Build with CoinStats’ all-in-one API. Learn more

Deutsch한국어日本語中文EspañolFrançaisՀայերենNederlandsРусскийItalianoPortuguêsTürkçePortfolio TrackerCryptocurrenciesPricingCrypto APIIntegrationsNewsEarnBlogNFTWidgetsDeFi Portfolio TrackerDerivativesETF FlowsCrypto Gaming24h ReportPress KitAPI Docs
CoinStats

Quantum Attack Estimates for Bitcoin Are Cut in Half After a New Shor Algorithm Benchmark

44m ago
bullish:

0

bearish:

0

The open ECDSA.Fail project published its preprint on September 9. It describes a smaller logical-circuit benchmark for a secp256k1 operation used in Shor’s algorithm, which is relevant to Bitcoin and Ethereum signatures.

At the July 26 cutoff, the best submission used 1,151 logical qubits and 1,299,453 average executed Toffoli gates. Its Q×T score was about 1.496 billion.

That score was more than 50% below Google Quantum AI’s published benchmark, according to the ECDSA.Fail preprint; the accounting conventions differed.

The result measures an improvement in the circuit itself. It does not provide a new estimate of the hardware required for a complete attack on Bitcoin.

ECDSA.Fail cuts the secp256k1 circuit benchmark

The project focused on point-addition circuits for secp256k1, the elliptic curve used by Bitcoin and Ethereum signatures. Point addition is a component of the computation required when applying Shor’s algorithm to the underlying elliptic-curve cryptography.

Its reported best circuit combined 1,151 logical qubits with 1,299,453 average executed Toffoli gates. Multiplying the project’s qubit and gate measures produced the roughly 1.496 billion Q×T score, a compact benchmark intended to track the circuit-resource trade-off.

Logical qubits are an abstraction used in quantum computing resource estimates; they are not the same as physical qubits in a machine. The distinction matters here because converting a logical design into a fault-tolerant physical implementation requires error correction, a cost not included in the new benchmark.

More than 100 contributors drove an 86.1% decline

The public ECDSA.Fail challenge ran for roughly two months and involved more than 100 participants and AI agents, according to an Eigen Labs account of the effort.

Its Q×T benchmark fell from 10.75 billion by 86.1%. The work used an open, collaborative process to optimize a cryptographic circuit relevant to long-term quantum risk to digital-asset signatures.

That result concerns the project’s own benchmark and baseline, not a matching percentage reduction in the resources required for an operational quantum attack. It is also an optimized component of a full quantum-attack circuit, rather than an end-to-end cryptanalytic system.

Official ECDSA.Fail research visual accompanying the benchmark announcement. — Source: Eigen Labs

Google’s estimate used tens of millions of Toffoli gates

Google Quantum AI’s March 2026 secp256k1 estimates were about 1,200 logical qubits and 90 million Toffoli gates, or 1,450 logical qubits and 70 million Toffoli gates, with fewer than 500,000 physical qubits under its stated superconducting-hardware assumptions. The figures come from Google’s resource-estimate paper.

ECDSA.Fail’s 1.299 million average executed Toffoli gates can look far lower, but its headline Q×T score combines logical qubits and executed Toffoli gates for the point-addition circuit. Google reported alternative resource estimates with explicit physical-qubit assumptions, so the two results differ in accounting and measurement scope and are not formally interchangeable. A lower Q×T score is consequently not a direct replacement for Google’s full set of figures.

One Shor-attack component, not a complete Bitcoin attack

From the challenge’s original 10.75 billion Q×T, the logical-circuit benchmark for secp256k1 point addition fell to approximately 1.496 billion.

That is a result for one major component of a prospective fault-tolerant Shor attack, not for a complete attack implementation. The ECDSA.Fail preprint does not include the physical error-correction costs needed to determine the number of real qubits a machine would require.

The comparison also has a defined limit: CoinDesk reported that the researchers acknowledge their benchmark and Google’s result are not formally like-for-like. Any effect on practical risk timelines would still depend on the unmeasured full-attack work and fault-tolerant hardware capable of running it.

Disclaimer: This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

44m ago
bullish:

0

bearish:

0

Manage all your crypto, NFT and DeFi from one place

Securely connect the portfolio you’re using to start.