Key points
- More than 100 participants and AI agents reduced a secp256k1 point-addition resource score by 86.1% during the ECDSA.Fail challenge.
- The leading cutoff design used 1,151 logical qubits and about 1.30 million Toffoli gates, producing a score of roughly 1.496 billion.
- The result optimizes one component of a theoretical attack; it does not break Bitcoin or Ethereum, and no current quantum machine can run it.
A lower benchmark for one quantum attack step
An open research challenge involving more than 100 participants and AI coding agents has sharply reduced the estimated quantum resources needed for one important operation in a theoretical attack on Bitcoin and Ethereum signatures. The ECDSA.Fail paper, posted to arXiv on September 9, reports an 86.1% reduction in its benchmark over roughly two months of public optimization.
At the paper's July 26 data cutoff, the best circuit used 1,151 logical qubits and an average of 1,299,453 Toffoli gates, a measure of expensive quantum operations. Multiplying those figures produced a resource score of about 1.496 billion, down from the challenge's 10.75-billion baseline. Lower is better because the score combines working memory and computational workload.
Related reporting: Revolut disclosed Bitcoin records after fake government request
The Google comparison needs a caveat
The new score was numerically more than 50% below a point-addition result reported by Google Quantum AI in March. However, the researchers explicitly said different interfaces, correctness assumptions and accounting conventions prevent a claim of formal dominance. The comparison shows progress in circuit efficiency, not a simple like-for-like defeat of Google's work.
Eigen Labs, which initiated the challenge and built its evaluator and public leaderboard, said participants could submit improvements that were automatically checked for correctness and resource use. Successful designs became starting points for later teams. The paper attributes the result to a combination of human judgment, AI-assisted code exploration and a machine-checkable evaluation process.
Why Bitcoin and Ethereum are involved
Bitcoin and Ethereum use the secp256k1 elliptic curve to authorize transactions. A sufficiently capable fault-tolerant quantum computer could, in principle, use Shor's algorithm to recover a private signing key from an exposed public key and then forge signatures. Point addition is one repeated arithmetic operation inside that larger calculation, making its cost relevant to estimates of a future attack.
The challenge did not implement a complete attack. Its benchmark also supplied one input to the circuit classically, a shortcut unavailable in part of a real Shor computation. The authors therefore constructed a windowed-addition-compatible variant that removed the shortcut, using 1,162 logical qubits and about 1.68 million Toffoli gates. A full implementation, which would chain many calls to the kernel, remains future work.
No present-day breach
No current quantum computer comes close to executing these circuits, according to Eigen Labs. The research did not recover private keys, move coins or expose a vulnerability in running blockchain software. Independent coverage from Unchained likewise described the work as a cheaper resource estimate for a component, rather than an attack on either network.
A separate September 8 study from U.S.-based IonQ estimated an end-to-end secp256k1 calculation for a specific future trapped-ion architecture, illustrating how strongly results depend on hardware and error-correction assumptions. IonQ also said no digital asset or platform was affected during its research. Its figures should not be directly substituted for the ECDSA.Fail logical-circuit benchmark.
Why the result still matters
The practical message is about preparation time. Moving blockchains, wallets, custody systems and hardware to post-quantum signatures would require coordinated upgrades long before a capable machine appears. Better estimates help developers decide how urgently to test migration paths. The new result narrows one software benchmark, but the date of a cryptographically relevant quantum computer remains uncertain and depends on advances far beyond this circuit.
Sources
- ECDSA.Fail: Open Autoresearch for Optimizing Elliptic-Curve Point Addition in Shor's Algorithm
- From a Hidden Quantum Circuit to Open Autoresearch: The ECDSA.fail Story
- Researchers Cut the Estimated Quantum Cost of a Key Step in Attacking Bitcoin and Ethereum by More Than Half
- IonQ Publishes End-to-End Blueprint for Breaking 256-Bit Elliptic-Curve Signatures
AI-generated editorial image; not a photograph of the reported event. Prepared with AI assistance and source verification.
