Google Quantum AI's March 2026 paper reduced the estimated qubit requirement to break Bitcoin's elliptic-curve cryptography by approximately 20x, from roughly 9 million physical qubits to fewer than 500,000. The finding, co-authored with Ethereum Foundation researcher Justin Drake and Stanford cr...
Google Quantum AI's March 2026 paper reduced the estimated qubit requirement to break Bitcoin's elliptic-curve cryptography by approximately 20x, from roughly 9 million physical qubits to fewer than 500,000. The finding, co-authored with Ethereum Foundation researcher Justin Drake and Stanford cryptographer Dan Boneh, models a real-time transaction-hijacking attack with a 41% success rate against Bitcoin's 10-minute block confirmation window, running in 9 to 12 minutes per key.
The research identifies approximately 6.9 million BTC — roughly 32% of total supply, valued at approximately $454 billion at current prices — sitting in wallets with exposed public keys. Three months after publication, independent researcher Giancarlo Lelli broke a 15-bit elliptic curve key on publicly accessible quantum hardware, winning Project Eleven's 1 BTC Q-Day Prize and representing a 512x jump in complexity over the previous 6-bit record. These developments have triggered a cascade of defensive measures: BIP-360 merged in February 2026, BIP-361 proposed in April, Ethereum published a four-year quantum defense roadmap, and Galaxy Digital committed $5 million in developer grants on July 21, 2026.
Current quantum hardware — IBM's Heron r3 at 156 qubits, Google's Willow at 105 — remains orders of magnitude below the 500,000-qubit threshold. Most hardware projections do not place commercially available systems at that scale before 2033–2035. The threat is not immediate. The question is whether Bitcoin's governance process can execute a network-wide cryptographic migration before the window closes.
On March 30, 2026, Google Quantum AI published a paper demonstrating that breaking the 256-bit elliptic curve discrete logarithm problem (ECDLP-256) — the mathematical foundation of Bitcoin's signature scheme — could require fewer than 500,000 physical qubits. The previous best estimate, from a 2019 analysis, placed the requirement at roughly 9 million. The reduction factor is approximately 20x.
The paper, co-authored by researchers from Google, the Ethereum Foundation, and Stanford University, modeled an optimized implementation of Shor's algorithm against secp256k1, the specific elliptic curve used by Bitcoin. Under Google's hardware noise model, the attack completes in approximately 9 to 12 minutes per key using no more than 1,200 logical qubits mapped onto fewer than 500,000 physical qubits.
The paper also modeled a transaction-interception scenario. An attacker monitoring the Bitcoin mempool could observe an unconfirmed transaction, extract the sender's public key (exposed at the moment of signing), derive the private key via quantum computation, and broadcast a competing transaction — all within Bitcoin's average 10-minute block confirmation window. The modeled success rate: 41%.
According to CoinDesk, the paper prompted immediate debate. Some researchers, including the QubitChain analysis team, noted that the 500,000 figure assumes error rates and gate fidelities that no current hardware achieves. Others pointed out that the 20x compression itself was the signal — the trajectory of improvement, not the absolute number.
The quantum threat to Bitcoin is not uniform. It concentrates on wallets where the public key is already visible on-chain. According to analysis cited in the Google paper and corroborated by CoinDesk and Coinpedia, approximately 6.9 million BTC fall into this category. At Bitcoin's price of approximately $65,800 on July 22, 2026, that represents roughly $454 billion in exposed value.
The exposure breaks down into several categories:
The critical distinction: P2PK and reused-address coins face an "offline" attack — no time pressure, no race against block confirmation. An attacker with a cryptographically relevant quantum computer (CRQC) could work through exposed keys systematically. The roughly 2.3 million BTC in addresses whose owners are believed to be unreachable — including Satoshi's estimated 1.1 million BTC — are considered irreversibly exposed, as no migration is possible without the original key holder.
On April 24, 2026, Giancarlo Lelli, an independent Italian researcher, broke a 15-bit elliptic curve cryptography key using publicly accessible quantum hardware. He won the 1 BTC Q-Day Prize from Project Eleven, a company building post-quantum security infrastructure for Bitcoin that raised $6 million in mid-2025.
Seven months prior, the record stood at 6 bits. Lelli's result represents a 512x increase in the complexity of the broken key (2^15 vs. 2^6). According to The Block, Lelli accomplished this working alone, using rented cloud-based quantum hardware — not a proprietary lab system.
The gap between 15 bits and the 256 bits protecting real Bitcoin wallets remains enormous: 2^241 orders of magnitude. No credible researcher has suggested that current or near-term quantum hardware can bridge this gap. The significance lies in the rate of progress and the demonstration that real quantum attacks on elliptic curve cryptography are no longer purely theoretical.
BIP-360: Pay-to-Merkle-Root (P2MR)
On February 11, 2026, BIP-360 was merged into Bitcoin's official BIP repository. The proposal introduces a new output type called Pay-to-Merkle-Root (P2MR), designated with the address prefix bc1z. P2MR functions similarly to Taproot (P2TR) but removes the exposed public key. Instead, keys are hidden behind a Merkle tree structure until the moment of spending.
According to Bitcoin Magazine and Blockspace Media, the merge into the BIP repository does not constitute endorsement or guarantee future activation. BIPs are merged as documentation of potential upgrades, not as commitments to deployment. P2MR protects coins going forward but does nothing for the approximately 6.9 million BTC already in quantum-vulnerable addresses.
BIP-361: Post-Quantum Migration and Legacy Signature Sunset
In April 2026, Jameson Lopp and five co-authors from the quantum security space published BIP-361. The proposal outlines a structured, multi-year migration with three phases:
According to CryptoSlate, BIP-361 forces the Bitcoin community to choose between frozen and stolen coins — a governance decision with no precedent in Bitcoin's history. The proposal effectively sets a deadline for the estimated $454 billion in exposed BTC to migrate or be permanently locked.
In February 2026, Vitalik Buterin published a quantum defense roadmap identifying four cryptographic systems requiring post-quantum upgrades: BLS signatures (validator consensus), KZG commitments (data availability), ECDSA (wallet signatures), and certain zero-knowledge proof systems. The plan introduces six quantum-resistant signature schemes and 13 EVM precompiles.
The Ethereum Foundation established a Post-Quantum Security team in January 2026 with more than 10 client teams, targeting full quantum resistance before 2030. According to CoinDesk, the Foundation launched a dedicated post-quantum security hub in March 2026.
At Devconnect Buenos Aires, Buterin stated that elliptic curve cryptography "could fail before the 2028 U.S. election" — a more aggressive timeline than most quantum computing experts endorse, but one that reflects the Ethereum community's risk calculus. Ethereum's "Strawmap" — a four-year Layer 1 upgrade plan — incorporates post-quantum hash-based signatures as a core component.
The key difference between Bitcoin and Ethereum's approaches: Ethereum's upgrade governance, while contentious, operates through a coordinated Foundation-led process with client team buy-in. Bitcoin's upgrade mechanism requires broad community consensus and historically operates on longer timescales. The SegWit activation debate took approximately two years; Taproot took roughly three from proposal to activation.
On July 21, 2026, Galaxy Digital announced the Bitcoin Quantum Readiness Initiative, committing up to $5 million in developer grants. The initiative targets three areas: quantum-resistant signature scheme development, wallet migration tooling, and security auditing of proposed post-quantum upgrades.
Galaxy established a Quantum Advisory Council with inaugural members including Barry Sanders (Professor and Scientific Director of Quantum City, University of Calgary), Damien Bérubé (MIT Sea Grant Knauss Fellow), and Eran Tromer (Professor of Computer Science, Boston University). The council will evaluate grant proposals and guide research priorities.
According to The Block, Galaxy Head of Research Alex Thorn positioned the initiative as bridging the gap between rapid quantum computing advances and Bitcoin's comparatively slow developer response. Applications opened immediately for projects advancing Bitcoin's cryptographic resilience.
The $5 million commitment is modest relative to the scale of the problem — BIP-361's migration would require tooling for millions of wallets — but represents the first significant private-sector funding directed specifically at Bitcoin's quantum defense. Galaxy is currently a Nasdaq-listed company (GLXY) with approximately $5.5 billion in assets under management.
The distance between current quantum hardware and the threat threshold provides context for urgency:
| System | Qubits | Year | |--------|--------|------| | Google Sycamore | 53 | 2019 | | Google Willow | 105 | 2024 | | IBM Heron r3 | 156 | 2025 | | IBM Kookaburra (planned) | 4,158 | 2026 | | IBM Starling (planned) | ~10,000 | 2029 | | Threshold to break ECDLP-256 | ~500,000 | Unknown |
According to The Quantum Insider and CryptoRank, the most optimistic hardware projections do not place commercially available systems at 500,000 physical qubits before 2033–2035. Some estimates extend the timeline to 2040 or beyond, depending on assumptions about error correction rates, gate fidelities, and qubit coherence times.
The number of physical qubits alone is insufficient. Those qubits must operate with error rates low enough to sustain the approximately 1,200 logical qubits required for the attack. Current error correction ratios require roughly 1,000 physical qubits per logical qubit, though this ratio is expected to improve.
NIST finalized three post-quantum cryptography standards in August 2024: CRYSTALS-Kyber (ML-KEM, FIPS 203) for key exchange, CRYSTALS-Dilithium (ML-DSA, FIPS 204) for digital signatures, and SPHINCS+ (SLH-DSA, FIPS 205) as a hash-based signature backup. A fourth standard, Falcon (FN-DSA, FIPS 206), remains in final draft with expected publication in 2027.
The algorithms exist. The challenge for blockchain networks is implementation and migration at scale. Bitcoin's BIP-360 does not directly implement any NIST standard; it introduces a framework-agnostic address type that can accommodate multiple post-quantum signature schemes. The specific algorithm selection remains an open question within Bitcoin's developer community.
The migration problem compounds for decentralized networks. Traditional IT infrastructure operates under centralized authority — a corporation can mandate cryptographic upgrades across its systems. Bitcoin's approximately 50,000 full nodes, millions of wallet holders, and consensus-driven governance model have no equivalent mechanism. Every holder of quantum-vulnerable BTC must individually migrate their funds, or — under BIP-361 — accept permanent freezing.
The quantum threat to blockchain cryptography has shifted from speculative to quantifiable in 2026. Google's 20x resource reduction, Lelli's 15-bit key break, and the BIP-360/361 proposals have moved the discussion from academic curiosity to active protocol engineering. The $454 billion in exposed Bitcoin provides a concrete measure of what is at stake.
The core tension is temporal. Bitcoin's governance process — designed for deliberation and broad consensus — must execute a cryptographic migration that touches every wallet on the network. Historical precedent (SegWit: ~2 years, Taproot: ~3 years) suggests this process operates on timescales measured in years, not months. If the 500,000-qubit threshold arrives by 2035, the window for preparation may be adequate. If error correction advances compress that timeline, it may not be.
Galaxy's $5 million commitment and the BIP-360/361 proposals represent the beginning of an organized response. Whether that response can scale to match the magnitude of the problem — migrating billions of dollars in value across a decentralized network with no central authority — remains the defining question. The algorithms to defend against quantum attacks exist. The engineering is underway. The governance is the bottleneck.