A public hacking challenge sees over 100 contributors optimizing circuits, slashing logical-qubit and Toffoli-gate scores by 86% to accelerate post-quantum upgrades
More than 100 cryptography researchers have reduced by over 50% the estimated computational resources required for a critical subroutine in a hypothetical quantum attack on Bitcoin and Ethereum, beating a benchmark Google’s Quantum AI team published in March 2026.
According to The Block, the findings, released on 10 September, 2026, arrive as both blockchain networks accelerate plans to replace their current elliptic-curve cryptography with quantum-resistant alternatives before sufficiently powerful quantum hardware emerges.
The reduction in computational demands came through a public optimization challenge launched by Eigen Labs on 30 May, 2026, which used a circuit verifier that Google had made available alongside its March estimates. Over roughly eight weeks, participants submitted more than 400 accepted designs that collectively drove the combined cost score — a product of logical qubits and Toffoli gates — down 86%, from 10.75bn to 1.496bn, according to a technical paper led by Theta Labs CTO Jieyi Long.
Open challenge drives down cost scores
The final figure was less than half Google’s previously reported benchmark of about 3bn, although the paper notes differences in accounting methods and interfaces mean the comparison is numerical context rather than a formal head-to-head outperformance.
Contributors had included researchers affiliated with the Ethereum Foundation, Eigen Labs, StarkWare, Starknet Foundation, Theta Labs, Brevis, Sei Labs, and Trail of Bits.
After the paper’s cutoff, submissions had continued to improve: one design reached 952,707 Toffoli gates, while another required only 813 logical qubits, albeit with higher gate counts.
The authors have emphasized that the circuits represent only a key arithmetic operation — reversible secp256k1 point addition used repeatedly inside Shor’s algorithm — and do not constitute a full attack implementation or account for physical error-correction overhead.
Even so, StarkWare co-founder Eli Ben-Sasson told The Block he had had “butterflies” when his team brought him the results, warning that if the cost estimate to break this cryptography is halved, then every quoted timeline for “Q-Day” must be shortened accordingly.
Ethereum and Bitcoin advance post-quantum migrations
The research coincides with concrete migration efforts on both chains.
- The Ethereum Foundation has set a December 2029 deadline for full quantum resistance across its execution, consensus, and data layers, calling the target non-negotiable at least until January 2027. On 10 September 2026 Ethereum co-founder Vitalik Buterin had said he hopes to include EIP-8288 — a draft proposal he co-authored in June — in a future network upgrade. The proposal would move heavy cryptographic verification off-chain by having mempool nodes batch proofs into a single recursive STARK per block, potentially reducing gas costs for quantum-safe private transactions from around 10m units to tens of thousands. EIP-8288 remains a draft and has not yet been implemented on Ethereum’s live protocol.
- Bitcoin developers are advancing BIP-360 and BIP-361, which define a new quantum-resistant address format and a migration timeline that would eventually bar new transactions to legacy address types. More than 7m BTC sit in addresses whose public keys are already exposed on-chain, according to estimates cited by Coinbase’s quantum advisory board.
US funding accelerates quantum hardware timelines
The US government is simultaneously accelerating quantum hardware development. Their Department of Commerce has committed over US$2 billion in CHIPS and Science Act equity stakes across nine quantum computing firms. IBM alone is receiving US$1bn to build a dedicated quantum foundry.
The National Institute of Standards and Technology has told federal agencies to plan on deprecating ECDSA by 2030 and disallowing it by 2035. Theta Labs’ Long said: “None of this is urgent because an attack is imminent…It is urgent because the remedy takes years and cannot be applied retroactively.”
