On April 24, 2026, researcher Giancarlo Lelli broke a 15-bit elliptic curve cryptography (ECC) key on publicly accessible quantum hardware, winning Project Eleven's 1 BTC Q-Day Prize (valued at approximately $78,000). The achievement represents a 512x increase over the prior public record of 6 bi...
"The resource requirements for this type of attack keep dropping, and the barrier to running it in practice is dropping with them." — Alex Pruden, CEO, Project Eleven
On April 24, 2026, researcher Giancarlo Lelli broke a 15-bit elliptic curve cryptography (ECC) key on publicly accessible quantum hardware, winning Project Eleven's 1 BTC Q-Day Prize (valued at approximately $78,000). The achievement represents a 512x increase over the prior public record of 6 bits, set in September 2025. While Bitcoin's 256-bit ECC remains intact, the result arrived alongside a cascade of developments compressing the estimated timeline for a meaningful quantum attack on blockchain cryptography.
Within the same month, a Caltech/Oratomic paper reduced the estimated qubit requirement for breaking ECC-256 to approximately 10,000 physical qubits in a neutral-atom architecture — down five orders of magnitude from 2012 estimates of roughly 1 billion. Google Research separately placed the threshold below 500,000 physical qubits using current gate-based systems. Approximately 6.9 million BTC (one-third of total supply) sit in addresses with exposed public keys. The industry response is fragmenting along chain-specific lines: Bitcoin's BIP-360 and BIP-361 proposals face governance friction, Ethereum has deployed four dedicated post-quantum teams running weekly testnets, and Solana's two core development teams announced convergence on the Falcon signature scheme on April 27.
The question facing the $1.8 trillion crypto market is no longer whether quantum machines will break current cryptography, but whether migration can complete before the cost of attack collapses further.
Project Eleven, a quantum security firm, launched its Q-Day Prize to benchmark real-world progress in quantum attacks against elliptic curve cryptography — the same mathematical foundation securing Bitcoin, Ethereum, and most blockchain wallets.
In September 2025, Steve Tippeconnic broke a 6-bit ECC key using IBM's 133-qubit quantum computer, the first public demonstration of Shor's algorithm applied to the Elliptic Curve Discrete Logarithm Problem (ECDLP) on real hardware. Seven months later, Lelli extended the record to 15 bits using a cloud-accessible quantum machine — no national laboratory or proprietary hardware involved. The search space expanded from 64 to 32,767 possibilities.
Bitcoin uses 256-bit ECC. The gap between 15 bits and 256 bits remains vast. But the trajectory matters: two public demonstrations in seven months, each pushing the boundary by orders of magnitude, using commodity-accessible hardware.
The resource estimates for a full-scale quantum attack on ECC-256 have declined sharply in recent years, accelerating in 2026:
| Year | Estimated Physical Qubits for ECC-256 Break | Source | |------|----------------------------------------------|--------| | 2012 | ~1 billion | Early academic estimates | | 2023 | ~20 million | IBM/academic consensus | | March 2026 | <500,000 | Google Research | | April 2026 | ~10,000–26,000 | Caltech/Oratomic (arXiv preprint) |
The Caltech/Oratomic paper, published in April on arXiv, proposes a new quantum error-correction architecture using neutral-atom qubits. According to the authors, an array of approximately 26,000 atoms could crack ECC-256 in roughly 10 days; 10,000 atoms could accomplish the same in approximately three years. One caveat: all nine authors hold equity in Oratomic, and six are company employees. The conflict of interest is disclosed but warrants scrutiny of the claims.
Google Quantum AI published separate work in March estimating a 256-bit break would require roughly 1,200 logical qubits — about 20 times fewer than earlier estimates. Physical qubit requirements depend on error-correction overhead, placing the number below 500,000 with current architectures.
No quantum system in existence today exceeds approximately 1,200 physical qubits in a fault-tolerant configuration. The gap remains large, but the trend line is compressing.
The quantum threat to blockchain targets digital signatures, not the ledger itself. Mining (hash-based computation) and the blockchain's integrity are not meaningfully affected. The vulnerability sits in wallet ownership: a sufficiently powerful quantum computer running Shor's algorithm could derive a private key from a public key exposed on-chain.
Approximately 6.9 million BTC sit in addresses with visible public keys, according to Project Eleven's analysis. This represents roughly one-third of all Bitcoin ever mined, valued at over $520 billion at current prices. The exposure breaks down as follows:
The practical implication: any entity that achieves quantum capability sufficient to break ECC-256 could drain these wallets. There is no on-chain mechanism to prevent it under current protocol rules.
Bitcoin's response centers on two proposals:
BIP-360 (merged into the official BIP repository February 11, 2026) introduces Pay-to-Merkle-Root (P2MR), a new output type based on Taproot but with the quantum-vulnerable key-path spend removed. P2MR addresses (beginning with "bc1z") force all spends through script paths, eliminating direct public key exposure. Trade-off: slightly higher transaction fees due to additional witness data.
BIP-361 ("Post Quantum Migration and Legacy Signature Sunset") proposes a three-phase timeline:
Neither proposal has achieved broad developer consensus. Critics call the approach "highly authoritarian and confiscatory," arguing that mandatory migration contradicts Bitcoin's foundational principle of sovereign control over funds. The core dilemma: freezing old address formats protects coins from quantum theft but renders them permanently inaccessible — including Satoshi's estimated 1 million BTC — unless Phase C materializes. Leaving them unfrozen creates a target for the first entity to achieve quantum capability.
BTQ Technologies has implemented BIP-360 on a Bitcoin testnet (v0.3.0), but mainnet activation requires a soft fork with broad community support. No activation timeline exists.
Ethereum's approach differs structurally from Bitcoin's. The Ethereum Foundation formed a dedicated Post-Quantum Security team in January 2026, building on research dating to 2018. According to the Foundation, more than 10 independent client teams participate in regular post-quantum devnets. The work is tracked publicly at pq.ethereum.org.
Key technical components:
The Ethereum Foundation has outlined structured fork milestones targeting completion of core post-quantum infrastructure by approximately 2029 — aligning with Google's estimated timeline for when quantum threats could materialize.
On April 27, 2026, the Solana Foundation published its post-quantum migration strategy. Two core developer teams — Anza and Jump Crypto's Firedancer — independently converged on the Falcon post-quantum signature scheme.
Falcon was selected for its balance of security and compact signature size, a critical consideration for Solana's throughput-intensive architecture. The Foundation stated that migration would be "manageable and unlikely to significantly impact performance."
The phased roadmap includes:
An existing quantum-resistant primitive, Blueshift's "Winternitz Vault," has operated on Solana for over two years and was recently cited by Google Quantum AI.
In an April 21, 2026, report, Coinbase's six-member advisory board — including Prof. Scott Aaronson (University of Texas), Prof. Dan Boneh (Stanford), Justin Drake (Ethereum Foundation), and Prof. Sreeram Kannan (Eigen Labs) — issued a structured assessment.
Key data points from the report:
The panel recommended a "1-of-2 signing" strategy: transactions accept either classical or post-quantum signatures during a transition period. This avoids a hard cutoff while enabling gradual migration.
Post-quantum signatures are substantially larger than current schemes. This creates a direct throughput and cost trade-off for every blockchain:
| Scheme | Signature Size | Multiple of Current ECDSA | |--------|---------------|---------------------------| | ECDSA (current) | 64 bytes | 1x | | ML-DSA (NIST standard) | 2,420 bytes | 38x | | Falcon-512 | 666 bytes | 10x | | leanXMSS + zkVM compression | ~10 bytes (compressed) | <1x |
Solana's choice of Falcon reflects a preference for a middle ground: 10x the current size, but compact enough for high-throughput operations. Ethereum's compression approach via leanVM targets near-zero overhead but adds computational complexity.
The signature size issue explains why migration is not a simple swap. Every transaction on every block gets heavier, increasing storage costs, bandwidth requirements, and potentially fees — unless compression or aggregation schemes are deployed alongside the migration.
The quantum threat to blockchain cryptography crossed a threshold in April 2026 — not because current systems are in danger, but because the estimated cost and timeline of an attack contracted materially. Lelli's 15-bit demonstration, the Caltech/Oratomic qubit reduction, and Google's revised estimates collectively shifted the conversation from theoretical to engineering.
The industry response reveals structural differences in blockchain governance. Ethereum's centralized development coordination enables a faster, more systematic migration. Bitcoin's decentralized governance model, while resistant to capture, also resists the coordinated emergency action that quantum migration may eventually require. Solana's smaller validator set and corporate development structure allowed the fastest alignment on a specific solution.
NIST's 2035 deadline and Google's 2029 estimate bracket a window during which migration must substantially complete. For the approximately $520 billion in exposed Bitcoin, the clock is running against both quantum progress and governance inertia.