More than 100 participants using AI coding agents reduced the challenge’s resource score from 10.75 billion to 1.496 billion.
The best circuit required 1,151 logical qubits and approximately 1.3 million Toffoli gates, although it cannot be directly compared with Google’s earlier benchmark.
A subsequent design reduced the gate count to fewer than one million, but the estimates do not include the hardware overhead required for a full-scale attack.
Researchers using AI coding agents have cut the resource estimate for a critical stage of a hypothetical quantum attack on the cryptography securing Bitcoin and Ethereum by 86%, according to a paper published Wednesday.
The optimization lowered the estimated quantum resources needed to recover a wallet’s private key from its public address, an outcome that could enable an attacker to steal its funds. It remains unclear when quantum computers will become powerful enough to mount such an attack, a milestone often referred to as “Q-Day.”
The researchers said the transition away from quantum-vulnerable cryptography is already underway despite the uncertain timeline. NIST has standardized post-quantum alternatives, while the initial public draft of NIST IR 8547 proposes phasing out classical public-key algorithms offering 112 bits of security after 2030 and prohibiting their use after 2035.
The results came from ECDSA.Fail, an open competition launched by Eigen Labs in late May. More than 100 participants developed quantum circuits for secp256k1, the elliptic curve used to secure transaction signatures on Bitcoin and Ethereum. The paper’s authors have affiliations with Theta Labs, MultiVM Labs, Eigen Labs, Trail of Bits, StarkWare, and the Ethereum Foundation.
The team designed and validated a quantum circuit that performs the calculation required to recover a secp256k1 private key, reducing its resource score by 86%. The tests confirmed the circuit’s calculations but did not crack an actual Bitcoin private key.
The challenge scored each circuit by multiplying its logical qubit count by its number of Toffoli gates, a resource-intensive quantum operation introduced by Tommaso Toffoli in 1980. A lower score indicates that the calculation requires fewer combined resources and could therefore be easier to execute on a sufficiently advanced quantum computer.
By July 26, contestants had lowered the score by 86%, from 10.75 billion to 1.496 billion. The leading circuit used 1,151 logical qubits and approximately 1.3 million Toffoli gates. The study estimated that this was roughly half of Google Quantum AI’s March benchmark, but differences in testing and accounting methods make the figures unsuitable for direct comparison.
The paper presents ECDSA.Fail not only as a source of improved circuits but also as a case study in “Open Autoresearch”—a verification-gated process in which researchers and AI agents repeatedly generate, implement, test, and share improvements against a shared quantitative objective.
The report reflects a broader push by cryptocurrency companies to fund research into defenses against quantum attacks.
In July, Galaxy Digital pledged up to $5 million for this work. Nine other companies, including BlackRock, Coinbase, and Strategy, committed a combined $15 million over three years to broader Bitcoin security research, including quantum-resistant measures.