AI Agents Shrink Quantum ECDSA Cost by 86%, Reframing Bitcoin’s Security Timeline
An open challenge cut a key quantum ECDSA step by 86% using AI agents—lowering resources for a Bitcoin/Ethereum attack without cracking keys, and accelerating post-quantum planning.

Because Bitcoin
September 11, 2026
Every security model has a stress test. This summer, one arrived for Bitcoin and Ethereum when an open challenge used AI coding agents to slash the resource estimate for a critical quantum subroutine tied to ECDSA by 86%. The math behind your wallet did not fall—but the margin for complacency did.
The ECDSA.Fail competition, launched by Eigen Labs in late May, drew more than 100 participants to design quantum circuits for secp256k1, the curve that secures Bitcoin and Ethereum transaction signatures. Researchers from Theta Labs, MultiVM Labs, Eigen Labs, Trail of Bits, StarkWare, and the Ethereum Foundation co-authored a paper posted Wednesday detailing the results.
The task targeted a specific calculation needed to recover a private key, and the group verified the circuit’s outputs end-to-end. No Bitcoin private key was broken. The benchmark they optimized multiplies a circuit’s logical qubits by its Toffoli gate count—Toffoli gates being expensive quantum operations introduced by Tommaso Toffoli in 1980. By July 26, the score fell from 10.75 billion to 1.496 billion. The leading circuit used 1,151 logical qubits and roughly 1.3 million Toffoli gates, and a later variant brought the gate count under 1 million. The authors note the best score was about half of Google Quantum AI’s March figure—but differences in how resources were counted make a strict apples-to-apples comparison inappropriate. The results also exclude the hardware and error-correction overhead a full attack would require.
The method mattered as much as the numbers. The team framed ECDSA.Fail as “Open Autoresearch”: a verifier-gated loop where humans and AI agents iteratively propose, test, and share improvements against a single measurable objective. That pipeline compresses the search space. You can feel the compounding: tighter arithmetic, more efficient modular reduction, fewer ancillae, reduced Toffoli depth—each tweak small, the sum material.
What does this actually change? The metric is directionally useful but coarse. Multiplying qubits by Toffolis hides depth, scheduling, and magic-state logistics; in practice, error rates, cycle times, and surface-code overhead determine feasibility. Today’s quantum hardware cannot run this attack. But an 86% drop in a bottlenecked subroutine moves the slope of progress. Timelines are still murky; incentives for migration are less so.
That is already reflected in policy. NIST has standardized post-quantum replacements, and its initial public draft of NIST IR 8547 proposes phasing out classical public-key cryptography at the 112-bit security level after 2030 and disallowing it after 2035. “Q-Day” remains uncertain, yet the migration clock is not waiting for certainty.
Capital is mobilizing in parallel. In July, Galaxy Digital committed up to $5 million for quantum-resilience research. Nine firms—including BlackRock, Coinbase, and Strategy—pledged a combined $15 million over three years to broader Bitcoin security work that includes quantum defenses. ECDSA.Fail gives these budgets a clearer target: prioritize components with measurable impact, and lean on AI-accelerated circuit search where it compounds quickly.
There is a governance dimension here. Publishing more efficient attack circuits can unsettle holders, but credible, verifier-gated disclosures reduce false comfort and help protocol teams stage upgrades. For Bitcoin and Ethereum, that points toward practical migration paths: inventory signature schemes in use, design wallet rotation policies, and test PQC integration under realistic constraints. Not every key is equally exposed; what matters is a credible plan aligned with NIST’s calendar, not a guess at hardware breakthroughs.
The headline is not that Bitcoin fell—it did not. It’s that open, AI-assisted research can rapidly erode assumed margins in the quantum stack. That should nudge roadmaps, not trigger panic.