Quantum Computers May Crack Bitcoin's Cryptography Sooner Than Expected
Researchers from Google Quantum AI and Ethereum have revised their estimates for how much quantum firepower is needed to crack Bitcoin's elliptic-curve cryptography. In a paper published in March 2026, they found that roughly 1,200 to 1,450 logical qubits and tens of millions of Toffoli gates could be sufficient to break the secp256k1 discrete logarithm problem.
Bitcoin and Ethereum's transactions use elliptic-curve cryptography, which could be vulnerable to quantum computers. A sufficiently powerful quantum computer could derive the private key from an exposed public key and redirect funds before a block is finalized.
An estimated 6.9 million BTC are sitting behind already-revealed public keys, making them vulnerable even without an active transaction. Millions of ETH face the same problem.
Dan Boneh, a researcher at Stanford, has warned that the industry needs to prepare for quantum computers now, but with surgical precision rather than panic. He is advocating for hash-based signatures, specifically schemes like SLH-DSA (also known as SPHINCS+), which are better suited to existing blockchain infrastructure.
Boneh has also proposed a mechanism for proving ownership of coins in a post-quantum world: leaving a cryptographic note on-chain today that would remain verifiable even after quantum computers render current signature schemes obsolete.