Three research papers published between May 2025 and March 2026 have compressed the estimated timeline for quantum attacks on blockchain cryptography by roughly an order of magnitude. The most recent, from Google Quantum AI released March 31, 2026, concludes that breaking Bitcoin's elliptic-curve...
"Progress in quantum computing has reached the point where publishing improved attack details in full has become less prudent." — Google Quantum AI, March 2026 research paper (method disclosed via zero-knowledge proof)
Three research papers published between May 2025 and March 2026 have compressed the estimated timeline for quantum attacks on blockchain cryptography by roughly an order of magnitude. The most recent, from Google Quantum AI released March 31, 2026, concludes that breaking Bitcoin's elliptic-curve cryptography may require fewer than 500,000 physical qubits — a 20-fold reduction from the 9 million qubits estimated by Litinski in 2023. At current exposure levels, approximately $600 billion in Bitcoin, Ethereum, stablecoins, and tokenized assets sit in address formats vulnerable to eventual quantum attack.
The papers have triggered immediate market reactions. Quantum-resistant tokens gained 40–51% in 48 hours. Bitcoin's BIP-360 proposal, which removes quantum-vulnerable key-path spending, has been deployed on a testnet for the first time. The Ethereum Foundation launched pq.ethereum.org on March 24, consolidating a seven-fork roadmap targeting quantum-resistant cryptography by 2029. No quantum computer capable of executing these attacks exists today. The question is no longer whether the threat is real, but whether migration will finish before hardware catches up.
The qubit estimates required to break widely used cryptographic standards have fallen sharply across a 13-year span:
| Year | RSA-2048 Estimate (Physical Qubits) | Source | |------|--------------------------------------|--------| | 2012 | ~1 billion | Various academic estimates | | 2019 | ~20 million | Gidney & Ekerå | | 2025 (May) | < 1 million | Craig Gidney, Google | | 2026 (Feb) | < 100,000 | Iceberg Quantum (Pinnacle architecture) |
For elliptic-curve cryptography (ECC-256), which secures Bitcoin, Ethereum, and most major chains:
| Year | ECDLP Estimate (Physical Qubits) | Source | |------|-----------------------------------|--------| | 2023 | ~9 million | Litinski | | 2026 (March) | < 500,000 | Google Quantum AI |
Paper 1: Craig Gidney (Google, May 2025). Targeted RSA-2048 encryption. Achieved a 20x reduction from the 2019 estimate using approximate residue arithmetic, yoked surface codes, and magic state cultivation. Runtime: less than one week on a sub-million-qubit machine.
Paper 2: Iceberg Quantum (February 2026). Further reduced RSA-2048 requirements to fewer than 100,000 physical qubits using the Pinnacle architecture based on quantum low-density parity-check (LDPC) codes. The startup, which raised a $6 million seed round, validated results through simulation, not hardware. The approach requires advanced qubit connectivity not yet available in production systems. All results remain unverified on physical hardware.
Paper 3: Google Quantum AI (March 31, 2026). Focused directly on the 256-bit elliptic curve discrete logarithm problem (ECDLP) used in secp256k1 — the signature scheme securing Bitcoin and Ethereum. The team designed two attack methods requiring 1,200–1,450 logical qubits and 70–90 million Toffoli gates, translating to fewer than 500,000 physical qubits. The paper was disclosed via zero-knowledge proof rather than full circuit publication, a first for a major cryptographic research disclosure. According to the researchers, this approach allows verification without providing a blueprint for misuse.
According to analysis based on Google's paper and on-chain data compiled by CryptoSlate, the total value at quantum risk across major networks exceeds $600 billion:
Bitcoin:
Ethereum:
Stablecoins and tokenized assets: ~$200 billion in additional exposure, according to the same analysis.
A particularly notable finding in the Google paper concerns Bitcoin's 2021 Taproot upgrade. Taproot (P2TR) was designed to improve privacy and scripting efficiency. However, it exposes public keys on-chain by default — unlike older address formats (P2PKH) that conceal the public key until the moment coins are spent.
According to Google's researchers, this design choice widens the quantum attack surface. In pre-Taproot formats, an attacker would need to intercept a transaction in the mempool and derive the private key before the transaction confirms. With Taproot addresses, the public key is visible at all times, giving a quantum attacker an indefinite window to compute the corresponding private key.
Approximately 78% of current Bitcoin addresses use formats that hide public keys until spending. However, adoption of Taproot continues to grow, and any coins held in P2TR outputs are exposed for the duration of their storage, not merely during the spending window.
BIP-360 (Pay-to-Merkle-Root). Co-authored by Hunter Beast, Ethan Heilman, and Isabel Foxen Duke, BIP-360 proposes a new output type modeled on Taproot but with the key-path spend removed entirely. Instead of committing to an internal public key, P2MR commits solely to the Merkle root of a script tree. Hash-based methods are considered resistant to known quantum algorithms.
BIP-360 was merged into Bitcoin's official BIP repository in early 2026. BTQ Technologies, a Vancouver-based quantum security firm, announced the first working implementation on Bitcoin Quantum testnet v0.3.0 on March 20, 2026. The testnet provides developers and researchers with a live environment to evaluate quantum-resistant transactions.
BIP-360 preserves compatibility with Lightning, BitVM, and Ark through Tapscript Merkle trees. Multisig, timelocks, and complex custody structures remain functional. The proposal does not require a hard fork.
Adoption across the broader Bitcoin ecosystem remains limited. A May 2025 analysis from Chaincode Labs noted that post-quantum initiatives were at an "early and exploratory stage."
The Ethereum Foundation launched pq.ethereum.org on March 24, 2026, consolidating research, EIPs, a technical roadmap, and a 14-question FAQ. More than 10 client teams are building devnets through a weekly PQ Interop process.
The roadmap outlines seven hard forks through 2029 on roughly six-month cadences — a "Ship of Theseus" strategy replacing cryptographic building blocks incrementally without pausing the live network. The Foundation noted that AI-accelerated R&D could compress timelines. According to Stanford cryptographer Dan Boneh, who has consulted on the effort, the transition plan reflects "the most organized post-quantum migration in any decentralized system."
Justin Drake of the Ethereum Foundation described five quantum attack paths that could put approximately $100 billion in Ethereum-based assets at risk, according to a CoinDesk report from March 31.
The initiative traces back to STARK-based signature aggregation research begun in 2018, representing eight years of foundational work now entering an engineering phase.
Solana developers introduced the "Winternitz Vault" concept in December 2025 — smart-contract-based vaults secured by hash-based, one-time signatures. Unlike protocol-level overhauls, these function as an opt-in security layer. Users concerned about long-term quantum risk can store assets in vaults while the broader network operates unchanged. Project Eleven is leading post-quantum security development for Solana.
The Caltech/Oratomic paper (March 31, 2026) estimated that a neutral-atom quantum computer with approximately 26,000 qubits could crack ECC-256 in roughly 10 days, while RSA-2048 would require about 102,000 qubits and three months. The team exploits neutral atoms' ability to move across qubit arrays using laser-based optical tweezers, cutting the physical-to-logical qubit ratio from roughly 1,000:1 down to approximately 5:1. All nine authors are Oratomic shareholders, with six employed by the company, representing a material conflict of interest.
No quantum computer currently operational can execute Shor's algorithm against production cryptographic keys. Current state of the industry:
The gap between current hardware (~100–200 qubits) and attack thresholds (~10,000–500,000 qubits depending on architecture) remains substantial. IBM targets its first large-scale fault-tolerant system by 2029. Google has set a 2029 deadline for migrating its own systems to post-quantum cryptography.
The publication of three converging papers triggered measurable market response in the quantum-resistant token sector:
Bitcoin and Ethereum prices showed no significant movement attributable specifically to the quantum research, suggesting the broader market views the threat as material but not imminent.
The quantum threat to blockchain cryptography has moved from theoretical to engineering-constrained. The question is no longer about the mathematics — Shor's algorithm works. The question is about hardware timelines and migration speed. At current trajectory, the industry's 2029 migration targets may or may not arrive ahead of capable hardware, depending on which qubit estimates prove most accurate.
The economic value at stake — $600 billion in directly exposed assets, plus the integrity of all ECC-secured smart contracts, bridges, and oracles — makes post-quantum migration one of the highest-value infrastructure projects in the blockchain ecosystem. The protocols that complete migration first will hold a structural security advantage. Those that delay face the risk of a "Q-Day" scenario in which asset migration becomes a race condition against an attacker with sufficient hardware.
The data is clear. The timeline is uncertain. The cost of waiting is measurable.