Google Quantum AI reported that breaking the secp256k1 elliptic-curve cryptography used by Bitcoin, Ethereum, and other cryptocurrencies may require far fewer quantum resources than previously estimated. In a new whitepaper co-authored with researchers from the Ethereum Foundation, Stanford, and UC Berkeley, the team said an attack could need fewer than 500,000 physical qubits rather than the millions often cited, with optimized circuits using roughly 1,200 to 1,450 high-quality logical qubits. Under idealized conditions, the research suggests a primed attacker could recover a private key in about nine minutes, making an on-spend attack against a Bitcoin transaction theoretically possible within the network’s typical 10-minute confirmation window.
The paper warns that Bitcoin’s 2021 Taproot upgrade may have increased long-term quantum exposure by making public keys visible on-chain by default, and estimates that about 6.9 million bitcoin are already held in wallets with exposed public keys. Google said it did not publish the attack circuits, instead releasing a zero-knowledge proof using SP1 zkVM and Groth16 so the results could be validated without providing weaponizable details, and said it notified the U.S. government before publication. While the researchers stressed that no cryptographically relevant quantum computer exists today, they argued that the engineering threshold for attacking ECC-based blockchain systems is materially lower than expected and called for migration toward post-quantum cryptography across cryptocurrency ecosystems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
By 2026-05-12, Ethereum was described as running a coordinated post-quantum initiative through pq.ethereum.org and ongoing interoperability devnets. The effort was presented as a more organized migration response than Bitcoin's fragmented governance around proposals such as BIP-360 and BIP-361.
On 2026-04-08, Blockstream CEO Adam Back said quantum computing is a real long-term theoretical risk to Bitcoin but not an immediate practical threat due to current hardware limits. He urged preparation rather than panic, including giving users a roughly decade-long path to migrate keys to quantum-resistant formats, and said research and experimentation are already underway at Blockstream and on the Liquid network.
On 2026-04-07, Grayscale published a research note urging faster work to make public blockchains quantum-resistant, arguing that Bitcoin’s main obstacle is decentralized governance and consensus rather than technical feasibility. The note highlighted debate over how to handle roughly 6.9 million BTC in wallets with exposed public keys, including whether such coins should be burned, left untouched, or rate-limited.
On 2026-04-04, CoinDesk reported that several Bitcoin quantum-resistance proposals were being advanced or discussed, including BIP 360, post-quantum signature approaches, Tadge Dryja's commit/reveal mempool protection concept, and Hunter Beast's Hourglass V2 for vulnerable legacy addresses. The report said none of these mitigations had been activated yet and noted Bitcoin's decentralized governance could slow deployment of any upgrade.
On 2026-03-31, Google Quantum AI and co-authors published a paper describing five ways a future quantum computer could attack Ethereum, including exposed wallet keys, DeFi and stablecoin admin keys, Layer 2 and bridge cryptography, validator signatures, and Data Availability Sampling ceremony risks. The paper estimated combined Ethereum exposure above $100 billion across major wallets, contracts, L2s, bridges, and staked ETH.
On 2026-03-31, researchers from Caltech and quantum startup Oratomic published a paper arguing that ECC-256 used by Bitcoin and Ethereum wallets could be broken with far fewer quantum resources than many prior estimates. The study said roughly 26,000 qubits could break ECC-256 in about 10 days, and that some wallet protections might be vulnerable with as few as 10,000 physical qubits on a neutral-atom architecture.
The research estimated that about 6.9 million bitcoin are held in wallets with exposed public keys, indicating a larger pool of potentially vulnerable funds than some earlier market estimates suggested. It also warned that real-time attacks on Bitcoin transactions could be plausible within the typical 10-minute confirmation window under ideal assumptions.
Alongside the paper, Google said it did not publish step-by-step attack details to reduce misuse risk. Instead, it released a zero-knowledge proof so others could validate the claims without disclosing weaponizable quantum attack circuits.
On March 31, 2026, Google Quantum AI published a whitepaper estimating that breaking secp256k1 cryptography used by Bitcoin and Ethereum may require fewer than 500,000 physical qubits, far below many prior estimates. The paper described optimized attack methods suggesting a private key could theoretically be recovered in about 9 minutes under idealized conditions.
Before releasing its findings, Google said it conducted responsible disclosure and engaged the U.S. government regarding the research and its implications for cryptocurrency security.
In March 2026, a paper by BTQ Technologies researcher Pierre-Luc Dallaire-Demers and colleagues concluded that using Grover’s algorithm for a quantum 51% attack on Bitcoin mining would require an impractical fleet of roughly 10^23 qubits and about 10^25 watts of power. The study argued that quantum threats to Bitcoin mining are far less realistic than wallet-focused cryptographic attacks.
Bitcoin's Taproot upgrade went live in 2021. Google later assessed that Taproot may have increased future quantum exposure by making public keys visible on-chain by default in more cases.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
21 references tracked. Mallory keeps watching after this page renders.
postquantum.com
Open sourcepostquantum.com
Open sourcepostquantum.com
Open sourcecoindesk.com
Open sourcecoindesk.com
Open sourcecoindesk.com
Open sourcecoindesk.com
Open sourcearxiv.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.