A convergence of three developments in early 2026 has moved the quantum threat to cryptocurrency from theoretical risk to operational planning concern. On March 31, Google Quantum AI published resource estimates showing fewer than 500,000 physical qubits — roughly 20x lower than prior benchmarks ...
"The resource requirements for this type of attack keep dropping, and the barrier to running it in practice is dropping with them." — Alex Pruden, CEO, Project Eleven
A convergence of three developments in early 2026 has moved the quantum threat to cryptocurrency from theoretical risk to operational planning concern. On March 31, Google Quantum AI published resource estimates showing fewer than 500,000 physical qubits — roughly 20x lower than prior benchmarks — could break the elliptic curve cryptography (ECDSA-256) securing Bitcoin, Ethereum, and most blockchains. On April 24, independent researcher Giancarlo Lelli broke a 15-bit ECC key on publicly accessible quantum hardware, a 512x improvement over the previous public demonstration seven months earlier. And on May 6, Project Eleven released a 110-page report placing its baseline "Q-Day" scenario — the moment a cryptographically relevant quantum computer exists — in 2033, with an optimistic bound of 2030.
The combined implication: more than $3 trillion in digital assets secured by elliptic curve cryptography face a narrowing window for migration. Approximately 6.9 million Bitcoin with exposed public keys, worth roughly $500 billion at current prices, sit in wallets immediately vulnerable once capable hardware arrives. Migration efforts are underway across major chains, but early testing reveals severe performance trade-offs, with Solana's quantum-resistant signature trials showing a 90% speed penalty. The gap, according to Project Eleven, is "not technical" but one of "coordination, urgency, and willingness to accept the costs of migration."
On March 31, 2026, Google Quantum AI researchers Ryan Babbush (Director of Research, Quantum Algorithms) and Hartmut Neven (VP of Engineering) published a whitepaper detailing two optimized quantum circuits implementing Shor's algorithm against ECDLP-256, the mathematical problem underlying blockchain signature security.
Circuit specifications:
| Circuit | Logical Qubits | Toffoli Gates | Physical Qubits | |---------|----------------|---------------|-----------------| | A | < 1,200 | 90 million | < 500,000 | | B | < 1,450 | 70 million | < 500,000 |
Both circuits execute in minutes under standard superconducting hardware assumptions, according to Google. The roughly 20-fold reduction from prior estimates — which placed the requirement at approximately 20 million physical qubits — fundamentally resets the industry's timeline calculus.
Google also modeled a real-time transaction hijacking attack against Bitcoin's 10-minute block confirmation window, estimating a 41% success rate. The company has set an internal deadline of 2029 to migrate its own infrastructure to post-quantum cryptography and employed zero-knowledge proofs to verify vulnerability claims without exposing operational attack details.
A separate estimate from Caltech and Oratomic placed the threshold as low as 10,000 qubits in neutral-atom architecture, though this projection remains unverified in practice.
On April 24, 2026, Project Eleven awarded its Q-Day Prize — 1 Bitcoin — to Giancarlo Lelli for executing the largest public quantum attack on elliptic curve cryptography to date. Lelli derived a private key from its public key across a search space of 32,767 using a variant of Shor's algorithm targeting the Elliptic Curve Discrete Logarithm Problem (ECDLP).
The attack ran on a cloud-accessible quantum computer. No national lab access or proprietary chip was required. For context, Steve Tippeconnic's 6-bit ECC break in September 2025 was the first public demonstration on quantum hardware. Lelli's 15-bit result represents a 512x expansion of the demonstrated attack surface in seven months.
Bitcoin uses 256-bit elliptic curve keys. A 15-bit break does not threaten the network today. The search space gap between 15 bits (32,767 possibilities) and 256 bits (approximately 1.16 × 10^77) remains astronomically large. But the trajectory — from theory to 6 bits to 15 bits in under a year — has concentrated industry attention.
Project Eleven's 110-page report, published May 6, 2026, constructs an analytical framework for estimating when a cryptographically relevant quantum computer (CRQC) will exist. The model's baseline places Q-Day in 2033. Optimistic and pessimistic scenarios bracket the range at 2030 and 2042, respectively.
Key findings from the report:
According to CoinDesk, Project Eleven CEO Alex Pruden suggested "recycling" vulnerable Bitcoin — effectively forcing migration by invalidating unmigrated keys after a deadline — rather than allowing quantum theft.
In April 2026, Coinbase convened an Independent Advisory Board on Quantum Computing and Blockchain comprising six researchers: Prof. Scott Aaronson (University of Texas at Austin), Prof. Dan Boneh (Stanford), Justin Drake (Ethereum Foundation), Prof. Sreeram Kannan (Eigen Labs / University of Washington), Prof. Yehuda Lindell (Coinbase / Bar-Ilan University), and Prof. Dahlia Malkhi (UC Santa Barbara).
The panel's central conclusion: a quantum computer capable of breaking blockchain encryption will eventually be built. At least two major engineering leaps remain, but waiting for urgency is not viable strategy.
Their position paper noted that NIST recommends completing migration to post-quantum cryptography (PQC) by 2035. The panel recommended:
The panel identified a critical research gap: no post-quantum equivalent exists for BLS signature aggregation, which Ethereum validators rely on. Existing alternatives require interactive coordinator communication, creating efficiency challenges at scale.
| Chain | Status | Timeline Target | |-----------|------------------------------------------------------|-----------------| | Ethereum | Formal PQ roadmap published February 2026; hard fork planned for core PQ infrastructure | ~2029 | | Bitcoin | BIP-360 proposal for public key hiding; no consensus on migration fork | None set | | Solana | Partnered with Project Eleven; Falcon (FN-DSA) selected; testnet trials in April 2026 | In progress | | Algorand | First post-quantum transaction executed on mainnet | Completed (partial) | | Optimism | Declared flag day of January 2036 for migration completion | January 2036 | | NEAR | Announced PQC integration into account infrastructure | In progress |
The Ethereum Foundation's approach is the most detailed, according to the Coinbase panel. Vitalik Buterin has outlined that validator signatures, data storage, accounts, and proofs all require changes. Account abstraction serves as the mechanism for migrating user wallets, with structured fork milestones targeting completion of core infrastructure by approximately 2029. Full ecosystem migration extends beyond that date.
Solana's approach centers on Falcon (FN-DSA), a NIST-approved lattice-based signature scheme selected by both Anza and Jump Crypto's Firedancer client for its compact design and high throughput relative to other PQC alternatives. The existing Winternitz Vault, a hash-based quantum-resistant solution available for over two years, provides interim long-term storage security but generates a new address for every transaction, making it impractical for general use.
The core technical obstacle across all chains: post-quantum signatures are substantially larger than current ECC signatures.
| Scheme | Signature Size | Relative to ECC (64 bytes) | |------------------|----------------|---------------------------| | Current ECC | 64 bytes | 1x | | ML-DSA (NIST) | 2,420 bytes | 38x | | Hash-based (SLH-DSA) | 17,000+ bytes | 265x+ | | Falcon (FN-DSA) | ~666 bytes | ~10x |
According to the Coinbase panel, naive implementation of ML-DSA could reduce transaction throughput by 90% or more. Solana's April 2026 testnet trials with quantum-resistant signatures confirmed this estimate, revealing a roughly 90% speed penalty. These signatures are up to 40x larger than current cryptographic signatures on Solana.
Falcon offers the most practical trade-off for high-throughput chains, which explains Solana's selection. Ethereum's path likely involves SNARKs to compress PQC signature verification, though this adds complexity.
An estimated 1.1 million Bitcoin attributed to Satoshi Nakamoto sit in addresses with exposed public keys — among the most vulnerable holdings on the network. The Coinbase panel framed the governance question starkly: each blockchain community must decide whether to freeze, revoke, or leave vulnerable assets exposed.
Two options exist:
Neither option is costless. The panel recommended these decisions be made and communicated publicly as early as possible.
A May 24, 2026, CoinDesk report highlighted a compounding factor: artificial intelligence is accelerating quantum computing development. According to NEAR Protocol co-founder and former Google AI researcher Illia Polosukhin, "AI is becoming more and more of an accelerator" for quantum research, with machine learning systems already optimizing quantum error correction.
Polosukhin warned that "harvest now, decrypt later" strategies — adversaries collecting encrypted data today for future quantum decryption — are already operational: "Everything we're putting on the internet, if you're identifiable as a person of interest, you can assume will be decrypted in two years."
Project Eleven's Pruden echoed this assessment: "Between quantum and AI, we're going to go into a world where security...you simply cannot count on the way you've always done things."
The quantum threat to cryptocurrency has transitioned from abstract risk to quantified engineering problem. Google's resource estimates, Lelli's hardware demonstration, and Project Eleven's timeline model collectively establish that Q-Day is not a question of "if" but "when" — and the "when" has moved measurably closer in 2026.
The industry's response is fragmented. Ethereum has the most detailed roadmap. Solana has the most active testing program. Bitcoin has the most exposed assets and the least consensus on a path forward. Algorand has shipped the first mainnet transaction. Optimism has declared the first hard deadline. No chain has completed migration.
NIST's 2035 migration recommendation provides a benchmark, but the Coinbase panel's assessment is more direct: the time to prepare is now. The 6.9 million Bitcoin with exposed public keys represent a $500 billion vulnerability that cannot be addressed retroactively. Every month without migration consensus is a month closer to the window closing.
The economic value at stake — more than $3 trillion across ECC-secured systems — makes this the largest coordinated infrastructure migration in the history of digital assets. Whether the industry can execute it before the threat materializes remains an open question.