A quantum computer that can forge a Bitcoin signature does not exist, and nobody serious claims one is coming this year. But the engineering target for building one just got smaller. A paper posted to arXiv and obtained ahead of publication by CoinDesk on September 10, 2026, shows that a team of more than 100 contributors, drawn from the Ethereum Foundation, Theta Labs, StarkWare and several other organizations, cut the estimated computing resources needed to break the elliptic-curve cryptography protecting Bitcoin and Ethereum wallets by more than half. The new circuit needs 1,151 logical qubits and roughly 1.3 million Toffoli gates to perform one arithmetic step inside Shor’s algorithm, the quantum routine that could eventually recover a private key from a public one.

That is a narrow, technical result. It is also the kind of number that custodians, exchanges and protocol developers watch closely, because it feeds directly into how urgently the broader cryptocurrency industry needs to migrate away from the cryptography both chains have used since launch. This piece breaks down what changed, what it does not change, and why the gap between “theoretically weaker” and “practically breakable” still spans years rather than months.

What the New Paper Actually Found

The research team focused on a single, expensive piece of a much larger puzzle: elliptic-curve point addition on the secp256k1 curve, the exact curve Bitcoin and Ethereum both use to generate key pairs. Shor’s algorithm, first described by mathematician Peter Shor in 1994, can in theory solve the discrete-logarithm problem that makes recovering a private key from a public key infeasible for classical computers. Running that algorithm against secp256k1 requires repeated elliptic-curve arithmetic, and point addition is one of the costliest repeated operations in the circuit.

Rather than attempt to model a full, end-to-end attack, the team rebuilt just that arithmetic stage and measured how cheaply it could run. Their circuit needs 1,151 logical qubits, the quantum equivalent of working memory, and about 1.3 million Toffoli gates, a unit that roughly tracks the volume of computation required. Multiplied together into a combined resource score, those two numbers land around 1.5 billion, more than 50% below the approximately 3 billion figure that Google Quantum AI published in a March 2026 whitepaper covering a comparable but not identical calculation.

The paper itself flags that the comparison is not perfectly clean, since the two teams used different accounting conventions. Still, a halving of the resource estimate for a core arithmetic step is a meaningful data point in a field where almost every published number has trended downward for the better part of a decade.

Logical Qubits, Toffoli Gates and Why the Units Matter

Two terms carry the weight of this story, and they measure different things. A logical qubit is an error-corrected, stable unit of quantum information built out of many noisy physical qubits working together through redundancy. Today’s most advanced machines operate with perhaps 100 logical qubits at most, built from roughly 1,000 to 1,200 physical qubits, according to figures cited in a June 2026 survey posted to arXiv under the title “Quantum Horizon.” A Toffoli gate, meanwhile, is a specific three-input logic gate used heavily in reversible arithmetic circuits; counting how many a computation needs is a standard way of estimating runtime and hardware volume.

Put plainly: the new paper did not build a quantum computer, and it did not demonstrate an attack. It produced a smaller blueprint for one specific piece of a hypothetical future attack, which matters because every published blueprint shrinks the gap that hardware teams still need to close. The gap remains enormous. Current machines are nowhere near 1,151 stable logical qubits, let alone the additional qubits needed for the rest of the discrete-logarithm circuit beyond point addition alone.

Human Scientists Plus AI Agents: A New Research Model

One detail in the reporting stands out beyond the raw numbers. According to The Quantum Insider, the project combined human scientists with AI agents during the optimization process and measured an 86.1% reduction from the team’s own internal starting point before arriving at the final circuit. The more widely cited 50%-plus improvement is measured against Google’s external March 2026 benchmark, which the paper’s authors treat as the more relevant comparison for the broader field, since it reflects progress against an outside baseline rather than the team’s own first draft.

That hybrid workflow is notable on its own terms. Circuit optimization for quantum algorithms is a search problem with an enormous space of possible gate arrangements, and it is exactly the kind of combinatorial task where automated agents can explore configurations faster than a small human team working alone. If this approach holds up and gets reused on other parts of the Shor’s-algorithm pipeline, it could compress the timeline for future resource-estimate papers, for better or worse depending on which side of the defense you sit on.

Who Is Already Exposed: Bitcoin and Ethereum by the Numbers

The reason any of this matters today, rather than purely as an academic curiosity, comes down to how much value already sits in a form a future quantum computer could target. Not every coin is equally exposed. A Bitcoin address that has never sent a transaction typically hides its public key behind a cryptographic hash, which offers meaningful protection even against a quantum adversary, at least for now. The risk concentrates in addresses that have already revealed their public key on-chain, either through old pay-to-public-key outputs from Bitcoin’s early years or through address reuse, where spending from an address exposes the key for any remaining balance.

Multiple research groups have tried to size that exposed pool, and they do not agree on an exact figure, largely because they use different on-chain snapshots and definitions of “exposed.” Blockstream’s quantum-security research page and a separate Spark research analysis both walk through the methodology gap in more depth. The table below lays out the competing estimates rather than collapsing them into one misleadingly precise number.

Source and DateExposed BTC EstimateShare of SupplyNotes
Google Quantum AI, March 2026~6.9 million BTC~35%Full public key already visible on-chain; cites ~20.5 million ETH similarly exposed
Glassnode, cited 2026~6.04 million BTC30.2%Includes 4.12 million BTC from address reuse and 1.92 million BTC from structural exposure; valued near $469 billion at the time of the analysis
Project Eleven, 2026~7 million BTC~33%Address reuse alone accounts for roughly 4.99 million BTC, or about 72% of the exposed total
Deloitte Netherlands, prior study~4 million BTC~25% at the timeEarlier P2PK and reused P2PKH analysis, included for comparison against 2026 figures

The spread between roughly 6 million and 7 million BTC reflects methodology, not disagreement about the underlying danger. Every group studying this agrees that somewhere between a quarter and a third of all circulating bitcoin sits in a form that a sufficiently capable quantum computer could eventually target, and that address reuse, not clever exploitation, is the single biggest driver of that exposure. We covered the exposure side of this story in more depth in our earlier look at Bitcoin’s 7 million BTC quantum risk and the stalled BIP-360 proposal, and in our piece on how NIST’s finalized post-quantum standards intersect with roughly $469 billion in exposed Bitcoin.

Two Different Attacks: At-Rest Theft and On-Spend Interception

Security researchers generally split the quantum threat to Bitcoin into two distinct scenarios, and they carry very different urgency. The first is an at-rest attack: an adversary with a working quantum computer scans the blockchain for exposed public keys, runs the discrete-logarithm circuit against each one, and drains the funds whenever the owner has not moved them to a safer address type. This is the slower, more patient version of the threat, and it is the one the exposure estimates in the table above describe.

The second is an on-spend attack, and it is the more alarming scenario for cryptographers because it does not require patience. Bitcoin’s roughly ten-minute block confirmation window briefly exposes a sender’s public key the moment a transaction broadcasts, before it settles into a block. A fast enough quantum computer could, in theory, derive the private key from that broadcast public key and submit a competing, faster transaction that steals the funds before the legitimate one confirms. That scenario does not need slow, patient computation; it needs a machine fast enough to win a race measured in minutes, which is a materially harder engineering target than the at-rest case but also the one that would matter the moment it becomes possible.

Why the Industry Still Has Time, According to the Paper’s Lead Author

Jieyi Long, the paper’s lead author and co-founder and chief technology officer of Theta Labs, framed the result’s significance in terms of planning rather than panic, according to Northeast Times’ reporting on his comments to The Quantum Insider. Long’s point was that credible, reproducible resource estimates are the input planners need to design a sensible migration away from vulnerable address types, and that roughly a third of all Bitcoin already sits in exposed-public-key addresses today. His broader argument was that remediation cannot happen retroactively once a sufficiently powerful quantum machine exists: coins that were never moved to a quantum-resistant address format before that point would simply be vulnerable, with no way to protect them after the fact. The urgency he described does not come from any imminent attack. It comes from the fact that migrating a network the size of Bitcoin or Ethereum, including persuading custodians, wallet providers and individual holders to move funds, takes years rather than months.

No Existing Machine Comes Close

It is worth stating plainly, because headlines about halved attack costs invite overreaction: nothing about this paper changes the fact that today’s quantum hardware is nowhere near capable of threatening Bitcoin or Ethereum. The “Quantum Horizon” survey posted to arXiv in June 2026 put the best machines available that year at roughly 1,000 to 1,200 physical qubits and at most about 100 logical qubits, against a stated requirement of somewhere between 1,200 and 2,330 logical qubits, or 0.5 million to 320 million physical qubits depending on architecture, just to break the relevant elliptic-curve cryptography. The new 1,151-logical-qubit figure sits inside that range, not below the error-correction overhead that turns logical qubits into a much larger physical-qubit requirement.

A separate March 2026 estimate, cited by CoinMarketCap Academy’s overview of the “Q-Day” debate, put the physical-qubit requirement at 317 million qubits for a one-hour attack window or 13 million qubits for a 24-hour window, assuming surface-code error correction with a physical gate error rate around one in a thousand. However the number gets sliced, the honest summary is the same: the theoretical attack has gotten cheaper on paper, and the practical attack remains out of reach of any machine that exists today.

Historical Context: A Decade of Shrinking Estimates

Resource estimates for breaking elliptic-curve and RSA cryptography have fallen steadily since researchers first began publishing concrete circuit designs for Shor’s algorithm in the 2010s. Each new paper tends to find a smarter way to arrange the same underlying arithmetic, trimming qubit counts or gate counts without changing the fundamental algorithm. The table below places the newest figures alongside the other benchmarks referenced in this piece, with the caveat that different teams measure different things, logical versus physical qubits, full attacks versus single arithmetic stages, and short runtimes versus multi-day windows, so none of these numbers should be read as a single continuous ladder.

EstimatePublishedKey FigureWhat It Measures
Google Quantum AI whitepaperMarch 2026Combined score ~3 billion; under 500,000 physical qubits with a ~9-minute precomputed attack scenarioBroader secp256k1 attack estimate, superconducting architecture
Yellow research citationMarch 2026317 million physical qubits (1-hour attack) or 13 million (24-hour attack)Surface-code error correction, 10⁻³ physical gate error rate
“Quantum Horizon” survey, arXivJune 20261,200 to 2,330 logical qubits; 0.5 million to 320 million physical qubitsRange across differing architecture assumptions
Ethereum Foundation / Theta Labs / StarkWare et al.September 10, 20261,151 logical qubits; ~1.3 million Toffoli gates; combined score ~1.5 billionSingle arithmetic stage: elliptic-curve point addition on secp256k1
Caltech / Oratomic neutral-atom concept202610,000 to 26,000 physical qubitsAlternative neutral-atom architecture; runtime measured in days, not minutes

The pattern across five separate research efforts in a single year is consistent even if the exact numbers are not directly comparable: every architecture anyone has modeled still needs either an enormous physical-qubit count on today’s hardware approaches or a substantially different, less mature architecture like neutral atoms to get the physical-qubit number down. Nobody has published a credible path to breaking Bitcoin’s cryptography on a machine that exists, or is likely to exist, within the next few years.

Bitcoin’s Response: BIP-360 and the Address-Reuse Problem

Bitcoin’s proposed answer to this entire category of risk is BIP-360, a draft standard for a new Pay-to-Merkle-Root output type designed to remove the quantum-vulnerable key-path spending route that Taproot currently allows, while preserving Taproot’s Merkleized script-tree design for everything else. We covered the proposal’s stalled status and the broader exposure numbers in detail in a previous article on Bitcoin’s quantum risk, and the short version has not changed: BIP-360 remains a draft, not an activated standard, and Bitcoin’s decentralized governance model means no single entity can simply flip a switch and force a network-wide migration.

A more aggressive companion proposal, often described by developers as covering post-quantum migration and a legacy signature sunset, goes further, outlining a phased timeline in which the network would stop accepting new transfers to legacy, quantum-vulnerable address types roughly three years after activation, and potentially invalidate old signatures entirely five years after that, which would functionally freeze any coins left unmigrated. That proposal illustrates the hardest part of this problem: the cryptography is fixable in principle, but fixing it means asking millions of holders, including people who lost their keys, died, or simply forgot about old wallets, to move funds before a deadline or risk losing access permanently. Our guide on setting up a quantum-resistant Bitcoin wallet today walks through the practical steps available to holders who do not want to wait for a network-level mandate.

Ethereum’s Different Exposure Profile

Ethereum shares the identical underlying cryptographic weakness, since both chains rely on ECDSA signatures over the secp256k1 curve, but the exposure shape differs. Ethereum accounts typically reveal their public key the first time they send any transaction, which means a larger share of active Ethereum addresses are exposed by design compared to Bitcoin, where many addresses never spend and therefore never reveal a key. Google’s March 2026 estimate put exposed ETH at roughly 20.5 million coins. Ethereum’s path to a fix also looks structurally different: because the network coordinates protocol changes through scheduled hard forks and already has an active research push around account abstraction, researchers broadly describe Ethereum as having a clearer, if not yet finalized, upgrade path than Bitcoin’s more contentious, consensus-dependent process. The involvement of Ethereum Foundation researchers as co-authors on the new resource-estimate paper itself signals how directly that ecosystem is engaging with the problem, rather than treating it as someone else’s concern.

For readers who want the cryptographic fundamentals behind why ECDSA and RSA are vulnerable to Shor’s algorithm in the first place, our explainer on elliptic curve cryptography versus RSA covers the math in plain terms, and our comparison of RSA against the NIST-standardized ML-KEM algorithm explains what the replacement cryptography actually looks like.

Market Reaction and Why It Was Muted

Academic resource-estimate papers rarely move crypto markets, and this one appears to be no exception. Bitcoin traded in a roughly $82,500 to $85,700 range through most of the surrounding week before climbing to $86,913 on October 2, 2026, its highest level since September 23, according to a QCP Capital report cited by ForkLog. That move lines up more plausibly with broader macro and flow dynamics than with a circuit-design paper about a single arithmetic subroutine, and no major exchange or custodian announced emergency changes to withdrawal policies, cold-storage procedures, or supported address types in response to the publication. That muted reaction is itself informative: institutional holders and exchanges appear to treat quantum resource-estimate papers as the ongoing research signal they are, worth tracking for migration planning, rather than as a near-term solvency threat requiring an immediate market response.

That calm should not be mistaken for the issue being resolved. It reflects a reasonable judgment that years, not weeks, separate today’s hardware from the capability this paper modeled.

Competing Hardware Paths: Superconducting Qubits vs. Neutral Atoms

Resource-estimate papers tend to assume a specific hardware architecture, because the overhead of turning noisy physical qubits into stable logical qubits varies enormously between approaches. Google’s benchmark and the new 1,151-qubit circuit both target superconducting-qubit architectures, the same general family of hardware Google and IBM have pursued for years. A separate 2026 study from Caltech researchers working with Oratomic explored neutral-atom architectures instead, estimating that a comparable computation might need only 10,000 to 26,000 physical qubits rather than the tens or hundreds of millions that surface-code superconducting estimates require. The tradeoff is speed: those neutral-atom systems would need days to complete a calculation that superconducting approaches model as running in minutes, which matters enormously for the on-spend attack scenario described earlier but far less for the slower at-rest scenario.

That split matters for anyone trying to forecast when a real threat might emerge, because “fewer qubits but much slower” and “more qubits but fast” are not interchangeable risks. A patient attacker willing to wait days per address only threatens coins that sit in cold storage indefinitely, while a fast attacker threatens anything that touches the network at all. No research group has yet shown a credible path to a machine that is both fast and small enough to run either attack with today’s known physical-qubit counts.

What This Means for Exchanges, Custodians and Individual Holders

The practical takeaway for anyone holding bitcoin or ether outside of a pure trading context is unglamorous but important: address reuse is the single most fixable piece of this problem, and it is entirely within an individual holder’s control today, years before any BIP activates. Moving funds to a fresh address after every withdrawal, rather than receiving repeatedly to the same old address, keeps the public key hidden behind a hash for as long as possible under current script types. Custodians and exchanges carry a heavier version of the same responsibility, since consolidated hot and cold wallets concentrate enormous value behind a comparatively small number of keys, some of which have necessarily been exposed through past transaction activity.

None of this requires panic-selling or emergency key rotation. It does argue for treating post-quantum migration as an infrastructure project with a multi-year runway, the same way large organizations have treated the broader shift toward NIST’s finalized post-quantum cryptography standards across the rest of the internet. Our explainer on the state of post-quantum cryptography adoption across the web covers how that broader migration is tracking outside of crypto specifically, which is a useful benchmark for how slowly even well-funded, centrally coordinated organizations tend to move on this kind of upgrade.

Predictions: What Happens Next

Several near-term developments look likely based on the trajectory this research area has followed through 2026.

Expect more resource-estimate papers, not fewer, as AI-assisted circuit optimization spreads beyond this one project. The 86.1% internal reduction the team reported suggests other groups will adopt similar human-plus-AI workflows to chase further cuts across different stages of the Shor’s-algorithm pipeline.

Expect continued disagreement over exposure statistics rather than convergence on one number, since Google, Glassnode and Project Eleven all use different on-chain criteria, and no single entity controls or audits how “exposed” gets defined.

Expect BIP-360 to remain in draft status for a while longer, given Bitcoin’s history of multi-year timelines for consensus changes far less contentious than one that could eventually restrict spending from legacy address types.

Expect Ethereum’s research community to keep moving faster on this specific question than Bitcoin’s, given the Ethereum Foundation’s direct authorship role on the new paper and the network’s generally more centralized upgrade process.

Expect muted market reaction to continue for any individual paper in this space, barring an actual hardware announcement that claims to approach the qubit counts these estimates describe, which no credible lab has done as of this writing.

The Bottom Line

A research team cut the estimated cost of one critical step in a hypothetical future attack on Bitcoin and Ethereum by more than half, using a combination of human expertise and AI-assisted optimization that is itself a notable development in how this kind of cryptanalysis research now gets done. That is real progress toward a more precise understanding of the threat, and it is not evidence of an imminent one. The gap between 1,151 logical qubits on paper and a working, fault-tolerant machine that can hold them remains measured in years of hardware development, not months. The more immediate, controllable risk for anyone holding crypto today is the mundane one: address reuse, old pay-to-public-key outputs, and a migration conversation that both Bitcoin and Ethereum are still having without a finished answer.

Frequently Asked Questions

Can a quantum computer steal my Bitcoin right now?
No. The circuit described in the September 2026 paper is a resource estimate for a hypothetical future machine, not a demonstrated attack. No existing quantum computer has anywhere close to the 1,151 stable logical qubits the point-addition step alone would require, let alone the additional qubits needed for a complete attack.

What is a logical qubit, and why does it matter more than the physical qubit count?
A logical qubit is an error-corrected unit built from many noisy physical qubits working together. Because today’s hardware needs large numbers of physical qubits to produce even one reliable logical qubit, the physical-qubit requirement for an attack is typically many times larger than the logical-qubit figure alone suggests.

Which Bitcoin addresses are actually at risk?
Addresses that have already revealed their public key on-chain, either through old pay-to-public-key outputs or by spending from a reused address, carry the exposure. Addresses that have never sent a transaction keep their public key hidden behind a hash and are considerably better protected under current script types.

What is BIP-360, and has it been activated?
BIP-360 is a draft Bitcoin proposal for a new Pay-to-Merkle-Root address format intended to remove Taproot’s quantum-vulnerable spending path. As of the most recent reporting, it remains a draft without a network-wide activation mechanism.

Is Ethereum more or less exposed than Bitcoin?
Both chains share the same underlying ECDSA and secp256k1 vulnerability. Ethereum tends to expose public keys more broadly by design, since most active accounts have already sent a transaction, while Bitcoin’s exposure concentrates more heavily in old or reused addresses specifically.

Should I move my crypto to a new wallet because of this news?
There is no urgent need to act on this specific paper alone. Avoiding address reuse and keeping funds in addresses that have never broadcast a transaction remains good practice regardless, and is already within any holder’s control today.

How does this compare to Google’s earlier quantum estimate?
Google Quantum AI’s March 2026 whitepaper put a comparable combined resource score at roughly 3 billion. The new paper’s combined score of about 1.5 billion is a reduction of more than 50%, though the two teams used different accounting methods, so the comparison is directional rather than exact.

What role did artificial intelligence play in this research?
According to The Quantum Insider’s reporting, the project combined human researchers with AI agents during circuit optimization and measured an 86.1% reduction from the team’s own internal starting point, a notable example of AI-assisted cryptanalysis research rather than a purely human effort.