Skip to content

Invest1 publisher3 min readPublished

Crowdsourced AI agents cut one step of a Bitcoin quantum attack by 86 per cent in about two months

Eigen Labs' ECDSA.Fail contest drove a point-addition resource score from 10.75 billion down to 1.496 billion. Neither IonQ nor Google has built the machine, and the end-to-end attack estimates that matter are still theirs.

The Investor · Invest desk

Illustration accompanying Crowdsourced AI agents cut one step of a Bitcoin quantum attack by 86 per cent in about two months

What happened

  • A paper published on September 9 reports that more than 100 researchers using AI coding agents cut the resource score for a key secp256k1 point-addition subroutine by 86.1 per cent.
  • Eigen Labs' ECDSA.Fail challenge, opened in late May, scored designs by logical qubits times Toffoli gates, and the score fell from 10.75 billion to 1.496 billion on July 26.
  • BIP 360 adds a Pay-to-Merkle-Root output that removes Taproot's vulnerable key-path spend, without covering mempool exposure or migrating existing coins automatically.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • constraint Because the 86.1 per cent applies to one subroutine, no one can yet price what it takes off the end-to-end attack, so the only comparable totals remain IonQ's and Google's separately computed estimates.
  • decision Sixty-eight per cent of the at-risk coins are exposed through address reuse. That puts the migration schedule in the hands of individual holders deciding to move funds.
  • exposure The window between broadcast and confirmation stays open under both BIP 360 and StarkWare's method, so a spender reveals a public key with no available cover.
  • precedent A public contest cut a published resource figure sevenfold in about two months. Any circuit cost estimate is a perishable input to migration planning.

The scoring rule is maximum logical qubits multiplied by average Toffoli gates, so a design gets cheap by shrinking either factor [3]. The winning entry's 1,151 logical qubits and roughly 1.3 million Toffoli gates multiply out to 1.4963 billion, and that is the 1.496 billion that closed the contest on 26 July [5][4][1]. Later entries pushed the gate count below a million, and one design ran on 813 qubits [6].

Put IonQ's end-to-end estimate through the same multiplication and you get 56.8 billion, or about 38 times the winning point-addition score [7][3]. That comparison is not legitimate, and the paper says as much, because the contest optimised one subroutine inside the attack [9]. Google's researchers put the full job at 1,200 logical qubits and 90 million Toffoli gates, or 1,450 qubits and 70 million gates [8].

The hardware gap between the two end-to-end estimates is wider than the gate counts suggest. IonQ's 19,397 physical trapped-ion qubits against 1,457 logical ones works out at 13.3 physical per logical, and the run takes about 25.7 days [7][4]. Google's superconducting circuit finishes in minutes and needs fewer than 500,000 physical qubits, under 417 for each logical one [8][4]. IonQ says the hardware fits plans it has set for around 2028 [7].

Glassnode counts 6.04 million BTC whose public keys are already on chain, 30.2 per cent of supply, which implies about 20 million coins in circulation [10][5]. Split that figure and 1.92 million sit in the output category, 4.12 million in the behaviour category, largely address reuse [11]. Sixty-eight per cent of the exposed coins are exposed because a holder reused an address [6].

That tranche is the constraint. BIP 360's Pay-to-Merkle-Root output removes Taproot's quantum-vulnerable key-path spend, but it does not migrate coins automatically, and it does not cover the interval while a transaction sits in the mempool with its public key revealed [13][12]. StarkWare's quantum-safe mainnet transaction needed hours of off-chain GPU work and a nonstandard miner-direct route, and it cannot protect keys that are already public [14].

So the efficiency work moves the attacker's cost, and 4.12 million coins stay where they are [11]. On this evidence the schedule is set by how fast holders move coins into new output types; the Toffoli count is the number a public contest cut by 86.1 per cent in roughly two months [1][8]. "Although its timing remains uncertain, migration away from vulnerable cryptography is already under way," the researchers wrote [15]. According to Decrypt, they were testing whether the maths behind the problem worked and did not hack a Bitcoin wallet [16].

The paper published on 9 September measures a subroutine [1][9]. What would change the reading is an end-to-end estimate that folds the optimised point addition into the full circuit and reports a Toffoli count well under IonQ's 39 million.

What to watch

  • An end-to-end secp256k1 estimate that folds in the optimised point-addition circuit and reports a Toffoli count under IonQ's 39 million.
  • Whether IonQ holds or slips the roughly 2028 date for the 19,397-physical-qubit machine.
  • Wallet-level data showing the 4.12 million BTC address-reuse tranche shrinking, or a BIP 360 activation path that does not depend on holders acting.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories