86%
Reduction in quantum circuit resource score achieved by researchers 2
1,151
Logical qubits utilized in the leading quantum circuit design 2
Over 99%
Proposed reduction in Ethereum quantum-safe private transaction costs via EIP-8288 3
256
Qubits in IonQ's newly unveiled Superion quantum computer 4

The ECDSA.Fail Breakthrough

In late May 2026, Eigen Labs launched an open competition called ECDSA.Fail to optimize quantum circuits for secp256k1, the elliptic curve cryptography that secures transaction signatures on both Bitcoin and Ethereum 2. By July 26, 2026, participants in the competition succeeded in reducing the resource score for a key step in a potential quantum attack by 86% 2. The resource score dropped from 10.75 billion to 1.496 billion 2. This score is calculated by multiplying the number of logical qubits by the number of Toffoli gates, which are expensive quantum operations first designed in 1980 2.

The leading circuit design in the competition utilized 1,151 logical qubits and approximately 1.3 million Toffoli gates 2. The research paper detailing these findings was co-authored by researchers from several organizations, including Theta Labs, MultiVM Labs, Eigen Labs, Trail of Bits, StarkWare, and the Ethereum Foundation 2. The researchers utilized AI coding agents to iteratively generate, implement, and test these candidate improvements 2.

Comparing Benchmarks and Quantum Mechanics

The newly achieved resource score is approximately half of the benchmark established by Google Quantum AI in March 2026, although direct comparisons are difficult due to variations in testing and counting methodologies 2. While these tests verified the mathematical calculations of the circuit, they did not actually crack a private key 2. Classical computers must search through 2^256 possible private keys linearly or in parallel, a task that is practically impossible due to the immense time and computational power required 1.

In contrast, quantum computers utilize qubits that exist in a superposition of both 1 and 0 simultaneously 1. By entangling these qubits, quantum algorithms can use constructive and destructive interference to alter the probabilities of different outcomes, allowing them to find a private key from a public key in a few runs without checking every option 1. This capability calls into question the foundational assumption of elliptic curve cryptography, which states that only the holder of a private key can sign transactions 1.

Ethereum's Mitigation Strategy

To defend against these emerging threats, Ethereum co-founder Vitalik Buterin has proposed EIP-8288, a standard co-authored with Thomas Coratger in June 2026 3. The proposal aims to reduce the gas costs of quantum-safe private transactions by more than 99% 3. Currently, verifying post-quantum signatures requires 150,000 to 200,000 gas, while quantum-safe private transactions can cost up to 10 million gas due to large STARK proofs that range from 128 to 512 kilobytes 3.

EIP-8288 would lower these costs to the low tens of thousands of gas by keeping the heavy cryptography off-chain 3. Instead, transactions would declare a 96-byte dependency claim, and mempool nodes would aggregate these claims to generate a single recursive STARK proof using the RISC-V instruction set 3. Buterin hopes to include this proposal in the "I-star" upgrade, which is planned to follow the "Hegota" upgrade 3.

Hardware Progress and Industry Funding

On the hardware front, IonQ unveiled its Superion 256 quantum computer on Tuesday, September 8, 2026 4. The system features 256-qubit processors fabricated by SkyWater, with deliveries scheduled to begin in 2027 4. IonQ is also developing the Superion 10K, aiming to demonstrate error-resistant computing in 2027 and start commercial production in 2028 4. However, a 256-qubit machine does not automatically break 256-bit security, as a successful cryptographic attack requires sustained, error-protected qubits 4.

To prepare for these developments, the National Institute of Standards and Technology (NIST) has standardized post-quantum replacements, proposing to deprecate classical public-key algorithms at the 112-bit security level after 2030 and disallowing them after 2035 2. Additionally, crypto firms are increasing funding for quantum defenses 2. In July 2026, Galaxy Digital committed up to $5 million for Bitcoin quantum-security research, while nine firms pledged a combined $15 million over three years for broader Bitcoin security research, including quantum defenses 24.

What is not yet established

  • The exact timeline for when a quantum computer powerful enough to execute a full cryptographic attack will arrive 2.
  • Whether the newly designed quantum circuits can be successfully executed on physical quantum hardware rather than simulated environments 2.
  • The exact schedule for Ethereum's Frames transaction overhaul and the subsequent Hegota and I-star upgrades 3.

Frequently asked questions

How does the newly designed quantum circuit reduce the resources needed for an attack?

The circuit reduces the resource score by 86% by optimizing the combination of logical qubits and Toffoli gates required to calculate secp256k1 private keys 2.

Does the release of a 256-qubit quantum computer mean Bitcoin's security is currently broken? [4]

No, because a 256-qubit machine does not automatically break 256-bit security; a successful attack requires sustained, error-protected qubits, which current hardware does not yet support 4.

What is Ethereum's plan to mitigate the high gas costs of quantum-safe transactions?

Ethereum co-founder Vitalik Buterin has proposed EIP-8288, which would move heavy cryptographic verification off-chain, reducing quantum-safe private transaction costs by more than 99% 3.

Sources

  1. Bitcoin Magazine — The Quantum Issue: WTF Is Quantum Computing? (2026-09-10) https://bitcoinmagazine.com/print/the-quantum-issue-wtf-is-quantum-computing
  2. Decrypt — AI Agents Just Slashed the Cost of a Quantum Attack on Bitcoin (2026-09-10) https://decrypt.co/377925/ai-agents-slash-cost-quantum-attack-bitcoin
  3. Decrypt — Vitalik Buterin Pushes Ethereum Plan to Slash Quantum-Safe Privacy Costs (2026-09-10) https://decrypt.co/377857/vitalik-buterin-pushes-ethereum-plan-to-slash-quantum-safe-privacy-costs
  4. Decrypt — While Bitcoin Devs Debate Next Moves, IonQ Unveils Superion 256 Quantum Computer (2026-09-09) https://decrypt.co/377737/bitcoin-debate-ionq-quantum-computer

This brief is for information and education. It is not financial advice or a recommendation to buy or sell.