Highlights
- A new paper estimates the key computational step in a future quantum attack on Bitcoin and Ethereum needs 1,151 logical qubits and 1.3 million Toffoli gates.
- That gives a combined resource score of about 1.5 billion, less than half Google's March benchmark of roughly 3 billion.
- Researchers from the Ethereum Foundation, StarkWare, Theta Labs and more than 100 contributors worked on the optimization.
- The improvement targets the point-addition step repeated inside Shor's algorithm, the method theoretically capable of deriving private keys from public ones.
- Authors stress the circuits are not an actual attack and omit the physical error correction needed for a real-world break.
A new research paper released this week shows the estimated computational cost of a critical step in a future quantum attack on Bitcoin and Ethereum has fallen by more than half compared with a benchmark Google published in March. The collaborative effort, involving researchers from the Ethereum Foundation, StarkWare, Theta Labs and more than 100 other contributors across academia and crypto projects, redesigned the quantum circuit used to model the point-addition operation that repeats throughout Shor's algorithm, the method that could theoretically let a sufficiently powerful quantum computer derive a private key from a public one and forge transactions.
A Sharper Quantum Circuit
According to reporting from The Block, the new circuit requires roughly 1,151 logical qubits and 1.3 million Toffoli gates, a combined resource score of about 1.5 billion, down from Google's earlier estimate of roughly 3 billion.
The paper was authored by Theta Labs chief technology officer Jieyi Long alongside researchers from Eigen Labs, Starknet Foundation, Brevis, Sei Labs and Trail of Bits, reflecting an unusually broad coalition spanning both established layer-1 protocols and newer scaling projects. The authors were explicit that the work is not itself an attack: the circuits do not account for physical error correction, a step that remains a major bottleneck for real-world quantum hardware, and the paper does not represent a full implementation of Shor's algorithm. Even so, halving a key resource estimate in six months illustrates how quickly the theoretical cost of breaking elliptic-curve cryptography is falling as researchers refine the underlying circuit designs, independent of whether the physical hardware needed to run them yet exists.
Related: Justin Sun: 50% Chance Quantum Computers Break Crypto by 2028
Why the Optimization Matters Now
The research adds urgency to an already active push across the crypto industry to prepare for a post-quantum future, even though most experts agree a cryptographically relevant quantum computer capable of running the full algorithm remains years away. Both Ethereum and Bitcoin developer communities have set internal deadlines for migrating away from the elliptic-curve signatures that a sufficiently advanced quantum computer could eventually break, and government-backed grants have started flowing toward quantum-safe cryptography research as a result. The gap between theoretical resource estimates and a working quantum computer is still enormous. Today's largest quantum processors operate with a few hundred physical qubits at most, and error-correction overhead means each logical qubit in a fault-tolerant circuit could require dozens or hundreds of physical qubits to implement reliably. StarkWare, one of the paper's contributing teams, has already executed what it called Bitcoin's first quantum-safe transaction on mainnet, a practical step that runs in parallel with this kind of theoretical resource modeling and shows the migration work is not purely academic.
What's Next for Post-Quantum Crypto
The next milestone to watch is whether the broader research consortium publishes a full end-to-end resource estimate that accounts for error correction, which would give a far more concrete timeline for when a cryptographically relevant attack becomes plausible rather than purely theoretical. In the meantime, expect continued incremental improvements to circuit designs from competing research groups, each shaving further off the qubit and gate counts required, alongside more real-world tests similar to the quantum-safe transaction StarkWare has already run. Most cryptographers caution against treating any single estimate as a countdown clock given how early-stage the underlying hardware still is, but the direction of travel, steadily falling resource requirements, is exactly what has pushed wallet providers and protocol teams to accelerate their own migration planning this year.
FAQ
What does the new quantum research paper show?
It shows the estimated computational cost of a key step in a future quantum attack on Bitcoin and Ethereum has fallen by more than half compared with Google's March 2026 benchmark, to a combined resource score of about 1.5 billion.
Who authored the research?
Researchers from the Ethereum Foundation, StarkWare, Theta Labs, Eigen Labs, Starknet Foundation, Brevis, Sei Labs, Trail of Bits and more than 100 other contributors.
Does this mean quantum computers can break Bitcoin now?
No. The authors stress the circuits omit physical error correction and are not a full implementation of Shor's algorithm, and today's quantum computers remain far short of what would be needed for a real attack.
What is the crypto industry doing to prepare?
Ethereum and Bitcoin developer communities have set internal migration deadlines away from elliptic-curve signatures, and projects like StarkWare have already tested quantum-safe transaction methods on mainnet.
