Google Quantum AI published a 57-page whitepaper on March 31, 2026, demonstrating that the quantum resources required to break the 256-bit elliptic curve cryptography (ECC) protecting Bitcoin, Ethereum, and most major blockchains are roughly 20 times smaller than prior estimates. The paper presen...
"It is extremely dangerous to rush cryptography; most NIST PQ candidates were broken or rejected." — Adam Back, CEO, Blockstream
Google Quantum AI published a 57-page whitepaper on March 31, 2026, demonstrating that the quantum resources required to break the 256-bit elliptic curve cryptography (ECC) protecting Bitcoin, Ethereum, and most major blockchains are roughly 20 times smaller than prior estimates. The paper presents two compiled quantum circuits: one requiring fewer than 1,200 logical qubits and 90 million Toffoli gates, and another requiring fewer than 1,450 logical qubits and 70 million Toffoli gates. Both are estimated to be executable in minutes on a superconducting quantum processor with under 500,000 physical qubits.
The implications are concrete: approximately 6.9 million BTC — one-third of total supply, valued at roughly $600 billion at current prices — sit in wallets where public keys are already exposed on-chain. These coins could be targeted at leisure by a sufficiently powerful quantum computer. For in-flight transactions, an attacker could derive a private key from an exposed public key in approximately nine minutes, yielding a 41% probability of beating Bitcoin's 10-minute block confirmation window.
The crypto industry's response has been immediate but fragmented. Bitcoin developers are debating BIP-360 (Pay-to-Merkle-Root), Ethereum's Vitalik Buterin has outlined a four-year post-quantum migration roadmap, quantum-resistant tokens have surged past $9 billion in combined market capitalization, and Naoris Protocol launched the first NIST-approved post-quantum Layer 1 mainnet on April 1, 2026.
The paper, titled "Safeguarding Cryptocurrency by Disclosing Quantum Vulnerabilities Responsibly," was authored by Ryan Babbush (Director of Research, Quantum Algorithms) and Hartmut Neven (VP Engineering) at Google Quantum AI. It reduces the estimated physical qubit requirement for breaking ECC from millions to fewer than 500,000 — a threshold that multiple hardware roadmaps now target within the 2029-2031 window.
Previous estimates placed the requirement at 10-20 million physical qubits. Google's optimization collapses this by roughly an order of magnitude through improved quantum circuit compilation and error correction techniques. The paper does not claim such a machine exists today. Google's own Willow chip, announced in December 2024, operates at 105 qubits with a coherence time of 100 microseconds. The gap between 105 and 500,000 qubits remains substantial, but the trajectory matters more than the snapshot.
Google has separately set a 2029 deadline to migrate its own authentication services to post-quantum cryptography, according to CoinDesk reporting from March 28, 2026. The company's internal migration timeline serves as a practical signal of how its own researchers assess the urgency.
The paper identifies approximately 6.9 million BTC with exposed public keys on the Bitcoin blockchain. This exposure comes from three sources:
These 6.9 million coins do not require the nine-minute race against block confirmation. An attacker with a sufficiently powerful quantum computer could work through these exposed keys without time pressure, according to analysis by SpendNode published April 1, 2026.
For the remaining coins in hash-protected addresses, the attack window is narrower. A quantum computer would need to derive the private key from the public key exposed during a spending transaction, before the transaction confirms. The Google paper estimates this at approximately nine minutes, yielding a 41% success probability against Bitcoin's roughly 10-minute average block time.
Taproot, activated in November 2021, was designed to improve Bitcoin's privacy and scripting efficiency. It introduced Schnorr signatures and Merkelized Abstract Syntax Trees (MAST). However, the P2TR output format stores the tweaked public key directly on-chain — a design choice that removes the hash layer present in older address formats like P2PKH and P2SH.
According to Google's researchers, this constitutes a "security regression" from a quantum perspective. The public key visibility in P2TR widens the pool of wallets vulnerable to offline quantum attacks, where no time race against confirmation is needed.
The irony is structural: an upgrade designed to improve Bitcoin's technical sophistication inadvertently expanded its quantum attack surface. According to CoinDesk reporting from March 31, 2026, the finding has prompted renewed debate about the trade-offs embedded in Bitcoin's upgrade history.
In a move described as unprecedented in quantum cryptanalysis, Google withheld the compiled attack circuits and instead published a zero-knowledge proof — constructed using SP1 zkVM and Groth16 SNARK — that allows third parties to verify the resource estimates without accessing the underlying attack details.
The disclosure was coordinated with the U.S. government, Coinbase, the Stanford Institute for Blockchain Research, and the Ethereum Foundation, according to Google's research blog. This model sets a new precedent: the cryptographic community can validate the threat without the research itself becoming an exploit blueprint.
BIP-360, co-authored by Hunter Beast, Ethan Heilman, and Isabel Foxen Duke, introduces Pay-to-Merkle-Root (P2MR) — a new output type that removes the public key from permanent on-chain storage. Additional proposals include adopting NIST-approved hash-based signatures like SPHINCS+ and implementing commit/reveal schemes to shield mempool transactions from quantum observation.
Blockstream CEO Adam Back, in an April 5 statement, advocated a phased approach. Back argued that Taproot already embeds quantum-ready features via "tapleaf" mechanisms designed for future compatibility with post-quantum cryptography. He cautioned against hasty adoption, noting that multiple NIST post-quantum candidates have been broken or rejected during the standardization process.
The community is divided on urgency. Charles Edwards has argued for 2026 deployment with penalties for coins that fail to migrate by 2028, according to Cointelegraph. Others, including Samson Mow, maintain the quantum threat is not imminent enough to justify forced migration timelines.
A separate proposal, Hourglass V2, would slow the spending of approximately 1.7 million legacy P2PK bitcoins — including Satoshi's estimated holdings — to prevent a quantum attacker from draining them before the network upgrades. Any such change would require broad consensus in Bitcoin's decentralized governance, where protocol modifications notoriously move slowly.
Project Eleven, a post-quantum security firm that raised $20 million in Series A at a $120 million valuation, has been working with Layer 1 protocols on quantum readiness, according to CoinDesk's April 4 reporting on what it termed Bitcoin's "$1.3 trillion security race."
Vitalik Buterin published a post-quantum roadmap in late February 2026, identifying four vulnerable Ethereum components: consensus-layer BLS signatures, KZG-based data availability, ECDSA account signatures, and zero-knowledge proofs.
The plan, called "Strawmap," outlines seven forks over four years with full post-quantum activation before 2030. Immediate priorities include EIP-8141, which would allow Ethereum wallets to switch signature schemes, and "frame transactions," a new transaction type supporting account abstraction with post-quantum signatures. Buterin has voiced support for including frame transactions in the Hegota upgrade, expected in the second half of 2026.
The Ethereum Foundation has established a dedicated Post-Quantum Security team to oversee the phased migration, according to reporting from DLNews. The approach contrasts with Bitcoin's governance model — Ethereum's more centralized upgrade coordination may allow faster response, though it introduces different trust assumptions.
The quantum-resistant crypto sector surpassed $9 billion in combined market capitalization in April 2026, with daily trading volumes exceeding $1.5 billion, according to BeInCrypto.
Notable price movements following the Google paper:
| Token | Move | Market Cap | |-------|------|-----------| | QRL (Quantum Resistant Ledger) | +51.4% to $1.70 | ~$127M | | Cellframe (CEL) | +40% | — | | Zcash (ZEC) | Included in $9B sector | — | | Starknet (STRK) | Included in $9B sector | — |
QRL, built on XMSS (eXtended Merkle Signature Scheme) since its 2018 genesis, uses NIST-approved hash-based signatures as its foundational architecture. QANplatform and Hedera have implemented CRYSTALS-Dilithium. Algorand activated Falcon-1024 on mainnet in November 2025.
Naoris Protocol launched its post-quantum Layer 1 mainnet on April 1, 2026, using NIST-approved algorithms. The protocol has processed over 106 million transactions in testing and implements an "irreversible security transition" — once a user adopts post-quantum keys, the system blocks traditional signature methods. At press time, Naoris's market cap was $36 million.
"Q-Day" — the point at which a quantum computer can break production cryptography — remains a moving target. Key data points:
The mismatch is notable: Google's own 2029 migration deadline suggests the company views the threat as potentially material within three years. Bitcoin's governance process may require a similar timeline just for a single soft fork. If the quantum threat materializes on the earlier end of estimates, the window for orderly migration narrows significantly.
The Google paper does not mean Bitcoin or Ethereum are broken today. No quantum computer with 500,000 physical qubits exists, and the gap between current hardware (105 qubits) and that threshold is substantial. What the paper does is compress the estimated timeline and resource requirements, converting a theoretical concern into an engineering problem with identifiable parameters.
The economic value at stake — $600 billion in exposed BTC alone, before accounting for Ethereum and other ECC-dependent chains — demands coordinated response. The value distribution question central to blockchain economics now includes a new variable: the cost and speed of cryptographic migration. Projects that can demonstrate quantum resilience may capture a security premium. Those that cannot migrate in time face existential risk to their value propositions.
The core tension is governance speed versus threat velocity. Bitcoin's decentralized upgrade process, which has historically prioritized caution over speed, now faces a scenario where caution itself may become the risk. Ethereum's more directed governance may allow faster response but introduces centralization trade-offs that are, in their own way, antithetical to the system's design goals.
The data is clear on the direction. The timeline remains debatable. What is not debatable is that the cryptographic foundations of every major blockchain are now operating on a finite, measurable clock.