More than a hundred researchers use AI programming agents to reduce the resource score of quantum attacks on Bitcoin by 86.1%
According to a paper published on September 9, more than 100 researchers use AI encoding agents to successfully reduce the resource score of key parts of the quantum attack against Bitcoin by 86.1%. This progress does not mean a breakthrough in hacking technology that can crack Bitcoin or recover private keys. Instead, it shows that the quantum resources required for elliptic curve operations can be significantly reduced through software optimization alone.
The real question is not whether Q-Day (Quantum Computing Threat Day) is imminent, but that every technological advancement that reduces the cost of quantum attacks will allow Bitcoin and other types of blockchains to be used to achieve a secure and successful post-quantum security transition becomes shorter.
What does ECDSA.Fail actually optimize?
Eigen Labs launched ECDSA.Fail in late May, aiming to challenge how to make the secp256k1 dot-add circuit more efficient. The scoring mechanism is calculated by multiplying the maximum number of logical qubits used by the average number of Toffoli gates executed.
On July 26, the score dropped from 10.75 billion to 1.496 billion. The top score used 1,151 logic qubits and about 1.3 million Toffoli gates, but in subsequent attempts the number of gates dropped below a million, with one design requiring only 813 qubits. According to Decrypt, researchers are exploring the mathematical principles behind the problem and have not really cracked the Bitcoin wallet. "Although the timing remains uncertain, the migration away from vulnerable cryptography has begun," the researchers wrote.
A complete attack still requires an unbuilt machine
End-to-end estimates provided by IonQ show that approximately 1,457 logic qubits and 39 million Toffoli gates are needed to achieve a full secp256k1 attack. This result corresponds to 19,397 physically trapped ion qubits, with a processing time of approximately 25.7 days. IonQ claims that the hardware is in line with the company's plans to achieve around 2028.
Calculations performed by Google researchers show that to efficiently implement a full secp256k1 attack, either 1,200 logic qubits and 90 million Toffoli gates, or 1,450 logic qubits and 70 million gates are needed. Thanks to the superconducting model, its circuits can run for several minutes with fewer than 500,000 physical qubits.
These numbers cannot be directly compared to the results of ECDSA.Fail. The reason is that ECDSA.Fail's optimization program only applies to the point addition subroutine. Fault-tolerant hardware required for real attacks does not currently exist.
Risk areas where Bitcoin has been exposed
According to Glassnode data, 6.04 million BTC are at risk of quantum attacks, accounting for 30.2% of the current supply, because their corresponding public keys have been disclosed on the blockchain. Of these, 1.92 million BTC were exposed in the output category, and another 4.12 million BTC were exposed due to behavioral patterns such as address reuse.
The second risk occurs when the hidden public key becomes public at the time of disbursement. In theory, a computer fast enough can calculate the private key before the transaction is confirmed.
The role of the patch and its limitations
BIP360 introduces a new output type called "Pay-to-Merkle-Root" that eliminates the threat to the Taproot keypath disbursement option, which is vulnerable to quantum attacks. While this will protect funds that are visible over the long term with the public key, it fails to address the quantum risks that exist in the short term after transactions enter the memory pool, nor does it provide a mechanism to automatically migrate funds to the new format.
Cryptopolitan previously reported that StarkWare also demonstrated quantum-secure Bitcoin transactions on the main website. This method requires hours of off-chain GPU work, uses non-standard miner direct connections, and fails to protect funds whose public keys have been exposed.
Avihu's breakthrough is important because it provides the psychological reassurance we and the assets themselves need. -- StarkWare CEO Eli Ben-Sasson
In practice, it provides breathing space rather than a cure. Ben-Sasson still prefers a protocol-level solution.
Migration windows, not machines, are the risks.
The bigger challenge lies in governance. As Coinbase's Independent Quantum Computing and Blockchain Advisory Committee report, approximately 1.7 million BTC are scattered among approximately 20,000 early P2PK public keys, stored in wallets believed to be controlled by Satoshi Nakamoto himself or to have lost access. Setting a deadline for the transfer of these funds could cause them to be frozen or someone to hack and steal them.
Ethereum aims to achieve full quantum resistance at the execution, consensus and data layers by December 2029; in addition, the company plans to be ready for Q-Day as early as 2030. At the same time, the G7 cyber expert group called for coordinated advancement of post-quantum migration work in the financial sector.
Therefore, before facing any quantum concerns, Bitcoin must first face market risks, especially the ambiguity about the migration process, custody methods, and dormant coins, which could cause trouble before the technology capable of decrypting secp256k1 was born.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC