Researchers Halve Quantum Threat Estimate for Bitcoin and Ethereum
Security

Researchers Halve Quantum Threat Estimate for Bitcoin and Ethereum

September 10, 20264 min read

New research has cut the quantum threat estimate for crypto in half. A team of scientists rechecked Google's numbers. The focus is Bitcoin and Ethereum security.

This is not a working attack. It is an updated resource estimate for one key step of Shor's algorithm.

What the researchers actually calculated

A paper shared with CoinDesk shows a team of scientists and AI agents recalculated how many computing resources one core operation inside Shor's algorithm requires. That algorithm could, in theory, break the elliptic-curve cryptography protecting private keys on Bitcoin and Ethereum.

In simple terms, here is how it works. A wallet's private key is mathematically linked to its public address through an operation that would take a classical computer billions of years to reverse. Shor's algorithm can, in theory, find that reverse path far faster, but only on quantum hardware of the right scale. The new paper recalculated exactly how much of that hardware would be needed. The work involved human researchers working alongside AI agents that helped optimize the underlying math. It is the second time this year that AI has sped up cryptographic research itself, rather than simply writing code around it.

The new figure came in at less than half of what Google's team published back in spring 2026. The Block notes the two papers use slightly different accounting methods, so a direct comparison is not perfect. Still, the direction is clear. The estimated cost of a future quantum attack keeps dropping year after year.

The topic has been on cryptographers' radar for a while. The US institute NIST finalized its first post-quantum encryption and signature standards back in 2024 for everyday internet traffic and banking. The open question is when similar schemes will reach wallets and blockchain protocols, since an upgrade there means getting thousands of network participants to agree, unlike one company simply shipping a patch.

Why this is not a reason to panic

No quantum computer capable of actually running this attack at the required scale exists yet. Even with the new, smaller benchmark, today's most powerful machines remain far below what would be needed, and we are talking decades of engineering work, not years. Running Shor's algorithm in practice needs stable, error-corrected "logical" qubits rather than raw ones, and each logical qubit currently costs hundreds of physical qubits.

Each paper like this nudges the so-called "quantum clock", the informal countdown researchers use to track how close quantum computing has gotten to threatening Bitcoin. Google's March estimate was itself a sharp cut from 2025 projections. Now it has been halved again, and this is unlikely to be the last such revision.

A similar pattern has played out with classical factoring records for years. Each year the records improve a bit, while the threat stays theoretical. Researchers publish this kind of work early on purpose, so protocols have time to prepare instead of patching a hole after the fact.

Who this already affects today

Discussion inside the Ethereum community had picked up even before this paper landed. Developers, including Vitalik Buterin, have recently pushed plans to move the network toward quantum-resistant cryptography and are looking for ways to make that shift cheaper. The catch is that quantum-resistant signatures usually weigh more than regular ones. Some schemes make signatures dozens of times larger, which raises the cost of every transaction on the network.

That gives the push for faster upgrades a bit more weight now. In theory, the most exposed wallets are the ones whose public address has already "revealed" its public key on-chain, for example after spending from an old Bitcoin address. That mostly applies to coins from the network's earliest years, sitting untouched for years on addresses with an exposed public key.

Owners who keep coins on hardware wallets such as Ledger will not notice any practical difference. The attack remains a lab calculation, not a working tool, and no wallet needs an urgent firmware update because of this paper.

What Bitcoin and Ethereum holders can do right now

There are not many concrete steps, and none of them are urgent. Still, basic hygiene is worth keeping in mind today rather than waiting for news of the first working quantum computer.

  • Avoid reusing the same Bitcoin address to receive funds, so the public key stays hidden longer.
  • Watch for wallet and protocol announcements about support for new, quantum-resistant signatures.
  • Do not move all your savings onto one old address without reason, especially if it has already been exposed on-chain.
  • Do not decide to sell assets just because of quantum research headlines, since there is no real threat to the networks yet.

What comes next

Updates like this are showing up more often, and this is unlikely to be the last one this year. The next benchmark could land within months, or sooner if another major lab or university team joins the race. The community will debate it under the same rule: fewer qubits on paper does not mean a working quantum computer in a lab.

For now, both Bitcoin and Ethereum are treating this as a multi-year engineering problem, not a fire to put out today. For the average crypto holder, the takeaway is practical. It is worth checking in on quantum-resistant wallet updates every few months, but there is no reason to make a rushed decision today over a single research paper.

Comments

Your email address will not be published. Required fields are marked *

or verify by email