On April 24, 2026, independent researcher Giancarlo Lelli derived a private key from a 15-bit elliptic curve public key on IBM's 133-qubit quantum hardware, winning Project Eleven's 1 BTC Q-Day Prize. The result represents the largest public quantum attack on elliptic curve cryptography (ECC) to ...
"The resource requirements for this type of attack keep dropping, and the barrier to running it in practice is dropping with them." — Alex Pruden, CEO of Project Eleven
On April 24, 2026, independent researcher Giancarlo Lelli derived a private key from a 15-bit elliptic curve public key on IBM's 133-qubit quantum hardware, winning Project Eleven's 1 BTC Q-Day Prize. The result represents the largest public quantum attack on elliptic curve cryptography (ECC) to date — 512 times larger than the previous 6-bit demonstration achieved by Steve Tippeconnic in September 2025.
The achievement reignited debate over the timeline and severity of quantum threats to $2.5 trillion in ECC-secured digital assets. Resource estimates for a full 256-bit ECC break have fallen sharply: Google's April 2026 whitepaper puts the requirement below 500,000 physical qubits, while a subsequent Caltech/Oratomic paper models the attack at as few as 10,000 qubits using neutral-atom architecture. Approximately 6.9 million BTC — roughly one-third of total supply — sit in addresses with exposed public keys, according to Project Eleven's analysis.
The result is not without controversy. Former Bitcoin Core maintainer Jonas Schnelli and developer Yuval Adam independently replicated Lelli's key recovery using random bits with no quantum hardware, arguing the demonstration constituted "a classical brute-force search with an expensive random number generator" rather than genuine quantum cryptanalysis. The debate underscores how far current quantum machines remain from practical ECC attacks — while simultaneously highlighting how fast the theoretical ceiling is dropping.
Project Eleven, a quantum security research firm, launched the Q-Day Prize to incentivize real-world demonstrations of Shor's algorithm against elliptic curve keys on publicly accessible quantum hardware. The challenge: derive a private key from its corresponding public key using a quantum computer.
Lelli's submission broke a 15-bit key across a search space of 32,767 values using a variant of Shor's algorithm targeting the Elliptic Curve Discrete Logarithm Problem (ECDLP). The hardware used was IBM's cloud-accessible 133-qubit system. The previous public record — Tippeconnic's 6-bit break in September 2025 — covered a search space of just 63.
The progression from 6 bits to 15 bits in seven months represents measurable advancement, though the gap to Bitcoin's 256-bit ECC security remains vast. A 256-bit key has a search space of approximately 1.16 × 10^77. Put differently: Lelli's demonstration solved a puzzle approximately 10^72 times smaller than the one protecting Bitcoin wallets.
Project Eleven CEO Alex Pruden framed the result as a trend indicator rather than an immediate threat, noting the consistent compression of resource estimates required for larger key breaks.
The result drew sharp criticism from several Bitcoin developers who questioned whether the quantum hardware contributed meaningful computation.
Analyst Checkmate stated: "It's nonsense, the quantum part can be swapped for a random number generator and get the same results." Developer Yuval Adam replaced the quantum circuit's output with random bytes from /dev/urandom and recovered byte-identical keys to Lelli's reported results. Adam characterized the method as "a classical brute-force search with an expensive random number generator."
The core technical argument: at 15 bits, the search space is small enough that random sampling plus classical verification will recover the key with high probability. The quantum circuit, critics contend, is not demonstrating Shor's algorithm at a meaningful scale — it is producing noisy outputs that happen to work because the target is trivially small.
This does not invalidate the broader quantum threat. It does, however, suggest that current public demonstrations remain firmly in the proof-of-concept category rather than representing functional quantum cryptanalysis.
The more consequential developments are theoretical. Resource estimates for breaking 256-bit ECC have fallen significantly over the past 18 months:
| Source | Date | Estimated Physical Qubits | Architecture | |--------|------|--------------------------|--------------| | Earlier academic consensus | Pre-2025 | Millions | Superconducting | | Google Quantum AI | April 2026 | < 500,000 | Superconducting | | Caltech / Oratomic | April 2026 | ~10,000 | Neutral-atom |
Google's refined version of Shor's algorithm requires 20 times fewer resources than prior implementations to crack ECDSA-256, according to the company's April 2026 whitepaper. A Google-led study indicated that a sufficiently advanced quantum system could theoretically derive private keys within one Bitcoin block interval (approximately 10 minutes).
Google's own 105-qubit Willow chip sits at Milestone 2 of the company's six-milestone roadmap, with commercially useful systems targeted by the end of the decade. Current machines are not capable of executing the attack. The question is when they will be — and whether crypto infrastructure will have migrated by then.
Not all cryptocurrency holdings face equal quantum risk. The vulnerability is specific to addresses where the public key has been exposed on-chain — primarily older pay-to-public-key (P2PK) format addresses and addresses that have been reused after spending.
According to Project Eleven's analysis, approximately 6.9 million BTC sit in addresses with exposed public keys. This includes an estimated 1 million BTC attributed to Satoshi Nakamoto's early mining activity, which used P2PK formats exclusively.
Wall Street broker Bernstein, in an April 2026 assessment, identified 1.7 million BTC in "legacy" wallets with concentrated quantum exposure and characterized the overall threat as "a medium to long term system upgrade cycle rather than a risk." Bernstein noted that Bitcoin's mining mechanism (SHA-256 hashing) remains effectively secure even in advanced quantum scenarios; the vulnerability is confined to the elliptic curve signatures used for wallet authentication.
Total ECC-secured digital assets across all chains — including Ethereum, Solana, and other networks using ECDSA or EdDSA — exceed $2.5 trillion, according to Project Eleven.
Bitcoin's quantum defense effort has produced two proposals that now define the community's internal fault line.
BIP-360 was merged into the official Bitcoin BIP repository on February 11, 2026. It introduces Pay-to-Merkle-Root (P2MR), a new output type that commits directly to the script tree's Merkle root without relying on an internal key or tweak. P2MR addresses (designated bc1z) preserve Taproot's scripting capabilities while eliminating the key-path spend that creates quantum vulnerability. BTQ Technologies launched Bitcoin Quantum testnet v0.3.0 in March 2026 with the first working BIP-360 implementation using CRYSTALS-Dilithium signatures. Merge into the BIP repository does not signal endorsement or activation.
BIP-361 extends BIP-360 with a mandatory migration timeline and enforcement mechanism:
BIP-361 targets approximately 6.5 million coins valued at roughly $74 billion. The proposal has generated significant opposition. Blockstream CEO Adam Back has publicly pushed for optional upgrades over forced freezes, arguing that mandated migration violates Bitcoin's property-rights principles. The core tension: protecting the network's long-term security versus respecting the immutability of existing holdings.
The Ethereum Foundation formed a dedicated Post-Quantum Security team in January 2026 and elevated quantum readiness to a strategic priority for the year.
Ethereum's approach differs structurally from Bitcoin's. Rather than proposing a single migration event, the Foundation is pursuing a layered strategy:
The Ethereum Foundation targets completion of core post-quantum infrastructure by approximately 2029, aligned with Google's own migration deadline.
A Coinbase-convened advisory board — including Stanford cryptographer Dan Boneh, Ethereum Foundation researcher Justin Drake, and Eigen Labs founder Sreeram Kannan — published recommendations in April 2026 stating that "preparation must begin now" and advocating hybrid systems combining existing and post-quantum cryptography as a transitional measure.
Solana has pursued a quieter, opt-in approach through the Winternitz Vault, developed by cryptography researcher Dean Little (chief scientist at Zeus Network). The vault implements Winternitz One-Time Signatures (WOTS) using truncated Keccak256 hashing, offering 224-bit preimage resistance — considered robust against Grover's algorithm.
The vault is optional: users must actively choose to store funds in Winternitz vaults to gain quantum protection. The scheme generates new keys for every transaction, eliminating the public key reuse that creates quantum exposure.
However, April 2026 testing revealed a critical performance trade-off: network speed dropped by approximately 90% when processing quantum-resistant signatures. This penalty highlights the fundamental tension across all chains — post-quantum security comes at a direct cost to throughput and transaction economics.
Post-quantum digital signatures are substantially larger than their ECC counterparts. The Coinbase advisory board report noted that replacing current signatures with quantum-proof alternatives could expand block sizes by up to 38 times. Signature sizes range from "tens to hundreds of times larger than current ones," according to the board's assessment.
For Bitcoin, this translates to higher transaction fees and reduced block capacity. For Ethereum, the 250x compression offered by leanVM is designed to mitigate this — but requires a new zkVM infrastructure layer that does not yet exist in production. For Solana, the 90% throughput penalty observed in testing demonstrates the cost in concrete terms.
The signature size problem is not a theoretical concern. It is the primary engineering barrier to post-quantum migration across every major chain.
NIST finalized three post-quantum cryptography standards in 2024:
Under NIST IR 8547, quantum-vulnerable algorithms will be deprecated by 2035. Federal systems face tighter deadlines: new National Security Systems acquisitions must be CNSA 2.0 compliant from January 1, 2027, with full compliance for most system types by 2033.
Google confirmed that Android 17 will integrate ML-DSA for post-quantum digital signature protection, with stable release expected June 2026. The company has set a 2029 deadline for migrating all authentication services to post-quantum cryptography.
The crypto industry operates outside these mandates. No regulatory body currently requires blockchain networks to adopt post-quantum cryptography. Migration is voluntary, community-governed, and subject to the consensus mechanisms of each chain — a process that, in Bitcoin's case, can take years for even non-controversial upgrades.
The 15-bit ECC break is a milestone, not a threat. Lelli's Q-Day Prize result demonstrates measurable progress in quantum attacks on elliptic curves, but credible critics have shown the result is replicable with random number generation at this key size. Current quantum hardware is not performing meaningful cryptanalysis against ECC.
Theoretical resource estimates are falling fast. Google's below-500,000-qubit estimate and Caltech/Oratomic's 10,000-qubit model represent order-of-magnitude reductions from prior consensus. The timeline for a practical 256-bit attack is compressing.
6.9 million BTC have exposed public keys. Approximately one-third of Bitcoin's total supply sits in addresses that would be vulnerable to a sufficiently powerful quantum computer. Bernstein estimates 1.7 million BTC in legacy wallets face concentrated exposure.
Migration proposals are live but contentious. Bitcoin's BIP-360 provides a voluntary quantum-safe output type; BIP-361 would enforce migration by freezing non-compliant coins. Ethereum pursues account-level optionality via native account abstraction. Solana offers opt-in vaults with a 90% speed penalty.
The signature size problem is the binding constraint. Post-quantum signatures are 10–100x larger than ECC equivalents. This directly impacts block capacity, transaction costs, and network throughput across all chains. No production-ready compression solution exists.
No regulatory mandate exists for crypto. NIST standards are finalized, Google targets 2029, and federal systems face 2027–2033 deadlines. Blockchain networks face no external requirement to migrate, leaving the timeline to community governance processes.
The quantum threat to cryptocurrency is real, measurable, and getting closer — but it is not imminent. Current quantum hardware cannot break production ECC keys. The immediate risk is not a sudden "Q-Day" attack but rather a slow migration failure: chains that delay post-quantum preparation may find themselves unable to execute the transition before the threat materializes.
The economic stakes are concentrated. Bitcoin's 6.9 million exposed-key BTC, Satoshi's estimated 1 million untouchable coins, and the broader $2.5 trillion in ECC-secured assets define the upper bound of quantum exposure. The engineering constraints — signature sizes, throughput penalties, and consensus timelines — define the lower bound of how quickly the industry can respond.
The gap between those two bounds is where the actual risk lives. Every month that theoretical qubit requirements fall while production migration stalls, that gap narrows.