A Google Quantum AI research paper published March 31, 2026 reduced the estimated qubit threshold for breaking Bitcoin's ECDSA-256 encryption from approximately 9 million physical qubits to fewer than 500,000 — a 20x reduction from prior models. The paper, titled "Securing Elliptic Curve Cryptocu...
"We engaged with the U.S. government and developed a new method to describe these vulnerabilities via a zero-knowledge proof, so they can be verified without providing a roadmap for bad actors." — Ryan Babbush, Head of Quantum Applications, Google Quantum AI
A Google Quantum AI research paper published March 31, 2026 reduced the estimated qubit threshold for breaking Bitcoin's ECDSA-256 encryption from approximately 9 million physical qubits to fewer than 500,000 — a 20x reduction from prior models. The paper, titled "Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities," was co-authored by nine researchers spanning Google Quantum AI, UC Berkeley, Stanford University, and the Ethereum Foundation. It estimates that 6.9 million BTC (approximately $470 billion at current prices, or 35% of total supply) sit in addresses vulnerable to quantum attack.
The paper cited Algorand's FALCON post-quantum signature scheme 32 times, calling it "the most complete deployment of post-quantum cryptographic primitives on a production blockchain." ALGO responded by rallying 57% in six days, from $0.079 on March 29 to $0.126 by April 4, reclaiming a $1.1 billion market cap. Meanwhile, Bitcoin developers have accelerated work on BIP-360, a quantum-resistant upgrade proposal now running on testnet with more than 50 miners and 100,000 processed blocks. The Ethereum Foundation formed a dedicated post-quantum team in January 2026 and has allocated $22 million across research prizes and formal verification initiatives.
The timeline for a cryptographically relevant quantum computer (CRQC) capable of executing the attack described in the paper remains uncertain, but Google's own internal target for migrating its infrastructure to post-quantum cryptography is 2029.
The paper's central finding: solving the 256-bit Elliptic Curve Discrete Logarithm Problem (ECDLP) over the secp256k1 curve — the cryptographic foundation of Bitcoin, Ethereum, and most major blockchains — requires either 1,200 logical qubits with 90 million Toffoli gates, or 1,450 logical qubits with 70 million Toffoli gates. Mapped onto a superconducting surface-code architecture, these requirements translate to fewer than 500,000 physical qubits.
Prior estimates, notably from Litinski (2023), placed the threshold at approximately 9 million physical qubits. The Google paper represents roughly a 20x reduction in the resource requirement.
Three factors drove the improvement:
The paper was accompanied by a responsible disclosure protocol. Google engaged with the U.S. government prior to publication and developed a zero-knowledge proof method that allows the vulnerability claims to be verified without providing implementation details to potential attackers. This is the first time a major quantum computing research group has applied responsible disclosure norms — typically reserved for software vulnerabilities — to cryptographic threat research.
Current quantum hardware operates in the hundreds to low thousands of physical qubits, with error rates far too high for the fault-tolerant computation the paper describes. No CRQC of this scale exists today. But the reduced threshold narrows the gap between current capability and the danger zone.
The paper identifies two categories of Bitcoin addresses exposed to quantum attack:
Pay-to-Public-Key (P2PK) addresses: Approximately 1.7 million BTC sit in P2PK scripts where public keys are directly visible on-chain. These include early-era addresses, notably those attributed to Satoshi Nakamoto's estimated 1.1 million BTC. A quantum attacker could derive private keys from these exposed public keys without requiring a time-constrained attack.
Reused addresses: When a Bitcoin address sends a transaction, its public key is broadcast to the network. Addresses that have been reused for sending expose their public keys permanently. According to CoinShares research cited in the paper, the total quantum-vulnerable supply across all script types reaches approximately 6.9 million BTC when address reuse is factored in.
At Bitcoin's current price of approximately $69,000, the vulnerable pool totals roughly $470 billion — approximately 35% of total BTC supply.
Ethereum faces a related but distinct risk profile. Ethereum uses the same secp256k1 elliptic curve cryptography, but its 12-second block time creates a significantly smaller window for real-time quantum attacks compared to Bitcoin's 10-minute block interval. The paper does not quantify Ethereum's vulnerable address pool but notes the shared cryptographic foundation.
ALGO was the clear market beneficiary of the paper's publication. The Google researchers cited Algorand 32 times, describing its implementation of FALCON (Fast Fourier Lattice-based Compact Signatures over NTRU) digital signatures as the model for quantum-resistant blockchain architecture.
Price action: ALGO traded at $0.079 on March 29 and reached $0.126 by April 4 — a 57% gain in six trading days. Market capitalization recovered to $1.1 billion. Seven-day trading volume reached $505 million, with daily volumes between $74 million and $89 million during peak activity.
Technical implementation: Algorand executed the first post-quantum transaction on a public blockchain mainnet on November 3, 2025, using FALCON-1024 signatures. FALCON-1024 produces signatures of approximately 1,280 bytes with public keys of approximately 1,793 bytes. Verification uses only integer arithmetic and completes in under 100 microseconds on standard hardware — a property that suits blockchain's asymmetric verification-heavy workload.
Algorand's State Proofs system already uses FALCON for generating compact attestations that summarize blockchain state over 256-round intervals. The 2026 roadmap includes a consensus module that verifies FALCON signatures natively, Ledger hardware wallet firmware for the larger key sizes, and an on-chain governance vote to enable "quantum-safe accounts" without requiring a hard fork.
Concurrent catalysts amplified the move:
These factors converged with the Google paper to produce the strongest ALGO price move in over a year.
The Bitcoin developer community has coalesced around BIP-360, a proposal for a new output type called Pay-to-Merkle-Root (P2MR). The design commits directly to a script tree's Merkle root without relying on an internal key or tweak, preserving Taproot's scripting capabilities while eliminating the key-path spend that creates quantum exposure.
Testnet status: BTQ Technologies implemented BIP-360 in Bitcoin Quantum testnet v0.3.0, announced March 20, 2026. The testnet has attracted more than 50 miners, processed over 100,000 blocks, and built a community of more than 100 open-source contributors.
Alternative proposals under discussion:
The community remains divided on urgency. Blockstream CEO Adam Back and JAN3 CEO Samson Mow have argued the quantum threat is not imminent and advocate a phased approach, noting that Taproot's key-path design already provides partial protection. Bitcoin investor Charles Edwards has pushed for deployment by 2026 and suggested penalizing unmigrated coins by 2028.
The core challenge for Bitcoin is governance speed. Any post-quantum upgrade requires consensus among miners, node operators, and developers — a process that historically takes years. The SegWit upgrade took approximately two years from proposal to activation; Taproot took approximately three.
The Ethereum Foundation has committed the most resources to post-quantum preparation among major blockchain projects:
The Ethereum Foundation's approach focuses on integrating post-quantum signatures into its existing zkEVM and proof aggregation infrastructure rather than replacing the base-layer signature scheme outright. Justin Drake, one of the Google paper's co-authors and a researcher at the Ethereum Foundation, participated directly in the research — a signal that Ethereum's leadership treats the quantum timeline as credible.
NIST released its first three finalized post-quantum encryption standards in August 2024: FIPS 203 (ML-KEM, derived from CRYSTALS-KYBER), FIPS 204 (ML-DSA, derived from CRYSTALS-Dilithium), and FIPS 205 (SLH-DSA, derived from SPHINCS+).
FALCON was also selected for standardization and will be published as FIPS 206 under the name FN-DSA (FFT over NTRU-Lattice-Based Digital Signature Algorithm). The draft standard is expected for public review, with finalization projected for late 2026 or early 2027.
FALCON's compact signature size (1,280 bytes for FALCON-1024 versus 2,420 bytes for ML-DSA-65) makes it particularly suited for blockchain applications where on-chain storage costs are non-trivial. This size advantage is the primary reason Algorand selected FALCON for its implementation and why the Google paper highlighted it as the preferred scheme for cryptocurrency migration.
Other blockchain projects adopting post-quantum cryptography include QANplatform (using ML-DSA via its XLINK layer for MetaMask-compatible Solidity contracts) and several projects in earlier research phases. However, Algorand remains the only major production blockchain with live FALCON transactions on mainnet.
There is no consensus on when a CRQC will materialize. Available estimates:
| Source | Estimated CRQC Timeline | Basis | |--------|------------------------|-------| | Google (internal target) | 2029 | Infrastructure migration deadline | | Global expert survey (2025) | 2030–2035 (50%+ likelihood) | One-third of respondents | | Adam Back / Blockstream | 2040+ | Conservative hardware extrapolation | | Google paper (resource estimate) | Not specified | 500,000 physical qubits required |
Current state-of-the-art quantum processors (Google's Willow, IBM's Heron) operate with hundreds to low thousands of physical qubits at error rates incompatible with fault-tolerant computation. The gap between current capability and the 500,000-qubit threshold remains substantial, but the trajectory of qubit scaling has accelerated in recent years.
The "harvest now, decrypt later" threat — where adversaries record encrypted data today for future quantum decryption — does not directly apply to blockchain transactions in the same way it applies to encrypted communications. However, exposed public keys on P2PK addresses and reused addresses represent a persistent, time-independent vulnerability that requires no real-time attack.
The Google Quantum AI paper did not reveal that quantum computers can break Bitcoin today. What it did was materially reduce the estimated distance between current quantum hardware and the threshold required to compromise secp256k1 cryptography. The practical implication: the window for migration is shorter than previously assumed, and the cost of inaction is quantifiable — $470 billion in vulnerable BTC alone.
The market's response followed predictable logic. ALGO, as the sole production blockchain with post-quantum transactions on mainnet, captured the narrative premium. Bitcoin and Ethereum, which face longer upgrade timelines due to governance complexity and larger attack surfaces, saw no material price disruption — the threat remains distant enough that markets are not pricing immediate risk.
The more consequential development may be institutional. Google's responsible disclosure protocol, the Ethereum Foundation's $22 million commitment, and NIST's FALCON standardization timeline collectively suggest that post-quantum migration is transitioning from research curiosity to infrastructure planning. For blockchain networks controlling trillions in value, the question is no longer whether to migrate but whether governance mechanisms can execute within the narrowing timeline.