Skip to content

Invest2 publishers3 min readPublished

More than 100 researchers with AI agents cut Bitcoin's quantum-attack benchmark sevenfold in two months

Eigen Labs' ECDSA.Fail leaderboard took the resource score for one step of a quantum key recovery from 10.75 billion to 1.496 billion by July 26, while the defense side works to fixed dates in 2029 and 2030.

The Investor · Invest desk

Illustration accompanying More than 100 researchers with AI agents cut Bitcoin's quantum-attack benchmark sevenfold in two months

What happened

  • Eigen Labs launched ECDSA.Fail in late May 2026 as an open leaderboard that ranked evaluator-checked quantum circuits for reversible point addition on the secp256k1 curve used by Bitcoin and Ethereum.
  • By the July 26 cutoff, more than 100 participants working with AI coding agents had taken the leading score from the contest's 10.75 billion baseline down to roughly 1.496 billion, a drop of 86.1 percent.
  • The preprint went up on arXiv on September 9, 2026, with lead author Jieyi Long of Theta Labs and co-authors from the Ethereum Foundation, StarkWare, the Starknet Foundation, Trail of Bits, Brevis and Sei Labs.
  • The authors say the result is not a working attack, and that no present-day quantum computer can run the full algorithm at cryptographic scale.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • constraint Migration runs on calendar dates while the benchmark runs on submissions, and the December 2029 target leaves about 39 months from the preprint to convert transactions, validators and storage.
  • cost The publicly committed defense money is about $5 million a year across nine firms plus Galaxy Digital's up-to-$5 million, and each further cut in the benchmark widens what that spending has to cover.
  • contradiction The same result is a 7.2x cut against the contest's own baseline and more than 50 percent below Google Quantum AI's March figure, and with different accounting conventions on each side, the multiple quoted depends on the baseline chosen.
  • precedent A verifier-gated leaderboard with AI agents is now a demonstrated way to move any benchmark with a checkable objective, and this one published its circuits where Google's estimate came with a zero-knowledge proof.

The score is a product, so which factor moved matters. Contest entries were ranked by peak logical qubit width multiplied by average executed Toffoli-gate count [1]. At the July 26 cutoff the leading circuit ran 1,151 logical qubits against about 1.30 million Toffoli gates, and 1,151 times 1.30 million is 1.496 billion [4][1]. Submissions kept coming after the cutoff. One later design got the gate count under a million and another got the qubit width down to 813, each at the expense of other resources [10]. Multiplying those two records together would give 813 million, a further 46% off the published figure, but the paper describes them as separate designs that each gave up something elsewhere [3][10].

What 1.496 billion counts is one arithmetic step: reversible point addition over secp256k1, the operation Shor's algorithm repeats many times to get from a public key to a private one [2]. The paper excludes error correction, magic-state factories and the other hardware costs a complete end-to-end break would require [8]. A second circuit, adapted to the single-call interface used in windowed versions of Shor's algorithm, scored about 1.96 billion after adjusting for measured success probability on random inputs [9].

The defense side is working to calendar dates. The Ethereum Foundation set a December 2029 deadline to make transactions, validators and storage quantum-resistant [17]. The researchers wrote that "NIST has standardized post-quantum replacements, and the initial public draft of NIST IR 8547 proposes deprecating classical public-key algorithms at the 112-bit security level after 2030 and disallowing them after 2035" [13]. From the September 9 preprint, December 2029 is about 39 months out [5]. The committed money is smaller than those horizons. Galaxy Digital committed up to $5 million in July, and nine firms including BlackRock, Coinbase and Strategy pledged $15 million over three years for broader Bitcoin security research including quantum defenses [18]. That is $5 million a year across nine names, or roughly $555,000 each per year if split evenly [4].

Tyler Warner writes Decrypt's Morning Minute, and Decrypt says his opinions are his own. He wrote that "every timeline in this space was built assuming attack research moves at human speed, and this is the first hard evidence it might not" [20]. Warner also wrote that no funds are at risk today [21]. I would put the finding narrower. A leaderboard with a verifier attached moved a defined score by 86% in about two months [11][22], and the score it moved sits above the hardware layer that dominates the cost of a real break [8]. None of the three accounts puts a date on Q-Day. The exposure the paper points to is public-key reuse and older address formats, which the authors say leave large amounts of value exposed once a sufficiently large fault-tolerant machine exists [19].

I would be wrong if the same verifier-gated process is aimed at error correction and magic-state distillation and takes comparable percentages off those. Then 2029 and 2030 are the wrong dates to be planning against. The other way this runs is that the contest found most of the available structure in point addition in its first two months. Later entries trade one resource for another, and the curve flattens well above what any machine can reach.

What to watch

  • Whether the Ethereum Foundation's December 2029 deadline for quantum-resistant transactions, validators and storage holds once post-cutoff submissions are scored.
  • Whether Google Quantum AI publishes point-addition circuit details under accounting that can be compared with the contest's score.
  • Whether further commitments follow Galaxy Digital's up-to-$5 million and the nine-firm $15 million pledge.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories