LyChain
Web3

Quantum Attack Cost Falls 50%: What 1,151 Logical Qubits Actually Mean for Bitcoin and Ethereum

CryptoPanda

A new paper cuts the estimated resource cost of breaking secp256k1 — the elliptic curve guarding nearly every Bitcoin and Ethereum private key — by more than half. The composite resource score falls from roughly 3 billion to roughly 1.5 billion. The optimized circuit needs about 1,151 logical qubits and about 1.3 million Toffoli gates.

Every headline I have read reports the first number and deletes the second. "Attack cost down 50%" is arithmetically correct and analytically hollow. It is the same category of error as quoting a gas fee without the gas price. A cost curve and a feasibility curve are not the same curve, and conflating them is how a research note becomes a panic candle.

Context: who wrote it, and what it actually changes

The provenance matters as much as the result. The author list carries affiliations from Theta Labs, the Ethereum Foundation, and StarkWare — a proof-of-stake data network, the largest smart contract ecosystem, and the leading ZK-Rollup team, in one paper. That is not a fringe group publishing on a preprint server at midnight.

Quantum Attack Cost Falls 50%: What 1,151 Logical Qubits Actually Mean for Bitcoin and Ethereum

The mechanism: Shor's algorithm, executed on a fault-tolerant quantum computer, solves the discrete logarithm problem in polynomial time. Elliptic curve discrete logarithms are precisely what make a public key safe to broadcast. secp256k1 is the curve BTC and ETH both use.

What the paper does is narrow. It optimizes point addition — the heaviest arithmetic block inside the Shor circuit for ECDLP — at the gate level. It builds no hardware. It does not remove the requirement for a fault-tolerant machine. It makes the offline algorithm cheaper. Algorithm optimization and hardware progress are two independent curves, and they compound. That is the whole finding.

Core: the unit behind the number

The number that matters is not 1,151. It is the ratio hidden behind it.

Quantum Attack Cost Falls 50%: What 1,151 Logical Qubits Actually Mean for Bitcoin and Ethereum

Logical qubits are the error-free abstract qubits an algorithm is written against. Physical qubits are what exist in hardware. Encoding one logical qubit requires many physical qubits bound together through quantum error correction. At today's error rates, surface-code-style overheads run in the hundreds to thousands per logical qubit. Multiply 1,151 by that overhead and you land back in the hundreds of thousands to low-millions of physical qubits, all of them operating below the error-correction threshold.

Current NISQ hardware sits at hundreds to low thousands of physical qubits, at error rates that are not below threshold. The gap is orders of magnitude, not percentages. Half of a very large number is still a very large number. The 1.5 billion composite score is a spacetime resource metric — qubit count multiplied by gate count and time. Halving it is real efficiency work. It does not shorten the timeline, because the timeline is gated by hardware, not by the algorithm.

I have watched this specific failure mode before. In 2020 I pulled Aave's liquidity pool metrics directly from Ethereum state and found a 12% deviation in interest accrual against the public dashboard. The cause was a rounding error in the oracle feed. The dashboard was smooth; the chain was not. I wrote up twenty pages and submitted it to the governance forum, and the protocol patched it. The lesson holds here: raw state reveals truth before dashboards do. The raw unit is logical qubits. The dashboard says "50% cheaper."

The blockchain-specific exposure diverges from every other cryptography discussion. In TLS, an adversary can harvest now and decrypt later — store ciphertext, wait, cash out years from now. Blockchains need no harvesting. The public keys are already on-chain, permanently, and there is no rotation primitive.

BTC: Pay-to-Public-Key outputs. Early block rewards, including the coins attributed to Satoshi, have never moved. Their public keys sit exposed in the script. No reuse, no rotation, no defense. Legacy P2PKH addresses are structurally safer if never spent from — an unspent address holds only a hash of the public key, and hash preimage is a different, harder problem. Spending once converts that buffer into exposure.

ETH: no such buffer exists. Every account that has ever signed a transaction exposed its public key in that signature. That is effectively every active account on the network. The account model has no equivalent of address hygiene.

This is not a vulnerability disclosure. Nothing is broken today. My point is narrower and harder: the exposed surface is already fixed and already permanent. Migration — not computation — is the binding constraint.

Contrarian: the market is watching the wrong curve

Consensus reaction to this paper will be wrong in one of two directions. The panic camp reads "50%" as "soon." The dismissive camp reads "logical qubits" as "irrelevant." Both skip the variable that actually moves.

That variable is migration latency. The co-author — Jieyi Long, CTO of Theta Labs — stated plainly that this is not an imminent threat. A researcher attached to an entity with a commercial interest in a security narrative declined to inflate it. That restraint is a data point. Trust is a variable, data is a constant, and the constant here is that post-quantum migration takes years and becomes irreversible the moment an attack is viable.

NIST has already standardized Kyber for key encapsulation and Dilithium for signatures. Traditional finance has started deploying them. Public blockchains, largely, have not.

BTC migration difficulty: high. PQC signatures require a consensus-level change, and Bitcoin governance is designed to minimize consensus-level change. A soft fork path exists, but it is contentious. Watch the developer mailing list, not the timeline.

ETH migration difficulty: lower. The EIP process is more flexible, and Ethereum Foundation researchers are on this paper's author list — which tells you the agenda is already live inside the ecosystem.

The transmission terminal is downstream: exchanges, custodians, wallet providers. Their key management is where this becomes a business continuity question rather than an academic one. If a custodian's hot wallet signs with ECDSA over secp256k1, that is a procurement problem waiting for a deadline.

Quantum Attack Cost Falls 50%: What 1,151 Logical Qubits Actually Mean for Bitcoin and Ethereum

One more piece of provenance. Theta Labs issues THETA. StarkWare issues STRK. That does not invalidate the research — the circuit optimization is checkable and the institutions are serious. It does mean the publication is a data point with an origin, and origin belongs in the analysis.

Takeaway: four signals to monitor, not one headline

Physical qubit counts and error rates from IBM, Google, and Quantinuum. The threshold that matters is the point where error-corrected logical qubits become cheap, not the point where a press release says they exist.

Ethereum Foundation research posts and EIP drafts on PQC signature schemes.

Bitcoin developer mailing list activity around PQC migration proposals.

Wallet and custodian changelogs. The first real-world post-quantum migration will surface there, buried in a release note, long before any announcement.

Yields that defy gravity usually crash to earth. So do attack cost estimates. This number will fall again. The open question is not whether the estimate gets cheaper — it is whether the migration starts before the last digit does.

Market Prices

BTC Bitcoin
$75,899.3 -3.97%
ETH Ethereum
$2,403.11 -5.34%
SOL Solana
$97.65 -5.27%
BNB BNB Chain
$719.2 -0.84%
XRP XRP Ledger
$1.3 -11.03%
DOGE Dogecoin
$0.0807 -4.71%
ADA Cardano
$0.1972 -7.02%
AVAX Avalanche
$7.33 -3.58%
DOT Polkadot
$0.9563 -6.06%
LINK Chainlink
$11.07 -5.46%

Fear & Greed

69

Greed

Market Sentiment

Event Calendar

{{年份}}
30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

12
05
halving BCH Halving

Block reward halving event

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

28
03
unlock Arbitrum Token Unlock

92 million ARB released

18
03
unlock Sui Token Unlock

Team and early investor shares released

Altseason Index

42

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$75,899.3
1
Ethereum ETH
$2,403.11
1
Solana SOL
$97.65
1
BNB Chain BNB
$719.2
1
XRP Ledger XRP
$1.3
1
Dogecoin DOGE
$0.0807
1
Cardano ADA
$0.1972
1
Avalanche AVAX
$7.33
1
Polkadot DOT
$0.9563
1
Chainlink LINK
$11.07

🐋 Whale Tracker

🔵
0xcbe2...3f5f
2m ago
Stake
1,669,312 USDT
🔵
0x4947...9af9
2m ago
Stake
48,573 SOL
🔵
0xe409...d9e8
1h ago
Stake
3,906 ETH

💡 Smart Money

0x8043...08d5
Market Maker
+$0.9M
68%
0x4adb...4bc6
Early Investor
+$2.9M
94%
0x88fc...6a5c
Experienced On-chain Trader
-$0.5M
69%

Tools

All →