A collaborative research effort utilizing AI coding agents has reduced the estimated quantum computing resources needed for a key step in attacking Bitcoin and Ethereum cryptography by over 50%. Participating in the ECDSA.Fail challenge, researchers optimized point-addition calculations to lower the resource score to 1.496 billion, well below Google's March 2026 benchmark. While no existing quantum computer can execute the attack, the findings accelerate the urgency for post-quantum migration, as Ethereum targets base-layer quantum resistance by December 2029 and the U.S. government backs hardware scaling with $300 million in CHIPS Act awards.
Quantum circuit optimization challenge
- ▪The optimized quantum circuit developed during the ECDSA.Fail challenge requires 1,151 logical qubits and approximately 1.3 million Toffoli gates, resulting in a resource score of 1.496 billion
- ▪The resource score of 1.496 billion achieved by the researchers is more than 50% lower than the benchmark of approximately 3 billion reported by Google Quantum AI in March 2026
- ▪The ECDSA.Fail challenge, launched by Eigen Labs on May 30, 2026, involved over 100 researchers and AI coding agents collaborating to optimize secp256k1 point addition circuits
- ▪A paper published on September 9, 2026, describes a quantum circuit that reduces the resource score for a key point-addition calculation in a potential quantum attack on Bitcoin and Ethereum by 86.1%
- ▪Submissions to the ECDSA.Fail challenge after the July 26, 2026, paper cutoff further reduced the gate count below 1 million Toffoli gates and lowered the machine-size requirement to 813 logical qubits
Post-quantum cryptography migration timelines
- ▪The Coinbase Independent Advisory Board on Quantum Computing and Blockchain estimated that approximately 7 million BTC sit in addresses vulnerable to quantum attacks because their public keys are exposed onchain
- ▪Bitcoin developers are advancing Bitcoin Improvement Proposals BIP-360 and BIP-361 to introduce post-quantum output types and establish a phased migration away from ECDSA and Schnorr signatures
- ▪The Ethereum Foundation has set a self-imposed deadline of December 2029 to achieve full post-quantum security across its execution, consensus, and data layers
U.S. quantum computing hardware funding
- ▪The U.S. government is taking minority stakes in Rigetti, D-Wave, and Quantinuum as part of the CHIPS Act funding to scale hardware, manufacturing, and error-correction systems
- ▪The U.S. Commerce Department finalized CHIPS Act awards worth up to $100 million each for quantum-computing companies Rigetti, D-Wave, and Quantinuum in September 2026
Quantum attack resource requirements
- ▪An end-to-end estimate from IonQ indicates that a full attack on secp256k1 cryptography would require approximately 1,457 logical qubits, 39 million Toffoli gates, and 19,397 physical trapped-ion qubits
- ▪Calculations by Google researchers estimate that a complete secp256k1 attack requires either 1,200 logical qubits and 90 million Toffoli gates, or 1,450 logical qubits and 70 million Toffoli gates
Debatable claims
- ▪Bitcoin should restrict legacy signatures to enforce quantum security
- ▪Quantum migration cannot wait for a perfect final design
Story comments
Loading comments…