Cryptelio

Security

New Research Reveals Quantum Computing Threat to Bitcoin and Ethereum Security

Cryptelio Editorial Published 10 Sep 2026 · 13:32 UTC

A recent collaboration involving Google Quantum AI, the Ethereum Foundation, and Stanford University has published a whitepaper that presents alarming findings regarding the security of Bitcoin and Ethereum against quantum computing attacks. The study reveals that fewer than 500,000 physical superconducting qubits would be required to break the elliptic curve cryptography that protects these cryptocurrencies, a substantial reduction from previous estimates of approximately 9 million qubits.

The research, dated March 30, 2026, focuses on solving the 256-bit elliptic curve discrete logarithm problem (ECDLP-256), which is crucial for maintaining the privacy of private keys. By employing Shor’s algorithm on the secp256k1 curve, the specific elliptic curve used by both Bitcoin and Ethereum, the researchers outlined two optimized circuit variants. One variant operates with a maximum of 1,200 logical qubits and 90 million Toffoli gates, while the other utilizes 1,450 logical qubits and 70 million Toffoli gates, with execution times ranging from 9 to 23 minutes.

Importantly, the study identifies two primary attack vectors. The first, termed an “on-spend” attack, could allow a powerful quantum computer to intercept and derive a private key from a public key during Bitcoin’s average 10-minute block confirmation window, with an estimated 41% success probability under certain conditions. The second, an “at-rest” attack, targets wallets with publicly visible keys, with approximately 6.9 million BTC and 20.5 million ETH at risk due to exposure.

Despite the concerning implications, experts like Dan Boneh, a Stanford cryptographer and co-author of the paper, advocate for a measured response rather than panic. He emphasizes the importance of transitioning to post-quantum signature schemes as a proactive measure. Currently, no existing quantum computer has the capability to reach the threshold of 500,000 physical qubits, with Google’s most advanced quantum processor operating at just 105 qubits.

For cryptocurrency holders, the key takeaway is to avoid reusing addresses and to use fresh addresses for transactions to mitigate risks associated with at-rest attacks. The findings underscore the necessity for the cryptocurrency community to prepare for potential quantum threats.

FAQ

What is the main finding of the recent research on quantum computing and cryptocurrency security?

The research indicates that fewer than 500,000 physical superconducting qubits could potentially break the elliptic curve cryptography that secures Bitcoin and Ethereum, a significant reduction from previous estimates of around 9 million qubits.

What are the two primary attack vectors identified in the study?

The two primary attack vectors are the 'on-spend' attack, which can intercept and derive a private key during Bitcoin's block confirmation window, and the 'at-rest' attack, which targets wallets with publicly visible keys.

What is the recommended action for cryptocurrency holders in light of these findings?

Cryptocurrency holders are advised to avoid reusing addresses and to use fresh addresses for transactions to mitigate risks associated with at-rest attacks.

How many logical qubits and Toffoli gates are required for the optimized circuit variants proposed in the study?

One variant requires a maximum of 1,200 logical qubits and 90 million Toffoli gates, while the other utilizes 1,450 logical qubits and 70 million Toffoli gates.

What is the current capability of quantum computers compared to the threshold needed to break cryptocurrency security?

Currently, no existing quantum computer has the capability to reach the threshold of 500,000 physical qubits, with Google's most advanced quantum processor operating at just 105 qubits.

Read story →