Don't want to trade it yourself?
Our desk runs DEX portfolios on profit share.
AI Just Cut the Cost of Cracking Bitcoin’s Encryption in Half. Is Q-Day Getting Closer?
A new cryptography paper just slashed the estimated cost of one critical step in a quantum attack on Bitcoin, and it happened in roughly two months. The researchers behind it are now asking whether the industry’s Q-Day timelines need to…
This post may contain links from our sponsors and affiliates, and Flywheel Publishing may receive compensation for actions taken through them.
Bitcoin(CRYPTO: BTC) is trading around $79,000, but the more important number for Bitcoin’s long-term future may have nothing to do with its price. A new cryptography paper has cut the estimated cost of one key step in a future attack on Bitcoin’s encryption by roughly 50% compared with Google Quantum AI’s March benchmark.
That does not mean someone is about to hack Bitcoin. The quantum computers needed to run the attack do not exist yet. But the result shows how quickly the estimates can change as researchers find more efficient ways to build the circuits needed to crack Bitcoin’s cryptography.
The paper, posted to arXiv on September 9, comes just months after Google’s benchmark and is already forcing some researchers to rethink how long Bitcoin has before quantum computers become a serious threat. The Head of Product Growth at StarkWare has argued that the industry should revisit its Q-Day estimates, because improvements like this can shorten the runway faster than expected. So does a 50% cut in two months move Q-Day closer?
Paper Cuts the Benchmark 50% Below Google’s March Figure
Researchers posted the paper to arXiv on September 9, as part of theECDSA.Fail open challengelaunched by Eigen Labs in May. The goal was straightforward but difficult. They wanted to find a cheaper way to perform one of the key arithmetic steps that a quantum computer would need to break the cryptography protecting Bitcoin and Ethereum (CRYPTO: ETH). That step involves elliptic-curve point addition inside Shor’s algorithm, which could eventually be used to work backward from a public key to its private key.
The researchers brought the estimated reMay. Their final benchmark comes to roughly 1.5 billion, based on 1,151 logical qubits and about 1.3 million Toffoli gates. That is roughly half of Google’s March 2026 benchmark of about 3 billion. A Toffoli gate is a three-qubit operation and one of the costly pieces of the calculation when the circuit is translated into hardware
The numbers went even lower in designs completed after the paper’s official cutoff. Those versions reached as low as roughly 950,000 Toffoli gates in one gate-optimized design, and as few as 813 logical qubits in a separate, qubit-conserving design. That is the eye-catching part of the research, but it is also where the comparison needs some caution.
The authors acknowledge that their figures and Google’s are not perfectly comparable because the two teams measure remean Bitcoin’s quantum defenses suddenly became twice as weak. The more important point is that researchers are finding ways to make the theoretical attack cheaper, and those improvements can change the assumptions behind how far away Q-Day really is
What the Paper Actually Measures
The circuits skip error correction and cover only part of Shor’s algorithm, which means the paper is measuring a much smaller piece of the attack than what a real quantum computer would eventually have to perform. Error correction is the machinery that keeps quantum calculations stable despite noise, and adding it to a practical attack would create a much larger resource requirement than the arithmetic measured here. No quantum computer available in September 2026 is anywhere close to running these circuits, so Bitcoin’s keys remain safe and wallets remain intact. What the paper shows is how much cheaper one important step in a future attack could become.
More than 100 contributorsfrom the Ethereum Foundation, Eigen Labs, StarkWare, Starknet Foundation, Theta Labs, Brevis, Sei Labs, Trail of Bits and MultiVM Labs worked on the challenge, with human researchers using AI coding agents to help design and optimize the circuits. The agents proposed changes that could reduce the computational cost, while human researchers tested and verified those suggestions before they were included. That makes the result less about one team finding a clever shortcut and more about what an open research effort can produce when AI becomes part of the optimization process.
Oli Freuler of StarkWare captured the significance of that shift when he said, “Google kept its circuits private. ECDSA.fail’s open community and AI agents more than halved Google’s benchmark score in about two months.” His point is not that Bitcoin can now be cracked, because it cannot. The concern is what happens if the same process keeps producing large efficiency gains, because every major reduction in the cost of the underlying attack changes the assumptions behind today’s Q-Day estimates. A threat that remains years away can still become a much closer problem if the cost of reaching it keeps falling faster than expected.
Does This Move Q-Day Closer?
Google’s March 2026 papercounted roughly 6.9 million Bitcoin in addresses with public keys already visible on-chain, along with about 20.5 million Ethereum. Those coins would face the earliest risk from a sufficiently powerful quantum computer. Ethereum is targeting quantum resistance by December 2029, while Ripple is targeting a 2028 mainnet amendment, but both timelines were set before the latest ECDSA.Fail benchmark.
The paper does not move Q-Day closer by itself because no quantum computer ran the attack. What it does change is the assumption behind the timeline. If researchers can cut the estimated cost of a key part of the attack by roughly 50% in two months, future Q-Day forecasts need to account for the possibility that the cost of reaching the threat could keep falling faster than expected. Q-Day is not here, but the runway may be shorter than the industry thought.
Contact [email protected] for any questions or corrections.
Sam Daodu is a crypto analyst who’s spent nearly a decade making blockchain understandable—no easy task when most whitepapers read like fever dreams. He writes for 24/7 Wall St., covering Bitcoin, altcoins, and crypto market analysis for investors. Before crypto, he was a tech writer (back when explaining “the cloud” was peak innovation). Since 2018, he’s written for CoinTelegraph, Yahoo Finance, The Block, Cryptonews, Zypto, Rain, and more—basically anywhere people want crypto news without the headache. Sam runs MacLabs Marketing, a content agency for crypto brands tired of sounding like AI wrote their website. He also publishes free crypto education on his site for Web3 enthusiasts who think “gas fees” is a typo. When he’s not writing or staring at charts, Sam’s either: – Watching anime (currently convinced One Piece has better tokenomics than most altcoins) – At the gym sculpting himself into a Greek god – Listening to the music your mum warned you only bad boys listen to Connect: LinkedIn | Email | MacLabs Marketing
Source: 247wallst.com
