AI agents have significantly reduced resource requirements for quantum attacks, putting millions of bitcoins at potential risk
According to a paper published on September 9, AI agents have helped researchers reduce resource scores for key quantum computing tasks related to Bitcoin by 86.1%. It should be emphasized that this result does not mean that Bitcoin has been compromised by hackers, but shows that software optimization can significantly reduce the quantum resources required to execute the secp256k1 elliptic curve algorithm.
This study only optimizes one specific part of the attack process-the secp256k1 point-add process, rather than a complete private key recovery attack. However, this development sounds a wake-up call for blockchain developers: post-quantum security solutions must be planned in advance before fault-tolerant quantum computers become practical.
Significant drop in quantum resource scores
In May this year, Eigen Labs launched the "ECDSA.Fail" competition to improve the secp256k1 point adding circuit. The competition measures the merits of a design by "multiplying the number of logical qubits used by the average number of Toffoli gates."
As of July 26, the resource score has dropped from 10.75 billion to 1.496 billion. One of the leading designs uses 1,151 logic qubits and about 1.3 million Toffoli gates. Subsequent entries further reduced the gate count to below one million, with another design even requiring only 813 qubits.
IonQ estimates that a complete secp256k1 attack requires approximately 1,457 logic qubits and 39 million Toffoli gates. Its model translates these requirements into 19,397 physical ion trap qubits and approximately 25.7 days of processing time. In addition, Google researchers have released higher-scale gate count estimates, whose models predict that a full attack will require 1,200 to 1,450 logic qubits and 70 million to 90 million Toffoli gates. Because ECDSA.Fail optimizes only one of the subroutines, it cannot be directly compared to the full attack model.
Millions of Bitcoin public keys have been exposed
Glassnode data shows that approximately 6.04 million BTC (30.2% of the total supply) are currently at risk of public keys being exposed. Among them, approximately 1.92 million BTC are in directly exposed output addresses, and another 4.12 million BTC are at risk of associated exposure due to user behavior (such as address reuse).
Another potential risk arises when the hidden public key becomes visible after the transaction is spent. In theory, if a quantum computer is powerful enough, it could deduce the private key before the transaction is confirmed.
Response Strategies and Future Outlook
BIP360 proposes a "Pay-to-Merkle-Root" output type to reduce exposure risks from Taproot keypath spending. However, the proposal does not eliminate short-term risks in memory pools, nor does it automatically protect old coins or already exposed assets.
An advisory report from Coinbase noted that approximately 1.7 million BTC are still stored in early P2PK addresses that may be related to Satoshi or lost wallets. Developers must decide how migration rules should handle these dormant assets.
In terms of overall industry planning, Ethereum aims to achieve broad quantum resistance by December 2029, while the G7 also urges the coordination of post-quantum security planning in the financial sector in future migration plans.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC