Researchers Reduce Quantum Resource Estimates for Attacking Bitcoin and Ethereum
A research collaboration involving Google Quantum AI, the Ethereum Foundation, and Stanford has identified that fewer than 500,000 physical qubits are required to compromise elliptic curve cryptography, a 20-fold reduction from previous estimates.

A whitepaper published by researchers from Google Quantum AI, the Ethereum Foundation, and Stanford details optimized quantum circuits capable of breaking the elliptic curve cryptography used by Bitcoin and Ethereum. The study, dated March 30, 2026, concludes that fewer than 500,000 physical superconducting qubits are necessary to solve the ECDLP-256 problem, a significant decrease from earlier benchmarks of approximately 9 million.
The research utilizes Shor’s algorithm to target the secp256k1 curve. Two circuit variants were presented: one requiring 1,200 logical qubits and 90 million Toffoli gates, and another using 1,450 logical qubits and 70 million Toffoli gates. Depending on the variant, execution time is estimated between 9 and 23 minutes on a standard superconducting surface-code architecture.
The paper outlines two primary attack vectors. An on-spend attack targets transactions during the broadcast window, with researchers estimating a 41% success probability under certain conditions. An at-rest attack targets wallets with exposed public keys. The researchers estimate that 6.9 million BTC and 20.5 million ETH are currently exposed, alongside smart contract administrative keys governing approximately $200B in assets.
A separate study by researchers from Caltech and Oratomic suggests that neutral-atom architectures could potentially require between 10,000 and 26,000 physical qubits, though these systems would require days to complete the computation.
Stanford cryptographer and co-author Dan Boneh recommends a measured transition to post-quantum signature schemes. Currently, no existing quantum computer reaches the 500,000 physical qubit threshold, with Google’s Willow processor operating at 105 qubits. The researchers utilized zero-knowledge proofs to verify their findings without publishing the specific circuit designs.
For asset holders, the researchers note that wallets which have not broadcast a transaction and thus have not exposed a public key remain secure. The primary recommendation for users is to avoid address reuse and utilize fresh addresses for every transaction.
Stay ahead
Join our Telegram Channel
Free real-time crypto news and price alerts, the moment they break.
- Breaking News
- Price Alerts
- Market Insights



