On April 24, 2026, independent researcher Giancarlo Lelli claimed Project Eleven's Q-Day Prize by deriving a 15-bit elliptic curve private key on publicly accessible quantum hardware — a 512x increase over the previous public demonstration. The achievement, while orders of magnitude below the 256...
"The resource requirements for this type of attack keep dropping, and the barrier to running it in practice is dropping with them." — Alex Pruden, CEO, Project Eleven
On April 24, 2026, independent researcher Giancarlo Lelli claimed Project Eleven's Q-Day Prize by deriving a 15-bit elliptic curve private key on publicly accessible quantum hardware — a 512x increase over the previous public demonstration. The achievement, while orders of magnitude below the 256-bit keys securing Bitcoin and Ethereum, arrives amid a 90-day period in which three separate research papers slashed estimated qubit requirements for breaking blockchain cryptography by a factor of 20.
The convergence of shrinking hardware thresholds, published attack methodologies, and an estimated $2 trillion in ECC-secured crypto assets has forced the question from theoretical to operational: which networks can migrate to post-quantum cryptography before the window closes, and at what cost? This report compares the quantum readiness postures of Bitcoin, Ethereum, Solana, Algorand, and Cardano — the five largest networks by either market capitalization or stated quantum preparedness — against current hardware trajectories and NIST post-quantum standards finalized in August 2024.
Three papers published between May 2025 and March 2026 rewrote resource estimates for quantum cryptanalysis:
| Date | Author / Institution | Target | Physical Qubit Estimate | Reduction vs. Prior | |------|---------------------|--------|------------------------|-------------------| | May 2025 | Craig Gidney, Google Quantum AI | RSA-2048 | < 1 million | 20x vs. 2019 estimate of 20 million | | Feb 2026 | Iceberg Quantum (Sydney) | RSA-2048 | < 100,000 | 10x vs. Gidney 2025 | | Mar 2026 | Google Quantum AI, Ethereum Foundation, Stanford | ECDLP-256 (secp256k1) | < 500,000 | 20x vs. Litinski 2023 (~9 million) |
The March 2026 Google paper is the most directly relevant to cryptocurrency. It demonstrated that Shor's algorithm applied to the 256-bit elliptic curve discrete logarithm problem (ECDLP-256) — the exact curve used by Bitcoin, Ethereum, and most major blockchains — can execute with 1,200–1,450 logical qubits and 70–90 million Toffoli gates. On a superconducting quantum computer, this translates to fewer than 500,000 physical qubits and a runtime of approximately nine minutes per key, according to the paper.
The nine-minute figure is notable because Bitcoin's average block confirmation time is ten minutes. Under idealized conditions, the paper estimated a 41% probability of deriving a private key before a pending transaction confirms. The authors — who include Justin Drake of the Ethereum Foundation and Dan Boneh of Stanford — published a zero-knowledge proof validating their results rather than disclosing full attack circuits, citing responsible disclosure. Google engaged U.S. government agencies prior to publication.
A separate paper from Caltech and quantum startup Oratomic proposed that neutral-atom quantum architectures could reduce the requirement further, to as few as 10,000 qubits, though this estimate depends on hardware connectivity assumptions that remain unproven at scale.
Meanwhile, Lelli's April 24 demonstration broke a 15-bit key across a search space of 32,767 using roughly 70 qubits. For context, Bitcoin uses 256-bit keys with a search space of approximately 1.16 × 10^77. The gap remains vast, but the trajectory of shrinking estimates — from 20 million qubits in 2019 to under 500,000 in 2026 — is what concerns cryptographers.
According to Project Eleven's analysis and the March 2026 Google paper, approximately 6.9 million BTC (roughly 33% of all Bitcoin in existence) sit in addresses with exposed public keys. At current prices near $93,000, this represents over $640 billion in quantum-vulnerable Bitcoin alone. Across all ECC-secured cryptocurrency assets, estimates exceed $2 trillion in at-risk value.
The exposure is not uniform across networks:
Bitcoin's response centers on two complementary proposals. BIP-360, introduced in February 2026, creates a new output type called pay-to-Merkle-root (P2MR) — a Taproot-style construction with the quantum-vulnerable key-path spend removed. BTQ Technologies implemented BIP-360 on Bitcoin's testnet in March 2026, using NIST-standard Dilithium post-quantum signatures.
BIP-361, co-authored by Jameson Lopp and five other researchers and updated April 15, 2026, addresses the 6.7 million BTC in legacy addresses through a three-phase plan:
BIP-361 remains a draft with no activation parameters. Community response is divided. Critics call the freeze mechanism "confiscatory" and incompatible with Bitcoin's self-sovereignty ethos. Supporters frame it as a defensive necessity — the alternative being that quantum-capable adversaries drain exposed wallets.
The Ethereum Foundation named post-quantum security a core 2026 priority. The upcoming Hegota upgrade, scheduled for late Q3 or early Q4 2026, will begin integrating post-quantum cryptographic primitives. Key elements include:
The Foundation established a dedicated post-quantum team and announced bi-weekly developer calls focused on quantum security. It also posted a $1 million bounty for advances in quantum-resistant cryptography. Ethereum's broader timeline targets full quantum-safe migration by approximately 2029.
Notably, Justin Drake — an Ethereum Foundation researcher — co-authored the March 2026 Google paper that quantified the threat. This dual role as threat assessor and defense architect gives Ethereum an unusual level of direct engagement with the problem.
Solana faces a structural disadvantage. Testing by Project Eleven revealed that a Solana build using quantum-resistant cryptography ran approximately 90% slower than the current network. Post-quantum signatures are 20–40x larger than classical equivalents, creating severe bandwidth and throughput constraints for a network optimized for speed.
Solana's planned Alpenglow consensus upgrade depends on BLS signature aggregation for efficient validator voting. No practical post-quantum equivalent to BLS aggregation exists. Research into lattice-based and STARK-based alternatives continues, but none are production-ready.
As an interim measure, the ecosystem is exploring Winternitz Vaults — wallet-level cryptographic protections that do not require a protocol-wide upgrade. The Solana Foundation is collaborating with Project Eleven on testing, but no binding migration timeline has been published.
A Coinbase research report published April 22, 2026 ranked Algorand as the most quantum-ready blockchain. Algorand executed a quantum-resistant transaction on mainnet using Falcon, a NIST-selected lattice-based signature scheme. Users can already create quantum-resistant accounts through logic signatures without a core protocol change.
Limitations remain: block proposal and committee voting mechanisms still use classical cryptography. A full protocol-level upgrade has not been scheduled.
Google's analysis ranked Cardano second in quantum readiness due to its extended UTXO (eUTXO) model, which keeps public keys hashed until funds are spent — providing longer protection than account-based networks. The protocol's architecture supports algorithm upgrades via hard forks without structural redesign.
However, Cardano has not implemented post-quantum signatures on mainnet or testnet. No firm upgrade timeline has been disclosed.
The economic cost of post-quantum migration is non-trivial. Key constraints include:
NIST's own timeline calls for quantum-vulnerable algorithms to be deprecated after 2030 and disallowed after 2035. The NSA's CNSA 2.0 directive requires all new national security systems to be quantum-safe by January 2027. IBM's hardware roadmap targets 200 logical qubits by 2029 and 2,000 by 2033.
The core risk is asymmetric: hardware development follows exponential improvement curves, while blockchain governance operates through consensus-driven soft forks that can take years from proposal to activation.
Current state of quantum hardware:
The gap between today's ~1,000 physical qubits and the ~500,000 needed for ECDLP-256 is large. But qubit counts have grown roughly 10x every three years since 2019. If that trajectory holds, the 500,000 threshold falls within the 2029–2033 window — precisely when IBM targets 200–2,000 logical qubits.
Project Eleven CEO Pruden cited 2029 as a worst-case timeline for quantum threat materialization. Google's internal deadline for completing its own post-quantum migration is also 2029.
The quantum threat to blockchain cryptography has shifted from a decades-away abstraction to a measurable engineering problem with published resource estimates, testnet implementations, and policy deadlines. The gap between current hardware (approximately 1,000 qubits) and the attack threshold (approximately 500,000 qubits) provides a window, but that window is narrowing at a rate that surprised researchers three times in the past year.
The networks that survive the transition will be those that solve the governance problem — coordinating millions of participants to upgrade cryptographic primitives — before the hardware problem solves itself. As of April 2026, no production blockchain has done so. The clock is running.