Google Quantum AI published research on March 31, 2026, demonstrating that breaking the 256-bit elliptic curve cryptography protecting Bitcoin and Ethereum requires fewer than 500,000 physical qubits — a 20-fold reduction from previous estimates. The two compiled circuits execute Shor's algorithm...
"Breaking cryptography is one of the easier applications for quantum computing, because it's very numeric." — John M. Martinis, 2025 Nobel Laureate in Physics, CTO of Qolab
Google Quantum AI published research on March 31, 2026, demonstrating that breaking the 256-bit elliptic curve cryptography protecting Bitcoin and Ethereum requires fewer than 500,000 physical qubits — a 20-fold reduction from previous estimates. The two compiled circuits execute Shor's algorithm for ECDLP-256 in approximately nine minutes using 90 million and 70 million Toffoli gates, respectively. Google has set a 2029 internal deadline for migrating its own authentication services to post-quantum cryptography, signaling the company's assessment of the threat's proximity.
The implications are concrete: 6.5 million BTC sit in addresses with exposed public keys, 1.7 million BTC occupy legacy P2PK wallets with no existing migration path, and Ethereum's architecture exposes public keys permanently once a user transacts. Four competing defense proposals for Bitcoin and three major Ethereum initiatives remain unactivated. No major blockchain has completed a post-quantum migration on mainnet.
Google Quantum AI's paper, published March 31, 2026, compiled two quantum circuits implementing Shor's algorithm against ECDLP-256 — the elliptic curve discrete logarithm problem underpinning Bitcoin, Ethereum, and most public blockchains. Key parameters:
| Metric | Circuit 1 | Circuit 2 | |--------|-----------|-----------| | Logical qubits | ~1,450 | ~1,200 | | Physical qubits | <500,000 | <500,000 | | Toffoli gates | 90 million | 70 million | | Execution time | Minutes | Minutes |
Previous academic estimates placed the physical qubit requirement in the millions. Google's 20-fold reduction moves the threat window from "theoretical" to "engineering challenge." Google's own Willow quantum processor, while not yet at this scale, represents the company's active pursuit of fault-tolerant quantum hardware.
Nobel Laureate John Martinis, former Google quantum hardware lead and current CTO of Qolab, endorsed the findings and estimated quantum computers capable of attacking ECDSA-256 could emerge within five to ten years. He characterized this timeline as uncertain but urged the blockchain industry to begin planning immediately, noting that decentralized networks upgrade far more slowly than centralized systems such as banks.
Bernstein analyst Gautam Chhugani, in an April 8 research note, characterized the quantum threat as "a medium to long term system upgrade cycle rather than a risk," estimating a three-to-five-year transition window for the industry.
Bitcoin's $1.3 trillion market capitalization rests on ECDSA-256 signatures. The vulnerability is not uniform:
Google's paper identified five distinct quantum attack vectors against Ethereum:
Exposed wallet keys. Ethereum public keys become permanently visible once a user transacts (unlike Bitcoin's hashed addresses). The top 1,000 wallets hold approximately 20.5 million ETH. A quantum computer cracking one key every nine minutes could compromise all 1,000 wallets in under nine days.
Smart contract admin keys. At least 70 major smart contracts with exposed administrator keys control approximately 2.5 million ETH directly and govern minting authority for stablecoins including USDT and USDC — roughly $200 billion in assets.
Layer 2 dependencies. Approximately 15 million ETH across Arbitrum, Optimism, and other L2 networks inherits Ethereum's quantum-vulnerable cryptography. StarkNet is an exception: its hash-function-based mathematics does not rely on elliptic curves.
Validator compromise. The 37 million ETH staked through proof-of-stake validators uses vulnerable digital signatures. Compromising one-third of validators prevents finalization; two-thirds enables chain rewriting. Lido's roughly 20% concentration presents a single point of failure.
Data availability sampling. Ethereum's blob data system depends on a one-time KZG setup ceremony that generated a secret number. Quantum computers could recover this secret, creating a permanent exploit tool usable without ongoing quantum access — and, according to Google, "potentially tradable" across all dependent L2s.
Solana faces the most acute architectural vulnerability. Unlike Bitcoin and Ethereum, which derive wallet addresses from hashed public keys, Solana exposes public keys directly. Alex Pruden, CEO of Project Eleven and former Coinbase/a16z veteran, confirmed in April 2026 testing: "100% of the network is vulnerable." An attacker could target any wallet without waiting for a transaction to expose the key.
Testing by the Solana Foundation and Project Eleven revealed that quantum-safe signatures are 20 to 40 times larger than current signatures, and a Solana testnet running post-quantum cryptography operated approximately 90% slower — a direct conflict with the network's throughput-first design.
Four proposals are under active development. None have been activated.
BIP 360 (Pay-to-Merkle-Root). Removes permanently exposed public keys by committing directly to the script tree's Merkle root. BTQ Technologies launched Bitcoin Quantum testnet v0.3.0 in March 2026 with the first working BIP 360 implementation using Dilithium signatures. Over 50 miners joined the testnet. Polymarket traders assign a 28% probability that BIP 360 is implemented by 2027.
SPHINCS+ / SLH-DSA. Hash-based post-quantum signatures standardized by NIST as FIPS 205. The tradeoff: signatures expand from 64 bytes to 8 kilobytes, increasing block space demand by roughly 125x per signature.
Commit/Reveal Scheme. Proposed by Lightning Network co-creator Tadge Dryja. Separates transactions into two phases with timestamps that reject quantum-forged competing transactions. Functions as an interim bridge.
QSB (Quantum Safe Bitcoin). Published April 10 by StarkWare researcher Avihu Levy. Operates entirely within Bitcoin's existing consensus rules — no soft fork required. Replaces signature-based security with hash-based proofs using GPU computation. Estimated cost: $75 to $200 per transaction, versus $0.33 for standard transactions — a 200x to 600x premium. Levy described it as "a last resort measure."
Blockstream CEO Adam Back advocated a phased approach on April 5, emphasizing that Bitcoin's existing Taproot design already embeds quantum-ready features through its tapleaf structure. He cited a 20-person team conducting post-quantum experiments on Blockstream's Liquid network and urged developers to give users approximately a decade to migrate.
Lightning Labs CTO Olaoluwa Osuntokun unveiled a prototype quantum-resistant wallet rescue tool on April 8. Performance: proof generation in ~55 seconds, verification in under 2 seconds, proof file size of 1.7 MB. No formal deployment proposal exists.
Vitalik Buterin published Ethereum's quantum resistance roadmap on February 26, 2026, as part of the four-year Strawmap. He identified four vulnerable components: consensus-layer BLS signatures, KZG commitments for data availability, ECDSA signatures for externally owned accounts, and Groth16 zero-knowledge proofs.
The proposed solution replaces vulnerable systems with hash-based or lattice-based quantum-resistant alternatives, supported by recursive STARK aggregation. EIP-8141 would allow accounts to migrate to different signature types without forcing wallet changes. The cost challenge is significant: ECDSA verification costs approximately 3,000 gas, while quantum-resistant checks may reach 200,000 gas — a 67x increase.
The Ethereum Foundation targets quantum-resistant upgrades by 2029, with Glamsterdam and Hegotá forks confirmed for 2026.
The technical solutions exist. The governance problem does not have a clear resolution.
Banks can migrate cryptographic infrastructure unilaterally — a CTO signs off, IT implements, users notice nothing. Public blockchains operate under consensus mechanisms that require buy-in from developers, miners or validators, node operators, exchanges, and wallet providers. Bitcoin's last major upgrade, Taproot, took four years from proposal to activation (2017-2021).
Adam Back's estimate of a decade-long migration window for Bitcoin users may be realistic from a social coordination standpoint but leaves limited margin against Google's 2029 internal migration deadline. Ethereum's seven-fork, four-year Strawmap represents the most structured timeline among major chains but depends on each deployed smart contract and bridge independently upgrading — a coordination challenge with no centralized enforcement mechanism.
Pruden summarized the dilemma: "This is a tomorrow problem — until it's today's problem. And then it takes four years to fix."
Naoris Protocol launched on April 1, 2026, as the first Layer 1 network built entirely on NIST-approved post-quantum cryptography. The network uses the ML-DSA algorithm (FIPS 204, based on CRYSTALS-Dilithium) for all transaction signatures.
Key metrics from the testnet phase: over 106 million post-quantum transactions validated, 603 million security threats mitigated, and more than one million security nodes activated. The protocol enforces an "irreversible security transition" — once a user adopts post-quantum keys, classical cryptographic methods are permanently blocked.
Naoris demonstrates that post-quantum blockchain operation is technically feasible. The open question is whether networks with hundreds of billions of dollars in existing value can migrate without breaking backward compatibility or fragmenting their user base.
The quantum threat to blockchain infrastructure has shifted from speculative to quantifiable. Google's March 31 paper provides specific qubit counts, gate counts, and execution times. The question is no longer whether quantum computers can break blockchain cryptography but when — and whether decentralized governance can respond quickly enough.
The economic value at stake — $1.3 trillion in Bitcoin alone, over $100 billion in Ethereum-adjacent assets — creates an asymmetric risk profile. Migration costs are high and technically complex. Inaction carries existential consequences. The blockchain industry faces a coordination problem that no amount of cryptographic research can solve: convincing millions of independent actors to upgrade their infrastructure before a threat materializes.
The migration clock is running. No consensus on when it expires has been reached.