A Google-led research team cut the physical qubit count needed to break the elliptic-curve cryptography securing Bitcoin and Ethereum to fewer than 500,000, down from roughly 9 million in prior academic benchmarks, according to a whitepaper dated March 30, 2026.
The paper, produced by Google Quantum AI with the Ethereum Foundation and Stanford University, targets the 256-bit elliptic curve discrete logarithm problem on the secp256k1 curve that both networks use for signatures. It presents two circuit variants: one running 1,200 logical qubits and 90 million Toffoli gates, the other 1,450 logical qubits and 70 million gates, executing in roughly nine to 23 minutes on a standard superconducting surface-code architecture.
"Migration to post-quantum signature schemes is a multi-year engineering program, not a switch we can flip when the hardware arrives," Dan Boneh, a Stanford cryptographer and co-author of the paper, said.
The researchers verified their claims with zero-knowledge proofs rather than publishing the circuit designs. A separate study from Caltech and Oratomic put neutral-atom requirements as low as 10,000 to 26,000 physical qubits for comparable computations, though those systems would need days rather than minutes.
6.9 million BTC and 20.5 million ETH sit in exposed wallets
The exposure is concentrated in address formats that broadcast a public key rather than a hash of one. The paper estimates about 6.9 million BTC sit in wallets with visible public keys, of which roughly 1.7 million come from legacy Satoshi-era P2PK outputs. On Ethereum, about 20.5 million ETH face similar exposure, and administrative keys controlling stablecoin and tokenized-asset contracts govern assets the paper values at about $200 billion.
The paper also models an "on-spend" attack, in which a quantum computer intercepts a public key revealed during broadcast and derives the private key before confirmation. Bitcoin's average 10-minute block interval gives that attack roughly a 41% success probability under the paper's conditions.
No machine in existence approaches the threshold. Google's most advanced publicly known processor, Willow, operates with 105 qubits.
Ethereum's 2029 deadline meets Bitcoin's non-upgradeable outputs
The Ethereum Foundation has made quantum resistance a top priority with a 2029 deadline, and the US government has backed a $300 million hardware push, according to CoinDesk reporting. Those are the only dated commitments attached to the benchmark revision so far; Bitcoin Core has not published a post-quantum migration timeline, and no major custody provider has committed to a date for rotating legacy address formats.
That asymmetry is the practical problem. Ethereum's account model and its history of coordinated upgrades give it a path to a new signature scheme. Bitcoin's 1.7 million P2PK coins are a different case: their public keys are already on-chain, so no software upgrade can retroactively hide them. Owners must move those coins to new addresses, and the coins have sat unmoved for more than a decade.
For holders, the defensive playbook is unchanged by the new numbers. Wallets that have never broadcast a transaction have never exposed a public key and remain out of reach of an at-rest attack. Using a fresh address for every transaction and avoiding address reuse removes the exposure that the paper quantifies.
The near-term market read is muted. The benchmark revision changes a multi-year structural risk, not a price catalyst, and the gap between 500,000 physical qubits and Willow's 105 is wide enough that no dated threat exists. What the paper does change is the cost of delay: every year that Bitcoin Core, the Ethereum Foundation, and custody providers leave migration unscheduled, the pool of exposed coins grows larger and the eventual rotation more disruptive.
This article is for informational purposes only and does not constitute investment advice.