# Quantum Computing Threat to Bitcoin, Ethereum Reduced 20-Fold

**Published:** 2026-09-11T08:18:25.467Z  
**Topic:** Ethereum  
**Sentiment:** neutral  
**Publisher:** TrendWatcher — https://www.trendwatcher.in/article/b38b758e-6af1-4233-9852-d8aa0af48af9

Researchers cut estimated physical qubits needed to crack Bitcoin and Ethereum encryption by 20x to under 500,000, accelerating quantum threat timelines.

A Google-led research team has reduced the estimated physical qubits required to break the elliptic curve cryptography underpinning Bitcoin and Ethereum by approximately 20 times, from 9 million to fewer than 500,000 [1]. This significant reduction in hardware requirements brings the timeline for potential quantum attacks closer than previously expected, impacting the security of millions of BTC and ETH.

| At a glance | |
|---|---|
| Quantum Qubit Estimate | Under 500,000 physical qubits [1] |
| Previous Estimate | 9 million physical qubits [1] |
| Reduction | 20-fold [1] |
| Attack Runtime | 9 to 23 minutes [1] |

## Optimized Quantum Circuits and Attack Vectors

The paper, dated March 30, 2026, details optimized quantum circuits designed to solve the 256-bit elliptic curve discrete logarithm problem (ECDLP-256), which secures private keys for Bitcoin and Ethereum [1]. The researchers used Shor’s algorithm targeting the secp256k1 curve, common to both blockchains [1]. Two circuit variants were presented, requiring either 1,200 logical qubits and 90 million Toffoli gates, or 1,450 logical qubits and 70 million Toffoli gates [1]. These circuits could execute in 9 to 23 minutes on a standard superconducting surface-code architecture [1].

This new benchmark is less than half of Google's prior estimates, though accounting methods differ [1]. Separately, Caltech and Oratomic researchers have explored neutral-atom architectures, claiming physical qubit requirements as low as 10,000 to 26,000 for similar computations, but with runtimes measured in days rather than minutes [1]. Another research effort, involving over 100 contributors from organizations including the Ethereum Foundation and StarkWare, also reduced the estimated computing resources needed for a key arithmetic step in Shor's algorithm [3]. This team's quantum circuit requires 1,151 logical qubits and approximately 1.3 million Toffoli gates, a combined score roughly 50% below Google Quantum AI's March benchmark, though direct comparison is not perfectly aligned due to differing accounting methods [3].

The paper identifies two primary attack vectors:
*   **On-spend attacks:** These target transactions during the average 10-minute Bitcoin block confirmation window, aiming to derive a private key from a revealed public key before confirmation [1]. Researchers estimate a 41% success probability under specific conditions [1].
*   **At-rest attacks:** These target wallets with public keys already visible on the blockchain [1]. Approximately 6.9 million BTC and 20.5 million ETH are estimated to be vulnerable [1]. This includes about 1.7 million BTC from legacy Satoshi-era P2PK outputs, which broadcast the full public key [1]. Additionally, administrative keys controlling smart contracts for stablecoins and other tokenized assets, valued at around $200 billion, face similar exposure [1].

## Current Capabilities and Mitigation

No existing quantum computer approaches the 500,000 physical qubit threshold identified in the research; Google's most advanced publicly known processor, Willow, has 105 qubits [1]. The researchers practiced responsible disclosure, verifying their claims with zero-knowledge proofs without publishing circuit designs [1].

Stanford cryptographer Dan Boneh, a co-author, advocates for a measured migration to post-quantum signature schemes [1]. For asset holders, wallets that have never broadcast a transaction and thus not exposed their public key remain safe from at-rest attacks [1]. Using fresh addresses for every transaction and avoiding address reuse is a defensive measure [1]. The vulnerable 6.9 million BTC and 20.5 million ETH are largely in older wallets or those using outdated address formats [1].

## What to watch

*   **Quantum hardware development:** Monitor progress in physical qubit counts and error correction rates in quantum computers, particularly those from Google Quantum AI and other leading research groups.
*   **Post-quantum cryptography standards:** Observe the development and adoption of new cryptographic standards designed to resist quantum attacks within the Bitcoin and Ethereum ecosystems.
*   **Blockchain migration efforts:** Track any initiatives by Bitcoin and Ethereum developers to implement post-quantum signature schemes or encourage users to migrate funds from older, exposed address formats.

The research highlights a significant theoretical advancement in quantum attack capabilities, narrowing the gap between current quantum technology and a potential threat to widely used cryptocurrencies, underscoring the need for continued vigilance and preparation within the crypto community.

## Sources
1. Crypto Briefing — [Researchers cut quantum resource benchmark 20-fold for Bitcoin and Ethereum attack](https://cryptobriefing.com/quantum-attack-bitcoin-ethereum-benchmark/)
2. Phys — [Proven quantum advantage: Researchers cut the time for a learning...](https://phys.org/news/2025-09-proven-quantum-advantage-task-million.html)
3. Northeast Times — [Quantum Computing Researchers Cut Estimated Cost of Attacking Bitcoin and Ethereum Encryption in Half](https://northeasttimes.com/2026/09/10/quantum-computing-researchers-cut-estimated-cost-of-attacking-bitcoin/)

---
Cite as: TrendWatcher, "Quantum Computing Threat to Bitcoin, Ethereum Reduced 20-Fold", https://www.trendwatcher.in/article/b38b758e-6af1-4233-9852-d8aa0af48af9
