Google's Quantum AI team published research on March 28-31 indicating that breaking Bitcoin's ECDSA cryptography may require fewer than 500,000 physical qubits — a figure 20 times lower than previous estimates that placed the threshold in the millions. The paper describes two attack vectors requi...
"Elliptic curve cryptography is on the brink of obsolescence." — Nic Carter, Co-founder, Castle Island Ventures
Google's Quantum AI team published research on March 28-31 indicating that breaking Bitcoin's ECDSA cryptography may require fewer than 500,000 physical qubits — a figure 20 times lower than previous estimates that placed the threshold in the millions. The paper describes two attack vectors requiring approximately 1,200 to 1,450 high-quality logical qubits each, capable of deriving private keys from exposed public keys in roughly nine minutes.
The research puts a dollar figure on the exposure: approximately 6.9 million BTC, worth over $440 billion at current prices, sits in address formats where public keys are already visible on-chain. Google has set a 2029 internal deadline for migrating its own authentication services to post-quantum cryptography, signaling that the company's engineers view the threat horizon as three years away, not thirty.
The crypto industry's response is fragmented. Ethereum launched pq.ethereum.org on March 25 with $2 million in research prizes, a dedicated team, and weekly post-quantum devnets involving more than 10 client teams. Bitcoin merged BIP-360 into its formal repository on February 11 but has no coordinated migration timeline, no funded engineering program, and no fork milestones. Solana has deployed experimental quantum-resistant vaults. The gap between Ethereum's systematic preparation and Bitcoin's decentralized debate is widening.
Google's Quantum AI team, in research signed by VP of Security Engineering Heather Adkins and Senior Cryptography Engineer Sophie Schmieg, published updated resource estimates for breaking the cryptographic primitives used by Bitcoin and Ethereum.
The core finding: factoring a 2048-bit RSA integer could be accomplished in less than a week using 1 million noisy qubits. For Bitcoin's 256-bit Elliptic Curve Digital Signature Algorithm (ECDSA), the threshold is lower — approximately 1,200 to 1,450 logical qubits, supported by fewer than 500,000 physical qubits, executing 70 to 90 million quantum gates.
Prior estimates from 2012-era research suggested breaking RSA would require a billion precise qubits. The 20x reduction in estimated resources reflects advances in error correction, algorithm optimization, and hardware architecture — not a single breakthrough but cumulative progress.
Google's Willow chip, announced in December 2024, operates at 105 physical qubits. The gap between 105 and 500,000 is significant but shrinking at a rate that quantum hardware has demonstrated roughly 10x power growth over five years.
The 6.9 million BTC figure cited in Google's research encompasses several address categories:
The figure contrasts with a CoinShares estimate of only 10,200 BTC vulnerable enough to significantly impact markets — a discrepancy that reflects different assumptions about what constitutes a "practical" quantum attack versus a theoretical one.
According to Ark Invest and Unchained analysis, approximately 35% of total Bitcoin supply exists in theoretically vulnerable address types. At BTC's current price near $68,000, the exposure exceeds $440 billion.
For Ethereum, the research identifies 37 million ETH at risk, with an additional systemic concern: smart contracts lack post-quantum cryptography, and BLS signatures used in Ethereum's Proof-of-Stake consensus create cascading risks if validator keys are compromised.
Bitcoin's Taproot upgrade, activated in November 2021, improved privacy and smart contract efficiency. It also introduced a specific quantum vulnerability that did not exist in prior address formats.
Taproot uses Schnorr signatures with publicly visible keys. In older address formats (P2PKH), public keys are hashed before appearing on-chain, providing a layer of protection — a quantum attacker would need to break both the hash function and the signature scheme. Taproot removes that intermediate step.
The practical implication: every wallet using Bitcoin's most modern address format exposes its public key on the blockchain. Google's researchers note this design choice could expand the population of wallets vulnerable to future quantum attacks, beyond the legacy P2PK addresses from Bitcoin's earliest years.
Google's attack model describes an "on-spend" scenario: when a user broadcasts a transaction, the public key is revealed in the mempool before the transaction is confirmed. A quantum attacker with sufficient hardware could theoretically derive the private key and broadcast a competing transaction in approximately nine minutes — beating Bitcoin's 10-minute block time roughly 41% of the time.
The Ethereum Foundation launched pq.ethereum.org on March 25, 2026, consolidating eight years of post-quantum research into a public roadmap with specific engineering targets. The site includes specifications, open-source repositories, EIPs, and a 14-question FAQ maintained by a dedicated PQ team.
Ethereum's approach spans three protocol layers:
Execution layer: Post-quantum signature verification via a vector math precompile. Account abstraction enables quantum-safe authentication without requiring simultaneous protocol-wide upgrades. Users can migrate wallets individually.
Consensus layer: Current BLS validator signatures will be replaced with leanXMSS, a hash-based signature scheme. A zero-knowledge virtual machine handles aggregation to maintain scalability despite the increased signature sizes inherent in post-quantum algorithms.
Data layer: Post-quantum cryptography extended to blob handling for data availability sampling.
The Foundation describes its strategy as "Ship of Theseus" — replacing cryptographic building blocks piece by piece across multiple hard forks without pausing the live network. More than 10 client teams participate in weekly PQ Interop devnets. The target is completing core L1 upgrades by 2029, aligning with Google's own migration deadline.
The $2 million research prize fund is designed to attract external cryptographers to audit and stress-test proposed schemes, including CRYSTALS-Dilithium and Falcon signature algorithms.
BIP-360, co-authored by Hunter Beast (MARA), Ethan Heilman, and Foxen Duke, was merged into Bitcoin's official BIP repository on February 11, 2026. It introduces Pay-to-Merkle-Root (P2MR), a new output type designed to accommodate quantum-resistant signature schemes.
On March 20, BTQ Technologies deployed the first working BIP-360 implementation on Bitcoin Quantum testnet v0.3.0, demonstrating that the proposal functions in practice. Developers, miners, and researchers can evaluate quantum-resistant transactions in a live test environment.
However, BIP-360's limitations are clearly defined. It removes Taproot key path exposure but does not fully replace ECDSA across the protocol. It provides a migration path for individual wallets, not a network-wide cryptographic overhaul.
The governance challenge is structural. Bitcoin has no equivalent of Ethereum's Foundation-funded research program, no dedicated PQ team, no fork milestones, and no consensus on urgency.
Charles Edwards of Capriole advocates for 2026 implementation. Adam Back (Blockstream) and Samson Mow (Jan3) remain skeptical of near-term quantum threats. Jameson Lopp, co-founder of Casa, has noted that upgrading Bitcoin and migrating user funds could independently require 5 to 10 years — meaning that if the threat materializes by 2029, work needed to start years ago.
Nic Carter of Castle Island Ventures described Bitcoin's approach as "worst in class" with "zero buy-in from top devs," contrasting it with Ethereum's "best in class" strategy.
A secondary proposal, the "Hourglass" concept, would gradually limit the use of vulnerable coins unless they are moved to quantum-safe addresses, creating economic pressure for migration without forced confiscation. Neither proposal has an activation timeline.
Solana: Project Eleven leads post-quantum security work. The "Winternitz Vault" provides quantum-resistant smart contract vaults using hash-based, one-time signatures. Participation is voluntary; the broader network operates unchanged.
Algorand: Has integrated post-quantum signature schemes at the protocol level, positioning itself as quantum-ready by default rather than through opt-in migration.
XRP Ledger: Has implemented post-quantum cryptographic primitives, though adoption among validators and wallet providers remains early-stage.
Coinbase: Established an independent advisory board of cryptographers, academics, and quantum experts tasked with assessing risks and guiding implementation.
Three institutional deadlines now converge:
| Entity | Deadline | Scope | |--------|----------|-------| | Google | 2029 | All authentication services migrated to PQC | | NSA | 2033 | National security systems transition complete | | NIST | 2035 | Legacy RSA algorithm deprecation |
A Trusted Computing Group survey found that 91% of businesses have no formal roadmap for quantum-safe migration. The tokenized real-world asset market, projected to exceed $16 trillion by 2030 according to Boston Consulting Group, would inherit whatever cryptographic vulnerabilities exist in its underlying chains.
IBM's fault-tolerant quantum systems roadmap also targets 2029, corroborating Google's timeline. Both companies view 2025 as the inflection point when error correction breakthroughs shifted the discussion from "if" to "when."
The economic value at stake extends beyond cryptocurrency holdings. Institutional custody, DeFi smart contracts, cross-chain bridges, and tokenized securities all rely on the same elliptic curve cryptography that Google's research places on a deprecation timeline.
Google's research does not describe an imminent attack. No quantum computer exists today with the capability to break ECDSA. The Willow chip's 105 qubits are orders of magnitude below the 500,000 physical qubit threshold the research identifies.
What the research does is compress the timeline. Estimates that once placed the quantum threat decades away now converge around 2029-2033. The question for the crypto industry is whether protocol upgrades — which themselves require years of engineering, testing, and consensus-building — can be completed within that window.
Ethereum's approach treats this as a concrete engineering problem with specific fork targets. Bitcoin's approach treats it as a theoretical risk subject to community debate. The market has not yet priced in this divergence. It may not need to for years. But the clock, according to Google's own engineers, is running.