Bitcoin Sees Quantum Closing In Faster Than Expected

Giant lock marked 813 qubits showing a Bitcoin key growing easier to break

Quantum computing is gaining on Bitcoin faster than projections assumed. The public ecdsa.fail scoreboard has posted a new floor since August 31: on paper, 813 logical qubits are now enough to break a Bitcoin key, the signature guarding every address. In 2017 the literature asked for 2,330. That is a 65% drop in nine years, and it comes mostly from circuits optimized by artificial intelligence rather than from better hardware.

Key Takeaways

  • The theoretical bar for breaking a Bitcoin key falls from 2,330 to 813 logical qubits.
  • Circle shipped a public counter in late August tracking lab progress against the attack threshold.
  • Google’s best processor tops out at 105 logical qubits today.

The Floor Drops From 2,330 Qubits to 813

The ecdsa.fail site, built by Eigen Labs, works as a leaderboard. Researchers and automated agents compete to shrink the quantum circuit capable of breaking secp256k1, the elliptic curve signing every Bitcoin and Ethereum transaction.

The best known circuit for breaking a Bitcoin key sits at 813 logical qubits as of August 31, against an academic estimate of 2,330 back in 2017. The gain came from writing the attack better, not from a bigger machine. AI-assisted optimization drives most of the drop, and the ranking is open to read in the public scoreboard Eigen Labs maintains.

A logical qubit is not a physical one. It takes thousands of physical qubits under constant error correction to hold a single stable logical qubit. That conversion is what still separates the theoretical number from any machine in existence.

Which is why a figure like this circulates without moving a single price. It describes the cost of an ideal attack, on perfect hardware, under conditions nobody knows how to build yet. What it really measures is how fast the target is closing in.

The topic is not new to the market. An estimate putting millions of BTC at risk by 2030 was already circulating in June, and it rested on thresholds far above the one posted today.

What has changed since is the direction of travel. Each revision of the number has moved down rather than up, and none of them required a hardware breakthrough to get there. A threshold that only ever falls is a different kind of problem from one that holds steady.


Quantum
Advertisement – investing involves risk.

Circle Puts a Public Counter on the Closing Gap

Circle, the issuer behind USDC, released a monitoring tool in late August called the Quantum Tracker. It plots on one chart the line of logical qubits actually demonstrated in laboratories against the attack threshold required to break ECDSA.

The company paired the launch with a warning. It argued that quantum computing is closing the gap to blockchain security faster than projections assumed, after recording that same 65% decrease in the computational requirements.

The move says something about timing. A stablecoin issuer does not install a public counter for educational purposes. It does it because migration has turned into a dated engineering decision, with a budget and a running order. The exposure has been quantified before, with an estimate putting 7M BTC at risk by 2030 circulating back in June.

The exposure also runs wider than Bitcoin. A stablecoin circulates across dozens of chains, and its security ends up worth whatever the slowest one to migrate is worth. An issuer can harden its own stack and stay exposed through the networks that carry it.

One caveat belongs here before anyone panics. ECDSA is not broken, and no wallet is vulnerable to an ordinary attacker today. The leaderboard measures future resources, not present-day theft capability.


Also on Cryptonomic:


What 105 Qubits in a Lab Actually Mean

Hardware reality sits a long way from the threshold. Google’s Willow processor tops out at 105 logical qubits today, against the 813 needed to run the best known circuit. A Google study from April 2026 separately put the requirement against a 256-bit key at under 500,000 qubits, where earlier work talked in millions.

What a holder should watch is not the date of the first capable machine. It is the harvest now, decrypt later approach. A well funded actor can collect exposed public keys today and simply wait for the compute to arrive.

That mechanic reorders the priorities. An address that has already spent, and therefore revealed its public key, sits exposed well ahead of the rest. Migrating to resistant signatures is not waiting on hardware. It is waiting on a decision, and a first quantum-resistant Bitcoin transaction going out in August shows the building block already exists.

There is an uncomfortable corollary for long-term holders. Coins parked in addresses that were used years ago cannot be protected retroactively without moving them, and moving them is exactly what many cold storage strategies were designed to avoid.

Bitcoin changes its rules slowly though, and the BIP-110 fork stalling after just two blocks was a reminder that consensus changes negotiate badly under pressure.

For the months ahead the indicator is simple enough. It is not a vendor announcing a qubit record. It is the pace at which the theoretical cost of a Bitcoin key keeps sliding. Another halving of that number would push the debate out of theory and into roadmap territory, and it would do so long before any machine exists to act on it.

Follow the story on Cryptonomic.

Comments

No comments yet. Why don’t you start the discussion?

    Leave a Reply

    Your email address will not be published. Required fields are marked *