A collaboration between Google Quantum AI, the Ethereum Foundation, and Stanford has published a whitepaper detailing optimized quantum circuits that could break the elliptic curve cryptography underpinning Bitcoin and Ethereum. The key finding: fewer than 500,000 physical superconducting qubits would be needed, down from prior estimates of roughly 9 million. That’s a 20-fold reduction in the hardware required to run what amounts to a skeleton key for blockchain wallets.
The paper, dated March 30, 2026, focuses on solving the 256-bit elliptic curve discrete logarithm problem, known as ECDLP-256. This is the math problem that keeps private keys private. Crack it, and you can derive anyone’s private key from their public key. The researchers used Shor’s algorithm targeting the secp256k1 curve, which is the specific flavor of elliptic curve cryptography that Bitcoin and Ethereum both rely on.
The numbers that matter
The paper presents two circuit variants. One operates with a maximum of 1,200 logical qubits and 90 million Toffoli gates. The other uses 1,450 logical qubits and 70 million Toffoli gates. Execution time for these circuits clocks in at roughly 9 to 23 minutes depending on the variant, running on a standard superconducting surface-code architecture. Previous academic benchmarks suggested you’d need a quantum computer with around 9 million physical qubits. This paper argues you’d need fewer than 500,000.










