Newsroom
11 September, 2026 / News / AI / Tags: quantum, algorithm, keys, attack, researchers

A collaborative effort using AI agents and human experts has cut the estimated quantum computing cost of a core operation in Shor’s algorithm targeting the cryptography behind Bitcoin and Ethereum
A team of researchers has reduced the estimated resources required for a critical calculation in a potential future quantum attack on Bitcoin and Ethereum by more than half relative to a Google Quantum AI benchmark from March. The work centers on optimizing elliptic-curve point addition, a repeated operation inside Shor’s algorithm that could, on a sufficiently powerful quantum computer, derive private keys from exposed public keys on the secp256k1 curve used by both networks.
The optimized quantum circuit requires 1,151 logical qubits and approximately 1.3 million Toffoli gates. Its combined resource score stands at roughly 1.5 billion, more than 50 percent below the approximately 3 billion figure previously reported by Google. A second version of the circuit, adapted more closely to the way Shor’s algorithm would apply the calculation, scored about 1.96 billion, still below the earlier benchmark. Researchers noted that the comparison is not perfectly equivalent because of differences in interfaces and accounting methods.
The results emerged from ECDSA.Fail, an open challenge organized by Eigen Labs. More than 100 participants, working with AI coding agents over roughly eight weeks, generated more than 400 accepted submissions. The process began from a starting resource score of 10.75 billion and achieved an 86 percent reduction by the July data cutoff.
AI agents handled much of the implementation, repeated testing and incremental optimizations. Human researchers primarily selected research directions and introduced larger design changes. The paper does not attempt to quantify the exact contribution of each. Successful improvements became the baseline for subsequent work, creating an iterative, verifier-gated research process.
The circuit addresses only one major component of a potential attack. It excludes physical error correction, the complete Shor calculation and various hardware-specific costs of running the algorithm on a real quantum computer. No existing quantum machine can apply the result to break Bitcoin or Ethereum today.
Resource requirements have continued to fall after the July cutoff used for the headline figure. A later design reduced the score to approximately 1.26 billion. Another lowered the logical-qubit requirement to 813, though at the expense of substantially higher computational demands.
Both Bitcoin and Ethereum rely on the same elliptic-curve cryptography targeted by the research. A sufficiently powerful quantum computer running Shor’s algorithm could, in principle, recover private keys from exposed public keys and authorize fraudulent transactions. Public keys become visible during normal transaction processes, and large volumes of coins already sit behind revealed keys.
The findings arrive as national efforts to advance quantum hardware continue. The U.S. Commerce Department recently finalized CHIPS Act awards of up to $100 million each for Rigetti, D-Wave and Quantinuum, taking minority stakes in the companies to support development of larger fault-tolerant machines.
Industry participants have begun allocating resources toward quantum defenses. Separate commitments include multi-million-dollar research funding from firms seeking to prepare blockchain networks for post-quantum cryptography. Standards bodies have already published post-quantum algorithm replacements, with timelines proposed for phasing out classical public-key methods in the coming decade.
Network upgrades to quantum-resistant signatures would require extensive development, testing and coordination. Because such changes cannot be applied retroactively to existing exposed keys, the research adds pressure for early planning even though a practical attack remains distant.









