AI Just Cut the Cost of Cracking Bitcoin’s Encryption in Half. Is Q-Day Getting Closer?

A new cryptography paper just slashed the estimated cost of one critical step in a quantum attack on Bitcoin, and it happened in roughly two months. The researchers behind it are now asking whether the industry's Q-Day timelines need to…

Published September 11, 2026, 6:32pm ET · 4 min read

A close-up of a hand in a suit pointing with its index finger at a glowing blue digital display. The display features a stylized circuit board design with bright blue lines and a central processor chip. The words 'QUANTUM COMPUTING' are prominently displayed on the chip, composed of small glowing squares. In the blurred background, tall buildings of a city skyline are visible with orange light.
A hand points to a conceptual quantum computing chip, symbolizing the profound impact of this technology on digital security and the accelerated timeline towards 'Q-Day' for cryptocurrencies like Bitcoin. © Funtap / Shutterstock.com

Bitcoin (CRYPTO: BTC) is trading around $79,000, but the more important number for Bitcoin’s long-term future may have nothing to do with its price. A new cryptography paper has cut the estimated cost of one key step in a future attack on Bitcoin’s encryption by roughly 50% compared with Google Quantum AI’s March benchmark.

That does not mean someone is about to hack Bitcoin. The quantum computers needed to run the attack do not exist yet. But the result shows how quickly the estimates can change as researchers find more efficient ways to build the circuits needed to crack Bitcoin’s cryptography.

The paper, posted to arXiv on September 9, comes just months after Google’s benchmark and is already forcing some researchers to rethink how long Bitcoin has before quantum computers become a serious threat. The Head of Product Growth at StarkWare has argued that the industry should revisit its Q-Day estimates, because improvements like this can shorten the runway faster than expected. So does a 50% cut in two months move Q-Day closer?

Paper Cuts the Benchmark 50% Below Google’s March Figure

Famale Engineer in Front of Quantum Computer

Shutterstock

Researchers posted the paper to arXiv on September 9, as part of the ECDSA.Fail open challenge launched by Eigen Labs in May. The goal was straightforward but difficult. They wanted to find a cheaper way to perform one of the key arithmetic steps that a quantum computer would need to break the cryptography protecting Bitcoin and Ethereum (CRYPTO: ETH). That step involves elliptic-curve point addition inside Shor’s algorithm, which could eventually be used to work backward from a public key to its private key.

The researchers brought the estimated resource requirement down 86.1% from the project’s starting point in May. Their final benchmark comes to roughly 1.5 billion, based on 1,151 logical qubits and about 1.3 million Toffoli gates. That is roughly half of Google’s March 2026 benchmark of about 3 billion. A Toffoli gate is a three-qubit operation and one of the costly pieces of the calculation when the circuit is translated into hardware.

The numbers went even lower in designs completed after the paper’s official cutoff. Those versions reached as low as roughly 950,000 Toffoli gates in one gate-optimized design, and as few as 813 logical qubits in a separate, qubit-conserving design. That is the eye-catching part of the research, but it is also where the comparison needs some caution.

The authors acknowledge that their figures and Google’s are not perfectly comparable because the two teams measure resources differently. The 50% gap therefore should not be taken to mean Bitcoin’s quantum defenses suddenly became twice as weak. The more important point is that researchers are finding ways to make the theoretical attack cheaper, and those improvements can change the assumptions behind how far away Q-Day really is.

What the Paper Actually Measures

A digital graphic featuring a human hand in a dark suit touching a bright, glowing blue wireframe sphere. The sphere displays pixelated white text 'QUANTUM COMPUTING' and is surrounded by interconnected lines and various technology icons like processors, lightbulbs, and smart devices. A faint world map made of dots is visible in the dark blue background.

Harsamadu / Shutterstock.com

The circuits skip error correction and cover only part of Shor’s algorithm, which means the paper is measuring a much smaller piece of the attack than what a real quantum computer would eventually have to perform. Error correction is the machinery that keeps quantum calculations stable despite noise, and adding it to a practical attack would create a much larger resource requirement than the arithmetic measured here. No quantum computer available in September 2026 is anywhere close to running these circuits, so Bitcoin’s keys remain safe and wallets remain intact. What the paper shows is how much cheaper one important step in a future attack could become.

More than 100 contributors from the Ethereum Foundation, Eigen Labs, StarkWare, Starknet Foundation, Theta Labs, Brevis, Sei Labs, Trail of Bits and MultiVM Labs worked on the challenge, with human researchers using AI coding agents to help design and optimize the circuits. The agents proposed changes that could reduce the computational cost, while human researchers tested and verified those suggestions before they were included. That makes the result less about one team finding a clever shortcut and more about what an open research effort can produce when AI becomes part of the optimization process.

Oli Freuler of StarkWare captured the significance of that shift when he said, “Google kept its circuits private. ECDSA.fail’s open community and AI agents more than halved Google’s benchmark score in about two months.” His point is not that Bitcoin can now be cracked, because it cannot. The concern is what happens if the same process keeps producing large efficiency gains, because every major reduction in the cost of the underlying attack changes the assumptions behind today’s Q-Day estimates. A threat that remains years away can still become a much closer problem if the cost of reaching it keeps falling faster than expected.

Does This Move Q-Day Closer?

Google’s March 2026 paper counted roughly 6.9 million Bitcoin in addresses with public keys already visible on-chain, along with about 20.5 million Ethereum. Those coins would face the earliest risk from a sufficiently powerful quantum computer. Ethereum is targeting quantum resistance by December 2029, while Ripple is targeting a 2028 mainnet amendment, but both timelines were set before the latest ECDSA.Fail benchmark.

The paper does not move Q-Day closer by itself because no quantum computer ran the attack. What it does change is the assumption behind the timeline. If researchers can cut the estimated cost of a key part of the attack by roughly 50% in two months, future Q-Day forecasts need to account for the possibility that the cost of reaching the threat could keep falling faster than expected. Q-Day is not here, but the runway may be shorter than the industry thought.

Contact [email protected] for any questions or corrections.

Sam Daodu

Sam Daodu is a crypto analyst who's spent nearly a decade making blockchain understandable—no easy task when most whitepapers read like fever dreams. He writes for 24/7 Wall St., covering Bitcoin, altcoins, and crypto market analysis for investors. Before crypto, he was a tech writer (back when explaining "the cloud" was peak innovation). Since 2018, he's written for CoinTelegraph, Yahoo Finance, The Block, Cryptonews, Zypto, Rain, and more—basically anywhere people want crypto news without the headache. Sam runs MacLabs Marketing, a content agency for crypto brands tired of sounding like AI wrote their website. He also publishes free crypto education on his site for Web3 enthusiasts who think "gas fees" is a typo. When he's not writing or staring at charts, Sam's either: - Watching anime (currently convinced One Piece has better tokenomics than most altcoins) - At the gym sculpting himself into a Greek god - Listening to the music your mum warned you only bad boys listen to Connect: LinkedIn | Email | MacLabs Marketing

All articles →