Researchers Halve Quantum Attack Benchmark for Bitcoin and Ethereum
A new study cuts the estimated quantum computing resources needed to crack Bitcoin and Ethereum's elliptic curve cryptography by roughly 50%, pushing the theoretical attack threshold below Google's benchmark and raising questions about migration timelines for post-quantum cryptography.
Researchers Halve Quantum Attack Benchmark for Bitcoin and Ethereum
A new study has cut the estimated quantum computing resources needed to crack Bitcoin and Ethereum's elliptic curve cryptography by roughly 50%, pushing the theoretical attack threshold below half of Google's previously reported benchmark. The finding is the most significant downward revision of attack complexity estimates to date, raising pointed questions about how much runway the blockchain industry actually has before quantum threats become practical.
The research centers on the quantum resource requirements for breaking elliptic curve cryptography (ECC), the mathematical foundation securing private keys on both Bitcoin and Ethereum. ECC relies on the computational difficulty of solving the discrete logarithm problem, a task that remains intractable for classical computers but is theoretically solvable by a sufficiently powerful quantum machine running Shor's algorithm. Until now, the resource bar for that attack was high enough that most security researchers treated the threat as decades away.
"The resulting benchmark is less than half Google's previously reported level, though the two approaches use different accounting methods."
That caveat matters. Different research teams use different accounting frameworks when measuring quantum resources, typically counting in terms of logical qubits, physical qubits, or gate operations, and those frameworks are not directly interchangeable. A separate analysis pegged the reduction at closer to 20-fold rather than 50%, a divergence that reflects methodology rather than disagreement on the underlying physics. The practical upshot is the same either way: the attack is cheaper than the field previously estimated, by a meaningful margin.
The gap between a benchmark reduction and an actual working attack remains enormous. Quantum computers capable of threatening blockchain cryptography do not exist today. Current quantum hardware operates with error rates and qubit counts that fall orders of magnitude short of what any credible attack scenario requires. Bitcoin and Ethereum have survived prior rounds of quantum anxiety intact, and both communities have demonstrated the ability to coordinate protocol upgrades when a genuine security case is made. Post-quantum cryptography (PQC) standards, including the lattice-based algorithms finalized by the National Institute of Standards and Technology (NIST) in 2024, are already available for integration.
"Quantum advancements could accelerate the need for blockchain systems to adopt post-quantum cryptography, impacting security protocols."
The urgency argument, however, is not purely about when a quantum attack becomes executable. It is about migration lead time. Upgrading Bitcoin or Ethereum to PQC signatures requires broad consensus, extensive testing, and coordinated hard or soft forks across thousands of nodes and millions of wallets. Ethereum's roadmap already includes quantum resistance as a long-term objective, and Bitcoin developers have debated PQC proposals in various Bitcoin Improvement Proposals. But neither network has committed to a concrete upgrade timeline. If the actual threat horizon is compressing, the window for an orderly migration narrows in parallel.
Google's 2023 quantum benchmarks had set a widely cited reference point for the resources needed to execute a cryptographically relevant attack on ECC. The new research places the requirement at less than half that figure. Even under the more conservative 20-fold reduction framing, the implication is that prior estimates overstated the difficulty of the attack by a substantial factor. Academic literature on quantum threats to blockchain has grown steadily over the past five years, but revisions of this magnitude are uncommon.
For holders of Bitcoin and Ethereum, the near-term risk remains negligible. No quantum computer on the horizon can execute this attack. The risk is structural and forward-looking: cryptographic migrations are slow, politically complex, and technically fraught, and the blockchain industry has a track record of underestimating how long coordinated upgrades take. The NIST PQC finalization removed one bottleneck. The harder work, getting decentralized networks to move in lockstep before the threat is imminent rather than after, is still ahead.





