More than 100 participants using AI coding agents cut the resource cost of a key step in a potential quantum attack on Bitcoin and Ethereum's cryptography by 86%, according to a paper posted Wednesday. The leading circuit used 1,151 logical qubits and about 1.3 million Toffoli gates, though the tests stopped short of cracking a real private key.
Researchers working with AI coding agents reduced a resource benchmark for a key step in a potential quantum attack on Bitcoin and Ethereum's cryptography by 86%, according to a paper posted Wednesday. The cut lowers the computing resources theoretically needed to derive a wallet's private key from its public key, a step that could let an attacker steal its funds.
ECDSA.Fail challenge drives the reduction
The findings came from ECDSA.Fail, an open competition Eigen Labs launched in late May. More than 100 participants built circuits for secp256k1, the elliptic curve that secures transaction signatures on Bitcoin and Ethereum. By July 26, participants had cut the challenge's resource score from 10.75 billion to 1.496 billion. The leading design used 1,151 logical qubits and about 1.3 million Toffoli gates, a costly type of quantum operation invented by Tommaso Toffoli in 1980. A later design brought the gate count below 1 million, though the results exclude the hardware costs of a full attack.
Tests verified the circuit's calculations only — they did not crack a Bitcoin private key. Still, according to the study, the score was roughly half of Google Quantum AI's March benchmark, though differences in testing and counting methods prevent a direct comparison.
Authors point to an ongoing migration effort
The paper's authors include researchers affiliated with Theta Labs, MultiVM Labs, Eigen Labs, Trail of Bits, StarkWare, and the Ethereum Foundation. According to the researchers: "migration away from vulnerable cryptography is already under way", they wrote in the paper. NIST has standardized post-quantum replacements, and the initial public draft of NIST IR 8547 proposes deprecating classical public-key algorithms at the 112-bit security level after 2030 and disallowing them after 2035.
Meanwhile, crypto firms have started funding this research directly. In July, Galaxy Digital committed up to $5 million to quantum-defense work. Nine firms — including BlackRock, Coinbase, and Strategy — separately pledged a combined $15 million over three years for broader Bitcoin security research, including quantum defenses.
The researchers described ECDSA.Fail as a case study in verifier-gated research, where human participants and AI agents iteratively test candidate improvements against a shared, measurable objective.
Source: Decrypt
Trading involves risk.