measured against Google, with an asterisk
Every account frames the result against a Google benchmark from earlier in 2026, and every account hedges it. The Block puts the new score at less than half Google's estimate. The Quantum Insider says more than 50% below, then cautions that the two circuits use different interfaces and accounting methods, so the comparison is context, not a verdict. CryptoBriefing is alone in printing a number for Google's work, roughly 3 billion Toffoli gates in March, and it gives that in gates while the challenge scores a product of gates and qubits. Those are not the same measure.
"If the estimate of what it costs to break this cryptography is being cut in half, as it is in this paper, then every timeline anyone has quoted you for Q-Day needs to be cut too," StarkWare co-founder Eli Ben-Sasson said, in remarks The Block carried.
What the paper does not claim
Point addition is one arithmetic step inside Shor's algorithm, the procedure that would break elliptic-curve signatures on a large enough quantum machine. The circuits leave out physical error correction and hardware compilation, and no end-to-end attack was run. Correctness was checked on 9,024 test cases and not proved for all inputs.
Lead author Jieyi Long, chief technology officer of Theta Labs, worked with researchers from the Ethereum Foundation, Eigen Labs, StarkWare, the Starknet Foundation, Brevis, Sei Labs and Trail of Bits. Eigen Labs ran the challenge, called ECDSA.Fail, opening it in late May; CryptoBriefing dates the start to June instead. More than 100 contributors filed over 400 submissions across about eight weeks, some using AI agents. Nobody compared human-only work against AI-assisted work.
The defence moved in the same week
A day before the paper, Vitalik Buterin promoted EIP-8288, a proposal to cut what quantum-safe transactions cost on Ethereum. A transaction would carry a 96-byte frame declaring a post-quantum signature or proof claim as a dependency, and mempool nodes would gather the claims into one recursive STARK proof per block. Decrypt puts a private transaction today at about 300,000 gas, a quantum-safe private transaction at about 10 million, and the same thing under EIP-8288 in the low tens of thousands. Those gas figures appear in that outlet alone.
Buterin wants it in I-star, the upgrade after Hegota, and conceded that adopting it would make RISC-V Ethereum's canonical instruction set in practice, which he called a big decision. Neither EIP-8288 nor Frames, the proposal it depends on, has been assigned to a fork. Ethereum is already redrafting its deposit contract for larger keys and targets full post-quantum security across execution, consensus and data layers by December 2029. StarkWare said late last month that a quantum-safe Bitcoin transaction had been mined on mainnet. Two objections raised when EIP-8288 first circulated in June are unanswered: whether nested proofs stay sound, and who is accountable when a block builder omits a transaction's proof. Q-Day still has no date. What moved this week is the arithmetic people were using to guess at one.
Read also: Ripple Sets Out a Four-Stage Path to a Quantum-Safe XRP Ledger