← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[DEEP DIVE] Google Cuts Quantum Crypto-Break Estimate to 500K Qubits

Zephyra|April 11, 2026|BPF
EXECUTIVE SUMMARY

Three research papers published between January and March 2026 have compressed the estimated quantum resource requirements for breaking elliptic curve cryptography by roughly 20x. Google Quantum AI's March 30 whitepaper demonstrates that Shor's algorithm can solve ECDLP-256 — the mathematical pro...

"We give at least a 10 percent chance that a quantum computer recovers a secp256k1 private key from an exposed public key by 2032." — Justin Drake, Ethereum Foundation Researcher

Executive Summary

Three research papers published between January and March 2026 have compressed the estimated quantum resource requirements for breaking elliptic curve cryptography by roughly 20x. Google Quantum AI's March 30 whitepaper demonstrates that Shor's algorithm can solve ECDLP-256 — the mathematical problem protecting every Bitcoin and Ethereum wallet — with fewer than 500,000 physical qubits, down from prior estimates exceeding 10 million. Google has set an internal deadline of 2029 for migrating its own authentication systems to post-quantum standards.

The blockchain industry's response is bifurcated. Ethereum has committed engineering resources, $2 million in bounties, and a multi-fork roadmap targeting full post-quantum security by 2029. Bitcoin has no coordinated plan, no funding structure, and no agreed timeline. Approximately 6.26 million BTC — roughly $650 billion at current prices — sit in addresses with exposed public keys, immediately vulnerable should a cryptographically relevant quantum computer (CRQC) come online. Meanwhile, Citi estimates a Q-Day attack on the U.S. financial system could trigger $2 trillion to $3.3 trillion in indirect economic losses.

Table of Contents

  1. The March Papers: A 20x Resource Reduction
  2. What Is at Stake: $650 Billion in Exposed Bitcoin
  3. Ethereum's Engineering Response
  4. Bitcoin's Governance Gap
  5. Solana's Speed-Security Tradeoff
  6. Naoris Protocol: First Post-Quantum L1 in Production
  7. The Harvest-Now-Decrypt-Later Problem
  8. NIST Standards and Regulatory Timelines
  9. Key Takeaways
  10. Conclusion

The March Papers: A 20x Resource Reduction

Between January and March 2026, three separate research efforts tightened the quantum threat timeline more than any development since Peter Shor published his factoring algorithm in 1994, according to The Quantum Insider.

The most significant was the Google Quantum AI whitepaper published March 30, co-authored by Ryan Babbush, Craig Gidney, and Hartmut Neven of Google, Justin Drake of the Ethereum Foundation, and Dan Boneh of Stanford University. The paper presented two quantum circuits implementing Shor's algorithm for ECDLP-256:

  • Circuit A: Fewer than 1,200 logical qubits, 90 million Toffoli gates
  • Circuit B: Fewer than 1,450 logical qubits, 70 million Toffoli gates

Both circuits can be executed on a superconducting qubit CRQC with fewer than 500,000 physical qubits in a matter of minutes, according to the paper. This represents a roughly 10x reduction in spacetime volume — the product of logical qubits and gate count — over the best previously published work, and approximately a 20x reduction in physical qubit requirements.

For context, IBM's Heron processor, released in late 2024, operates at 156 qubits. Google's Willow chip, announced in December 2024, runs 105 qubits. The gap between current hardware and the 500,000-qubit threshold remains large, but the trajectory is compressing. Google has set 2029 as its internal deadline for post-quantum migration across all authentication services.

What Is at Stake: $650 Billion in Exposed Bitcoin

The financial exposure is concentrated in addresses where public keys are already visible on-chain. According to research cited by Project Eleven, more than 10 million Bitcoin addresses have exposed their public keys through prior spending activity. Approximately 6.26 million BTC — roughly $650 billion — sit in these addresses.

A subset of this exposure is particularly acute: Bitcoin's early Pay-to-Public-Key (P2PK) addresses, used by Satoshi Nakamoto and early miners, broadcast the full public key directly. An estimated 1.72 million BTC remain in these legacy formats. A quantum attacker capable of deriving private keys from public keys would have access to these funds without any additional steps.

Citi's January 2026 report, "Quantum Threat: The Trillion-Dollar Security Race Is On," estimated that roughly 25% of all Bitcoin is quantum-exposed due to address formats and key-reuse patterns. The report further estimated that a one-day disruption to a top-five U.S. bank's access to the Fedwire Funds Service — a scenario a CRQC could enable — could generate $2 trillion to $3.3 trillion in indirect economic losses, equivalent to 10% to 17% of U.S. GDP.

Project Eleven launched the Q-Day Prize in early 2026, offering 1 BTC to the first team to break a toy version of Bitcoin's ECC key (1-25 bits) using Shor's algorithm on an actual quantum computer. The deadline was April 5, 2026. The challenge was designed less as a bounty and more as a diagnostic tool to measure how close current quantum hardware is to the threshold.

Ethereum's Engineering Response

The Ethereum Foundation elevated post-quantum security to its top strategic priority in January 2026, forming a dedicated Post Quantum team led by Thomas Coratger. The effort is backed by eight years of cryptographic research and has moved from background study to active engineering.

Key components of Ethereum's response:

  • Multi-fork roadmap targeting full post-quantum security by 2029
  • Biweekly developer sessions on post-quantum transactions
  • Multi-client post-quantum consensus test networks shipping weekly across roughly ten client teams
  • $1 million Poseidon Prize to strengthen the Poseidon hash function
  • $1 million Proximity Prize advancing post-quantum cryptographic research
  • Justin Drake's co-authorship of the Google paper, embedding Ethereum's team directly in the frontier research

Drake's stated completion date for Ethereum being fully post-quantum secure is 2029, matching Google's own internal timeline. The approach involves multiple hard forks that would replace the network's current signature schemes with NIST-approved post-quantum alternatives.

Bitcoin's Governance Gap

Bitcoin's response stands in sharp contrast. According to CoinDesk, Bitcoin has no coordinated plan, no centralized funding structure, and no agreed-upon timeline for post-quantum migration. The decentralized governance model that gives Bitcoin its censorship resistance also makes coordinated protocol upgrades significantly slower.

Several proposals are in circulation:

  • QRAMP (Quantum-Resistant Address Migration Protocol): Would enforce a network-wide migration from legacy wallets to quantum-safe formats. Developer consensus is skeptical; critics argue it would effectively void a non-trivial portion of the coin supply, particularly funds in lost wallets.
  • BIP 360 (Pay-to-Merkle-Root / P2MR): Proposes a new output type that removes the public key from the blockchain entirely, eliminating the target for quantum attacks on new coins.
  • Commit/reveal schemes: Would shield mempool transactions by concealing public keys until confirmation.

Adam Back, CEO of Blockstream, has advocated a phased approach, citing existing Taproot defenses as a partial mitigation. However, Taproot addresses still expose public keys upon spending.

The fundamental challenge: migration of Bitcoin's infrastructure — user wallets, exchange support, new address formats — could take 5 to 10 years even after a solution is agreed upon, according to Chaincode Labs. With quantum threats potentially arriving by 2029-2033, the window for action is narrow.

Solana's Speed-Security Tradeoff

Solana occupies an intermediate position. In December 2025, the Solana Foundation partnered with Project Eleven to launch a public testnet replacing every Ed25519 signature with CRYSTALS-Dilithium, a NIST-approved lattice-based scheme. The results exposed a harsh tradeoff: quantum-safe signatures are up to 40x larger and reduced network throughput by approximately 90%, according to CoinDesk.

Separately, the Winternitz Vault — introduced by developer Dean Little in January 2025 — offers wallet-level protection using hash-based one-time signatures that are resistant to Shor's algorithm. This provides an opt-in defense for individual users but does not address protocol-level vulnerability.

The Solana case illustrates the performance penalty that post-quantum migration imposes on high-throughput chains. Any network processing thousands of transactions per second will face similar bandwidth and computational constraints when adopting larger signature schemes.

Naoris Protocol: First Post-Quantum L1 in Production

Naoris Protocol launched its mainnet on April 1, 2026, becoming the first Layer 1 blockchain built from genesis with NIST-approved post-quantum cryptography. The network runs on ML-DSA (the standardized version of CRYSTALS-Dilithium, published as FIPS 204) for all transaction signatures.

Key metrics from the testnet period:

  • 603 million threats detected and mitigated
  • 106 million post-quantum transactions processed
  • 3.3 million wallets created
  • More than 1 million security nodes activated globally

Access is currently restricted to an invite-only group of strategic partners, investors, and validator operators. The SEC cited Naoris in a September 2025 research submission as a reference model for its Post-Quantum Financial Infrastructure Framework (PQFIF).

The protocol operates at what it calls the "Sub-Zero Layer," using a Decentralized Proof of Security (dPoSec) consensus model. Whether it can achieve the throughput and adoption necessary to compete with established L1s remains to be seen.

The Harvest-Now-Decrypt-Later Problem

The quantum threat is not exclusively forward-looking. "Harvest now, decrypt later" (HNDL) attacks — where adversaries record encrypted data today for decryption once quantum computers are available — are already underway, according to Citi.

For blockchain networks, HNDL has a specific application: every transaction that has ever exposed a public key on-chain is permanently recorded. An adversary with a future CRQC would not need to intercept anything in real time — the data is already public and immutable. This makes blockchain particularly vulnerable compared to traditional encrypted communications, which can at least be rotated or deleted.

The implication is that migration timelines should be measured not from when CRQCs arrive, but from when data was first exposed. For Bitcoin, that window opened in January 2009.

NIST Standards and Regulatory Timelines

NIST finalized three post-quantum cryptographic standards in August 2024:

| Standard | Algorithm | Type | |----------|-----------|------| | FIPS 203 (ML-KEM) | CRYSTALS-Kyber | Key Encapsulation | | FIPS 204 (ML-DSA) | CRYSTALS-Dilithium | Digital Signatures | | FIPS 205 (SLH-DSA) | SPHINCS+ | Hash-Based Signatures |

NIST's deprecation timeline (IR 8547) calls for quantum-vulnerable algorithms — including RSA-2048 and ECDSA with P-256 — to be deprecated after 2030 and disallowed after 2035. U.S. federal agencies are expected to begin migrating high-risk systems by 2030.

In Europe, coordinated national strategies are required by the end of 2026, with high-risk system transitions mandated by 2030. The White House's March 2026 National Cybersecurity Strategy further accelerated adoption of post-quantum cryptography across federal systems.

Citi estimates the probability of widespread breaking of public-key encryption by 2034 at 19% to 34%, rising to 60% to 82% by 2044.

Key Takeaways

  • Google's March 2026 paper reduced ECDLP-256 quantum resource estimates by ~20x to fewer than 500,000 physical qubits, with a 2029 internal migration deadline.
  • $650 billion in BTC sits in addresses with exposed public keys, immediately vulnerable to a CRQC.
  • Ethereum has committed $2M in bounties, a dedicated team, weekly test networks, and a 2029 completion target.
  • Bitcoin has no coordinated migration plan; proposed BIPs face governance friction and a 5-10 year implementation timeline.
  • Solana's testnet showed quantum-safe signatures reduce throughput by ~90%, illustrating the performance cost across high-throughput chains.
  • Naoris Protocol is the first post-quantum L1 in production, though access remains invite-only.
  • NIST deprecation of ECDSA and RSA is scheduled for 2030, with disallowance by 2035.
  • Citi estimates 19-34% probability of practical quantum decryption by 2034.

Conclusion

The quantum threat to blockchain cryptography has shifted from theoretical to engineering-grade. Three research papers in three months have reduced the estimated cost of breaking ECDLP-256 by an order of magnitude. Google co-authored the most consequential of these papers with Ethereum Foundation researchers, then set 2029 as its own migration deadline.

The blockchain ecosystem's response reveals a governance divergence: Ethereum is treating this as a coordinated engineering project with deadlines, funding, and weekly test networks. Bitcoin is treating it as an open governance question with no timeline. Solana is stress-testing the performance implications. Newer protocols like Naoris are building post-quantum from genesis.

The data suggests a 3-7 year window before CRQCs become operational. For networks that need 5-10 years to migrate, that window may already be insufficient. The $650 billion in quantum-exposed BTC, the 90% throughput penalty on quantum-safe Solana testnet, and the absence of a Bitcoin migration plan are not theoretical risks. They are measurable gaps between the threat timeline and the response timeline.

Sources & References

  1. Google Quantum AI — Securing Elliptic Curve Cryptocurrencies — Google's cryptocurrency whitepaper and responsible disclosure blog post, March 2026
  2. Google Quantum AI — Full Whitepaper (PDF) — Technical paper detailing ECDLP-256 circuit estimates
  3. Q-Day Just Got Closer: Three Papers in Three Months — The Quantum Insider, March 31, 2026
  4. Bitcoin's $1.3 Trillion Security Race — CoinDesk, April 4, 2026
  5. Google Warns Five Quantum Attack Paths on Ethereum — CoinDesk, March 31, 2026
  6. Ethereum Foundation Post-Quantum Security Team — The Block, January 2026
  7. Citi Institute — Quantum Threat: The Trillion-Dollar Security Race Is On (PDF) — Citi, January 2026
  8. Solana's Post-Quantum Push Reveals Harsh Tradeoff — CoinDesk, April 4, 2026
  9. Naoris Protocol Launches Post-Quantum L1 Mainnet — The Quantum Insider, April 1, 2026
  10. Naoris Protocol Quantum-Resistant Blockchain Goes Live — CoinDesk, April 3, 2026
  11. How Bitcoin, Ethereum, and Solana Are Preparing for the Quantum Threat — CoinDesk, March 28, 2026
  12. Google Shortens Timeline for Quantum-Safe Encryption Transition — The Quantum Insider, March 25, 2026
  13. Project Eleven Q-Day Prize — Bitcoin Magazine, 2026
  14. NIST Post-Quantum Cryptography Standards — NIST official page
  15. Adam Back Advocates Phased Quantum Upgrade for Bitcoin — CoinAlert News, April 5, 2026