A collaborative research effort involving more than 100 participants and AI coding agents has sharply lowered a widely cited measure of the quantum resources needed for a core arithmetic step in a theoretical attack on the elliptic-curve signatures used by Bitcoin and Ethereum.
The work, released as an arXiv preprint on September 9, 2026, focuses on reversible point addition over the secp256k1 curve.
That operation is repeated many times inside Shor’s algorithm when the goal is to recover a private key from a public key.
The project, known as ECDSA.
Fail and launched by Eigen Labs in late May 2026, treated circuit design as an open leaderboard contest.
Contributors submitted evaluator-checked designs that were ranked by a spacetime-style score equal to peak logical qubit width multiplied by average executed Toffoli-gate count.
At the July 26 cutoff used in the paper, the leading circuit used 1,151 logical qubits and about 1.30 million Toffoli gates, for a combined score of roughly 1.496 billion.
That is an 86.1 percent drop from the contest’s starting baseline of 10.75 billion.
Relative to a Google Quantum AI point-addition benchmark published in March, the new score is more than 50 percent lower, though the authors emphasize that the two efforts use different interfaces and accounting conventions, so the comparison is not exact.
Lead author Jieyi Long of Theta Labs and co-authors from the Ethereum Foundation, StarkWare, the Starknet Foundation, Trail of Bits, Brevis, Sei Labs, and other groups stress that the result is not a working attack.
No present-day quantum computer can run the full algorithm at cryptographic scale.
The paper also excludes the additional overhead of error correction, magic-state factories, and other hardware costs that a complete end-to-end break would require.
A second circuit, adapted to the single-call interface used in windowed versions of Shor’s algorithm, scored about 1.96 billion after adjusting for measured success probability on random inputs.
Work continued after the paper’s cutoff.
Later submissions pushed the Toffoli count below one million in one design and the qubit count down to 813 in another, at the expense of other resources.
The authors frame the exercise as “open autoresearch”: humans and agents publish verified improvements rather than closed-source circuits.
Google’s earlier estimates had been accompanied by a zero-knowledge proof instead of public circuit details.
The open contest, they argue, produces reproducible numbers that help networks judge how quickly they must migrate to post-quantum signatures.
Bitcoin and Ethereum developers are already studying that transition.
Public-key reuse and older address formats leave large amounts of value exposed once a sufficiently large fault-tolerant machine exists. The new benchmark does not change the fact that such a machine is still years away, but it tightens the resource gap that planners must watch.