AI Agents Slash Quantum Attack Cost on Bitcoin by 86%
- An open research initiative called ECDSA.Fail has reduced the estimated quantum resources needed to attack BitcoinBTC-- and EthereumETH-- encryption by 86.1%.
- The project combined AI agents with human scientists to optimize the elliptic-curve point addition step in Shor’s algorithm.
- Ethereum has established a strict 2029 deadline to achieve full quantum resistance across its base layer.
- New Bitcoin Improvement Proposals focus on hiding public keys to prevent reverse-engineering by future quantum computers.
- Researchers caution that these metrics represent theoretical circuit optimizations rather than immediate physical threats.
An open research project named ECDSA.Fail has significantly reduced the estimated quantum computing resources required for a key step in attacking blockchain encryption. By combining human scientists with AI agents, more than 100 contributors improved a quantum circuit for elliptic-curve point addition, a core arithmetic operation in Shor’s algorithm used against elliptic-curve cryptography. The project reduced its principal resource cost measure by 86.1% from its baseline, reaching a best circuit using 1,151 logical qubits and approximately 1.3 million Toffoli gates. This result is roughly 50% below a benchmark reported by Google, though direct comparison is limited by different accounting methods.
The study focused on secp256k1, the elliptic curve used by Bitcoin, Ethereum, and related systems. While the work does not demonstrate a working attack or imply immediate danger, it provides critical data for planning cryptographic migration. Lead author Jieyi Long noted that the results help quantify the remaining gap between current quantum hardware capabilities and the resources needed to break deployed cryptography. With roughly a third of all Bitcoin in addresses where public keys are visible, the findings underscore the need for proactive transition to post-quantum cryptographic systems, a process that may take years.
How Did AI Agents Optimize the Quantum Circuit?
ECDSA.Fail also served as a testbed for "open autoresearch," where AI agents and humans collaboratively optimized circuits against a shared, machine-checkable objective. Over eight weeks, participants produced over 400 submissions, with AI agents proving particularly effective for implementing incremental changes and testing. The challenge, launched in early June 2026, focused on optimizing a reversible quantum circuit for secp256k1 elliptic curve point addition. Participants matched Google's initial results within eight hours of the launch and surpassed them within 72 hours.

Researchers from the Ethereum Foundation, Theta Labs, StarkWare, and other organizations published findings showing that the estimated work required for a key step in a future quantum attack on Bitcoin and Ethereum has fallen by more than half compared to a benchmark set by Google in March. The new circuit scored approximately 1.96 billion when adapted more closely to actual Shor's algorithm usage, still below Google's figures. The improvements were achieved through ECDSA.Fail, an open challenge by Eigen Labs, involving over 100 participants and AI coding agents over eight weeks.
While the optimization reduces the machine size and workload needed for the attack, the researchers noted that the circuit does not cover the entire attack process, omitting physical error correction and hardware-specific costs. Consequently, no existing quantum computer can currently break Bitcoin or Ethereum using these results. The benchmark excludes physical error correction, hardware compilation costs, and end-to-end validation, meaning logical qubit estimates cannot be directly translated to physical qubit requirements for real-world machines.
What Is the Industry Response to Quantum Threats?
The Ethereum Foundation’s Protocol Cluster has committed to making Ethereum a quantum-resistant Layer 1 by December 2029. This target was published alongside the group’s first unified tier list for the Hegota upgrade, covering 62 proposals. The deadline applies to execution, consensus, and data layers, meaning the entire base layer must be secured, not just isolated components. Nine internal teams assessed 397 submissions, rejecting 28 outright.
The Protocol Cluster described the date as self-imposed, acknowledging that while no current machine can break elliptic curve cryptography, the risk is non-zero. The target remains non-negotiable until at least January 2027, when outside specialists will reassess the pace of quantum computing progress. Fredrik Svantes, leading protocol coordination, stated the cluster is "aggressively targeting" a quantum-resistant Layer 1 no later than December 2029.
This timeline influences engineering recommendations for Hegota, the fork expected to follow the Glamsterdam release in late 2026. Two must-ship proposals for Hegota have been identified, including one that makes account abstraction native to the protocol, laying groundwork for post-quantum authentication. Planning documents now instruct developers to assume a cryptographic breakthrough could occur as early as 2030, aligning with migration targets set by Google, Cloudflare, and Microsoft.
While quantum computers theoretically threaten Bitcoin's security by using Shor's Algorithm to reverse-engineer private keys from public keys, recent developments suggest this risk may be overblown. Bitcoin's security relies on the difficulty of deriving private keys from public keys, a process quantum computers could accelerate. However, data scientists have developed new mathematical locks through Bitcoin Improvement Proposals (BIPs) designed to resist quantum attacks.
The primary defense is BIP-360, a proposal to hide public keys from quantum computers, preventing reverse-engineering. These quantum-proof locks require more computing power than current Bitcoin mechanisms. To maintain network efficiency, developers plan to use zero-knowledge proofs to compress hundreds of quantum signatures into single packages, preventing blockchain congestion.
Crucially, the migration strategy includes a grace period of up to five years, allowing users to move Bitcoin to new BIP-360 addresses before older addresses are frozen. This timeline is designed to ensure that by the time quantum systems are capable of cracking current encryption, most public keys will either be hidden or frozen. Current top-tier quantum systems remain too small and unstable to run Shor's Algorithm at the necessary scale.
Vitalik Buterin previously warned at a Buenos Aires conference that elliptic curve cryptography could fall before the 2028 U.S. presidential election, urging a four-year transition window. He estimates a 20% probability of a cryptography-breaking machine arriving before 2030, based on Metaculus forecasts. This urgency has reordered developer priorities, placing post-quantum readiness among five key research tracks alongside fast finality, privacy, state, and zkEVM. Investors should not assume quantum computing will immediately render Bitcoin obsolete, as the ecosystem has a structured path to upgrade its cryptographic defenses.
Blending traditional trading wisdom with cutting-edge cryptocurrency insights.
Latest Articles
Stay ahead of the market.
Get curated U.S. market news, insights and key dates delivered to your inbox.



Comments
No comments yet