📈 Get daily crypto insights that make you smarter about your money

AI Agents Slashed the Cost of a Quantum Attack on Bitcoin by 86 Percent — and the Race Just Got Real

AI coding agents have cut the estimated resource cost of a key step in a potential quantum attack on Bitcoin and Ethereum by 86 percent, according to a research paper posted Wednesday on arXiv. The result comes from ECDSA.Fail, an open competition launched by Eigen Labs in late May, and it forces a uncomfortable question for the crypto industry: if artificial intelligence can make quantum cryptanalysis cheaper this quickly, how much time does the ecosystem really have before Q-Day?

The numbers behind the 86 percent reduction

More than 100 participants, many working alongside autonomous AI coding agents, competed to optimize quantum circuits for secp256k1, the elliptic curve that secures transaction signatures on both Bitcoin and Ethereum. Breaking that signature scheme would allow an attacker to recover a wallet’s private key and steal its funds.

The challenge scored each circuit by multiplying its logical qubit count by its Toffoli gate count, a costly quantum operation invented by Tommaso Toffoli in 1980. A lower score means the calculation requires fewer combined quantum resources, and therefore that a future attack would be easier to execute on real hardware.

The starting benchmark was a resource score of 10.75 billion. By July 26, participants had driven that figure down to 1.496 billion, an 86 percent reduction. The leading design used 1,151 logical qubits and roughly 1.3 million Toffoli gates. A later refinement pushed the gate count below one million. According to the study, the best score was roughly half of Google Quantum AI’s March benchmark, although the authors caution that differences in testing and counting methods prevent a direct comparison.

An important caveat: the tests verified that the circuits performed the required calculation correctly. Nobody cracked an actual Bitcoin private key. The exercise also excludes the enormous hardware costs of mounting a full attack, which would require a fault-tolerant quantum computer far beyond anything that exists today.

Human researchers, amplified by AI agents

The authors, who include researchers affiliated with Theta Labs, MultiVM Labs, Eigen Labs, Trail of Bits, StarkWare, and the Ethereum Foundation, describe the competition as a case study in what they call Open Autoresearch: a verifier-gated process in which humans and AI agents iteratively generate, implement, test, and share candidate improvements against a shared, measurable objective.

That framing matters as much as the raw numbers. The 86 percent improvement did not come from a single breakthrough in a laboratory. It came from a distributed search process in which AI agents rapidly explored design space and humans validated the results. If that methodology keeps working, resource estimates for quantum attacks could continue falling faster than the conservative timelines many in the industry assume.

The migration has already started

The researchers are blunt about the implication. Although the timing of Q-Day, the milestone at which quantum computers can break current cryptography, remains uncertain, migration away from vulnerable cryptography is already under way. The United States National Institute of Standards and Technology has standardized post-quantum replacements, and the initial public draft of NIST IR 8547 proposes deprecating classical public-key algorithms at the 112-bit security level after 2030 and disallowing them entirely after 2035.

For Bitcoin, the stakes are particularly acute. Roughly a quarter of all BTC sits in addresses that use exposed public keys, including the estimated 1.1 million coins mined by Satoshi Nakamoto, whose public keys have been visible on the blockchain for over a decade. Ethereum faces similar exposure, though its roadmap includes a more direct path to quantum resistance through account abstraction and hard-fork upgrades.

The industry is not standing still. In July, Galaxy Digital committed up to 5 million USD to quantum defense research, while a consortium of nine firms, including BlackRock, Coinbase, and Strategy, pledged a combined 15 million USD over three years for broader Bitcoin security research, including quantum defenses. Ethereum Foundation researchers have mapped out a transition plan, and projects like StarkWare have demonstrated quantum-safe transaction prototypes on Bitcoin testnets.

A moving target in both directions

The honest read of the ECDSA.Fail result is that quantum risk is a race between two moving targets. On one side, attack resource requirements are falling, now demonstrably faster when AI agents are applied to the problem. On the other, defense research, standardization, and migration tooling are accelerating too, with real budgets behind them.

What the competition removes is complacency. An 86 percent reduction in a benchmark score in roughly two months, achieved largely by AI-assisted optimization, suggests that static estimates of quantum timelines deserve skepticism. Exchanges, custodians, and long-term holders who have deferred thinking about post-quantum migration now have one more data point arguing that the transition window may be shorter than advertised.

Bitcoin traded around 77,000 USD at the time of writing, little changed on the day, as markets digest this week’s inflation data and position ahead of next week’s Federal Reserve decision. The quantum story is not moving prices today. But it is the kind of slow-burn structural risk that the industry ignores at its own peril, and the ECDSA.Fail paper just turned the flame up a notch.

The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.

16 thoughts on “AI Agents Slashed the Cost of a Quantum Attack on Bitcoin by 86 Percent — and the Race Just Got Real”

  1. 86 percent cheaper from an open contest with 100 random participants. and people still tell me quantum is a 2050 problem lol

    1. to be fair, a lower logical qubit times Toffoli count on paper still needs error corrected hardware we do not have. big gap between circuit math and an actual machine

      1. thats what people said about gpu costs for mining a decade ago. its the slope of improvement that should worry you, not the absolute number today

    2. open contest, 100 participants, ai agents, and an 86 percent cut. now extrapolate to whatever a state lab runs privately

    3. open autoresearch with verifier gates is the actual story here imo. 100 random participants iterating via AI and Eigen Labs publishes it anyway, that is either brave or terrifying

  2. secp256k1 secures signatures on both BTC and ETH, so this is not a bitcoin-only headline. credit to Eigen Labs for quantifying it in public instead of sitting on the data

  3. gates under a million from 1.3 million sounds great until you remember the leading design still needs 1151 logical qubits. nobody has that by a mile

  4. every year someone cuts the theoretical cost of breaking bitcoin and every year the hardware is still decades out. ill worry when a lab demos 50 stable logical qubits

      1. double digit logical qubits with error rates that still need distillation to do anything useful. the slope is scary, but decades to 1151 logical is arithmetic, not cope

      2. double digit logical qubits with error rates that still need distillation to do anything useful. the slope is scary, but decades to 1151 logical is arithmetic, not cope

  5. the math got 86 percent cheaper and every pre-2014 p2pk bitcoin is still sitting there unmoved. those coins are the actual canary

    1. the unmoved p2pk coins might just be lost keys, satoshi era wallets went with their owners. treat them as dust, not a canary

    2. the unmoved p2pk coins might just be lost keys, satoshi era wallets went with their owners. treat them as dust, not a canary

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$77,156.00-0.3%ETH$2,522.93-0.6%SOL$101.41-1.4%BNB$726.27-0.1%XRP$1.36-0.1%ADA$0.2073+0.2%DOGE$0.0848+0.3%DOT$1.03-2.2%AVAX$7.40-1.1%LINK$11.50-1.1%UNI$6.35+4.3%ATOM$1.61-2.1%LTC$53.64+0.3%ARB$0.1399-0.8%NEAR$2.35-6.1%FIL$0.8020+2.4%SUI$0.7225-1.2%BTC$77,156.00-0.3%ETH$2,522.93-0.6%SOL$101.41-1.4%BNB$726.27-0.1%XRP$1.36-0.1%ADA$0.2073+0.2%DOGE$0.0848+0.3%DOT$1.03-2.2%AVAX$7.40-1.1%LINK$11.50-1.1%UNI$6.35+4.3%ATOM$1.61-2.1%LTC$53.64+0.3%ARB$0.1399-0.8%NEAR$2.35-6.1%FIL$0.8020+2.4%SUI$0.7225-1.2%
Scroll to Top