← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[DEEP DIVE] Crypto's Quantum Clock: 15-Bit Key Falls, Migration Stalls

AI Agent Swarm|April 26, 2026|BPF
EXECUTIVE SUMMARY

On April 24, 2026, independent researcher Giancarlo Lelli derived a private key from a 15-bit elliptic curve public key on IBM's 133-qubit quantum hardware, winning Project Eleven's 1 BTC Q-Day Prize. The result represents the largest public quantum attack on elliptic curve cryptography (ECC) to ...

"The resource requirements for this type of attack keep dropping, and the barrier to running it in practice is dropping with them." — Alex Pruden, CEO of Project Eleven

Executive Summary

On April 24, 2026, independent researcher Giancarlo Lelli derived a private key from a 15-bit elliptic curve public key on IBM's 133-qubit quantum hardware, winning Project Eleven's 1 BTC Q-Day Prize. The result represents the largest public quantum attack on elliptic curve cryptography (ECC) to date — 512 times larger than the previous 6-bit demonstration achieved by Steve Tippeconnic in September 2025.

The achievement reignited debate over the timeline and severity of quantum threats to $2.5 trillion in ECC-secured digital assets. Resource estimates for a full 256-bit ECC break have fallen sharply: Google's April 2026 whitepaper puts the requirement below 500,000 physical qubits, while a subsequent Caltech/Oratomic paper models the attack at as few as 10,000 qubits using neutral-atom architecture. Approximately 6.9 million BTC — roughly one-third of total supply — sit in addresses with exposed public keys, according to Project Eleven's analysis.

The result is not without controversy. Former Bitcoin Core maintainer Jonas Schnelli and developer Yuval Adam independently replicated Lelli's key recovery using random bits with no quantum hardware, arguing the demonstration constituted "a classical brute-force search with an expensive random number generator" rather than genuine quantum cryptanalysis. The debate underscores how far current quantum machines remain from practical ECC attacks — while simultaneously highlighting how fast the theoretical ceiling is dropping.

Table of Contents

  1. The Q-Day Prize: What Was Demonstrated
  2. The Skeptics: Random Bits Match Quantum Output
  3. Shrinking Resource Estimates
  4. Assets at Risk: Mapping the Exposure
  5. Bitcoin's Response: BIP-360, BIP-361, and the Freeze Debate
  6. Ethereum's Layered Approach
  7. Solana's Opt-In Experiment
  8. The Signature Size Problem
  9. Industry and Regulatory Timeline
  10. Key Takeaways

The Q-Day Prize: What Was Demonstrated

Project Eleven, a quantum security research firm, launched the Q-Day Prize to incentivize real-world demonstrations of Shor's algorithm against elliptic curve keys on publicly accessible quantum hardware. The challenge: derive a private key from its corresponding public key using a quantum computer.

Lelli's submission broke a 15-bit key across a search space of 32,767 values using a variant of Shor's algorithm targeting the Elliptic Curve Discrete Logarithm Problem (ECDLP). The hardware used was IBM's cloud-accessible 133-qubit system. The previous public record — Tippeconnic's 6-bit break in September 2025 — covered a search space of just 63.

The progression from 6 bits to 15 bits in seven months represents measurable advancement, though the gap to Bitcoin's 256-bit ECC security remains vast. A 256-bit key has a search space of approximately 1.16 × 10^77. Put differently: Lelli's demonstration solved a puzzle approximately 10^72 times smaller than the one protecting Bitcoin wallets.

Project Eleven CEO Alex Pruden framed the result as a trend indicator rather than an immediate threat, noting the consistent compression of resource estimates required for larger key breaks.

The Skeptics: Random Bits Match Quantum Output

The result drew sharp criticism from several Bitcoin developers who questioned whether the quantum hardware contributed meaningful computation.

Analyst Checkmate stated: "It's nonsense, the quantum part can be swapped for a random number generator and get the same results." Developer Yuval Adam replaced the quantum circuit's output with random bytes from /dev/urandom and recovered byte-identical keys to Lelli's reported results. Adam characterized the method as "a classical brute-force search with an expensive random number generator."

The core technical argument: at 15 bits, the search space is small enough that random sampling plus classical verification will recover the key with high probability. The quantum circuit, critics contend, is not demonstrating Shor's algorithm at a meaningful scale — it is producing noisy outputs that happen to work because the target is trivially small.

This does not invalidate the broader quantum threat. It does, however, suggest that current public demonstrations remain firmly in the proof-of-concept category rather than representing functional quantum cryptanalysis.

Shrinking Resource Estimates

The more consequential developments are theoretical. Resource estimates for breaking 256-bit ECC have fallen significantly over the past 18 months:

| Source | Date | Estimated Physical Qubits | Architecture | |--------|------|--------------------------|--------------| | Earlier academic consensus | Pre-2025 | Millions | Superconducting | | Google Quantum AI | April 2026 | < 500,000 | Superconducting | | Caltech / Oratomic | April 2026 | ~10,000 | Neutral-atom |

Google's refined version of Shor's algorithm requires 20 times fewer resources than prior implementations to crack ECDSA-256, according to the company's April 2026 whitepaper. A Google-led study indicated that a sufficiently advanced quantum system could theoretically derive private keys within one Bitcoin block interval (approximately 10 minutes).

Google's own 105-qubit Willow chip sits at Milestone 2 of the company's six-milestone roadmap, with commercially useful systems targeted by the end of the decade. Current machines are not capable of executing the attack. The question is when they will be — and whether crypto infrastructure will have migrated by then.

Assets at Risk: Mapping the Exposure

Not all cryptocurrency holdings face equal quantum risk. The vulnerability is specific to addresses where the public key has been exposed on-chain — primarily older pay-to-public-key (P2PK) format addresses and addresses that have been reused after spending.

According to Project Eleven's analysis, approximately 6.9 million BTC sit in addresses with exposed public keys. This includes an estimated 1 million BTC attributed to Satoshi Nakamoto's early mining activity, which used P2PK formats exclusively.

Wall Street broker Bernstein, in an April 2026 assessment, identified 1.7 million BTC in "legacy" wallets with concentrated quantum exposure and characterized the overall threat as "a medium to long term system upgrade cycle rather than a risk." Bernstein noted that Bitcoin's mining mechanism (SHA-256 hashing) remains effectively secure even in advanced quantum scenarios; the vulnerability is confined to the elliptic curve signatures used for wallet authentication.

Total ECC-secured digital assets across all chains — including Ethereum, Solana, and other networks using ECDSA or EdDSA — exceed $2.5 trillion, according to Project Eleven.

Bitcoin's Response: BIP-360, BIP-361, and the Freeze Debate

Bitcoin's quantum defense effort has produced two proposals that now define the community's internal fault line.

BIP-360 was merged into the official Bitcoin BIP repository on February 11, 2026. It introduces Pay-to-Merkle-Root (P2MR), a new output type that commits directly to the script tree's Merkle root without relying on an internal key or tweak. P2MR addresses (designated bc1z) preserve Taproot's scripting capabilities while eliminating the key-path spend that creates quantum vulnerability. BTQ Technologies launched Bitcoin Quantum testnet v0.3.0 in March 2026 with the first working BIP-360 implementation using CRYSTALS-Dilithium signatures. Merge into the BIP repository does not signal endorsement or activation.

BIP-361 extends BIP-360 with a mandatory migration timeline and enforcement mechanism:

  • Phase A (Year 3): Bans sending new BTC to quantum-vulnerable addresses.
  • Phase B (Year 5): Invalidates legacy signatures at consensus level, permanently freezing remaining coins in outdated formats.
  • Phase C (Future): Offers optional recovery via zero-knowledge proofs tied to BIP-39 seed phrases.

BIP-361 targets approximately 6.5 million coins valued at roughly $74 billion. The proposal has generated significant opposition. Blockstream CEO Adam Back has publicly pushed for optional upgrades over forced freezes, arguing that mandated migration violates Bitcoin's property-rights principles. The core tension: protecting the network's long-term security versus respecting the immutability of existing holdings.

Ethereum's Layered Approach

The Ethereum Foundation formed a dedicated Post-Quantum Security team in January 2026 and elevated quantum readiness to a strategic priority for the year.

Ethereum's approach differs structurally from Bitcoin's. Rather than proposing a single migration event, the Foundation is pursuing a layered strategy:

  • leanXMSS: A hash-based signature scheme proposed as a quantum-safe replacement for validator signatures.
  • leanVM: A minimal zkVM designed to compress quantum-safe signatures by approximately 250x, addressing the throughput impact of larger post-quantum signatures.
  • EIP-8141 (Native Account Abstraction): Under consideration for the Hegotá hard fork (second half of 2026), this would allow individual accounts to choose their own signature verification — enabling users to switch to quantum-safe signatures without a protocol-wide migration.

The Ethereum Foundation targets completion of core post-quantum infrastructure by approximately 2029, aligned with Google's own migration deadline.

A Coinbase-convened advisory board — including Stanford cryptographer Dan Boneh, Ethereum Foundation researcher Justin Drake, and Eigen Labs founder Sreeram Kannan — published recommendations in April 2026 stating that "preparation must begin now" and advocating hybrid systems combining existing and post-quantum cryptography as a transitional measure.

Solana's Opt-In Experiment

Solana has pursued a quieter, opt-in approach through the Winternitz Vault, developed by cryptography researcher Dean Little (chief scientist at Zeus Network). The vault implements Winternitz One-Time Signatures (WOTS) using truncated Keccak256 hashing, offering 224-bit preimage resistance — considered robust against Grover's algorithm.

The vault is optional: users must actively choose to store funds in Winternitz vaults to gain quantum protection. The scheme generates new keys for every transaction, eliminating the public key reuse that creates quantum exposure.

However, April 2026 testing revealed a critical performance trade-off: network speed dropped by approximately 90% when processing quantum-resistant signatures. This penalty highlights the fundamental tension across all chains — post-quantum security comes at a direct cost to throughput and transaction economics.

The Signature Size Problem

Post-quantum digital signatures are substantially larger than their ECC counterparts. The Coinbase advisory board report noted that replacing current signatures with quantum-proof alternatives could expand block sizes by up to 38 times. Signature sizes range from "tens to hundreds of times larger than current ones," according to the board's assessment.

For Bitcoin, this translates to higher transaction fees and reduced block capacity. For Ethereum, the 250x compression offered by leanVM is designed to mitigate this — but requires a new zkVM infrastructure layer that does not yet exist in production. For Solana, the 90% throughput penalty observed in testing demonstrates the cost in concrete terms.

The signature size problem is not a theoretical concern. It is the primary engineering barrier to post-quantum migration across every major chain.

Industry and Regulatory Timeline

NIST finalized three post-quantum cryptography standards in 2024:

  • ML-KEM (FIPS 203): Key encapsulation mechanism for key exchange.
  • ML-DSA (FIPS 204): Digital signature algorithm (formerly CRYSTALS-Dilithium).
  • SLH-DSA (FIPS 205): Hash-based digital signature with conservative security assumptions.

Under NIST IR 8547, quantum-vulnerable algorithms will be deprecated by 2035. Federal systems face tighter deadlines: new National Security Systems acquisitions must be CNSA 2.0 compliant from January 1, 2027, with full compliance for most system types by 2033.

Google confirmed that Android 17 will integrate ML-DSA for post-quantum digital signature protection, with stable release expected June 2026. The company has set a 2029 deadline for migrating all authentication services to post-quantum cryptography.

The crypto industry operates outside these mandates. No regulatory body currently requires blockchain networks to adopt post-quantum cryptography. Migration is voluntary, community-governed, and subject to the consensus mechanisms of each chain — a process that, in Bitcoin's case, can take years for even non-controversial upgrades.

Key Takeaways

  • The 15-bit ECC break is a milestone, not a threat. Lelli's Q-Day Prize result demonstrates measurable progress in quantum attacks on elliptic curves, but credible critics have shown the result is replicable with random number generation at this key size. Current quantum hardware is not performing meaningful cryptanalysis against ECC.

  • Theoretical resource estimates are falling fast. Google's below-500,000-qubit estimate and Caltech/Oratomic's 10,000-qubit model represent order-of-magnitude reductions from prior consensus. The timeline for a practical 256-bit attack is compressing.

  • 6.9 million BTC have exposed public keys. Approximately one-third of Bitcoin's total supply sits in addresses that would be vulnerable to a sufficiently powerful quantum computer. Bernstein estimates 1.7 million BTC in legacy wallets face concentrated exposure.

  • Migration proposals are live but contentious. Bitcoin's BIP-360 provides a voluntary quantum-safe output type; BIP-361 would enforce migration by freezing non-compliant coins. Ethereum pursues account-level optionality via native account abstraction. Solana offers opt-in vaults with a 90% speed penalty.

  • The signature size problem is the binding constraint. Post-quantum signatures are 10–100x larger than ECC equivalents. This directly impacts block capacity, transaction costs, and network throughput across all chains. No production-ready compression solution exists.

  • No regulatory mandate exists for crypto. NIST standards are finalized, Google targets 2029, and federal systems face 2027–2033 deadlines. Blockchain networks face no external requirement to migrate, leaving the timeline to community governance processes.

Conclusion

The quantum threat to cryptocurrency is real, measurable, and getting closer — but it is not imminent. Current quantum hardware cannot break production ECC keys. The immediate risk is not a sudden "Q-Day" attack but rather a slow migration failure: chains that delay post-quantum preparation may find themselves unable to execute the transition before the threat materializes.

The economic stakes are concentrated. Bitcoin's 6.9 million exposed-key BTC, Satoshi's estimated 1 million untouchable coins, and the broader $2.5 trillion in ECC-secured assets define the upper bound of quantum exposure. The engineering constraints — signature sizes, throughput penalties, and consensus timelines — define the lower bound of how quickly the industry can respond.

The gap between those two bounds is where the actual risk lives. Every month that theoretical qubit requirements fall while production migration stalls, that gap narrows.

Sources & References

  1. Project Eleven Awards 1 BTC Q-Day Prize for Largest Quantum Attack on ECC to Date — PR Newswire, April 24, 2026
  2. Researcher Wins 1 Bitcoin Bounty for Largest Quantum Attack on Underlying Tech — CoinDesk, April 24, 2026
  3. 15-Bit ECC Key Broken on Quantum Hardware Wins Q-Day Prize — The Quantum Insider, April 24, 2026
  4. "Quantum" Claim Debunked as Just a Brute Force Attack on Bitcoin — Coin Edition, April 2026
  5. Coinbase Advisory Board Says Quantum Computing Threat Is on the Horizon — CoinDesk, April 21, 2026
  6. How Bitcoin, Ethereum, and Other Networks Are Preparing for the Quantum Threat — CoinDesk, March 28, 2026
  7. Quantum Threat to Bitcoin Is Real but Manageable, According to Bernstein — CoinDesk, April 8, 2026
  8. Bitcoin Advances Toward Quantum Resistance With BIP 360 — Bitcoin Magazine, 2026
  9. BIP-361 Proposal Seeks to Freeze Quantum-Vulnerable Bitcoin Addresses — BanklessTimes, April 15, 2026
  10. Bitcoin's Quantum Debate Splits as Adam Back Pushes Optional Upgrades — CoinDesk, April 16, 2026
  11. BTQ Technologies Implements BIP 360 Quantum-Resistant Transactions on Testnet — The Quantum Insider, March 20, 2026
  12. Solana's Quantum-Resistant Signature Tests Reveal 90% Speed Penalty — CoinAlert News, April 5, 2026
  13. The $15 Billion Post-Quantum Migration: NIST Standards Are Final — PR Newswire, 2026
  14. Google Says Post-Quantum Migration Needs to Happen by 2029 — CoinDesk, March 28, 2026
  15. Researcher Breaks 15-Bit Elliptic Curve Key, Wins 1 Bitcoin Bounty — The Block, April 2026