Quantum Attack Benchmark Halved: What It Means for Bitcoin and Ethereum Accounting
A collaborative research effort spanning more than 100 contributors from academic institutions and crypto projects has cut the estimated quantum resource cost of attacking Bitcoin and Ethereum cryptographic keys by more than half, in under two months. The result directly compresses the timelines that risk committees, auditors, and CFOs holding digital assets have been using as their planning horizon. For anyone responsible for bitcoin accounting, ethereum accounting, or any form of digital asset custody reporting, this finding is not a distant theoretical concern: it resets the urgency of post-quantum preparation right now.
What the Research Actually Found
The paper, authored by Theta Labs CTO Jieyi Long alongside researchers from several crypto projects and academic institutions, presents an optimised circuit for the core cryptographic operation at the heart of a hypothetical quantum attack on Bitcoin and Ethereum. Specifically, it targets elliptic curve discrete logarithm computation using Shor's algorithm, the mathematical method a sufficiently powerful quantum computer would use to derive a private key from an exposed public key.
The benchmark score and what it measures
The researchers quantify the circuit's efficiency using a combined score: the number of logical qubits (the working memory of the circuit) multiplied by the number of Toffoli gates (the operations that dominate runtime). A lower product means a more efficient circuit and, consequently, a less demanding quantum machine to execute it.
Their final circuit requires 1,151 logical qubits and 1.30 million Toffoli gates, producing a combined score of approximately 1.496 billion. When the ECDSA.Fail public challenge launched on 30 May via Eigen Labs, using a verifier Google Quantum AI had made available, the starting score stood at roughly 10.75 billion. Over approximately two months, more than 100 contributors drove it down by 86%. The final figure is also less than half the benchmark Google had reported when it published its own estimates in March alongside a 2029 target for post-quantum cryptography migration. Crucially, the researchers caution that Google used different interfaces and accounting conventions, so the comparison provides numerical context rather than a formal claim of superiority over Google's circuit.
What the circuit does not yet represent
The authors are explicit on the scope of this work. The circuit does not account for physical error correction, which in practice multiplies hardware requirements considerably. It is not a full, end-to-end implementation of Shor's algorithm ready to run on existing hardware. No quantum computer capable of executing even this optimised circuit exists today. The research community, including the Ethereum Foundation, Eigen Labs, StarkWare, the Starknet Foundation, Theta Labs, Brevis, Sei Labs, and Trail of Bits, framed the challenge as a resource estimation exercise, not an attack.
Why the Rate of Progress Is the Risk Signal
Theta Labs' Long made the key observation plainly: "None of this is urgent because an attack is imminent. It is urgent because the remedy takes years and cannot be applied retroactively."
StarkWare co-founder and CEO Eli Ben-Sasson was more pointed. He described "butterflies" when his team brought him the findings, and told The Block: "Cutting the cost of breaking Bitcoin's cryptography in half, in two months means that everyone should sit up and take notice. If the estimate of what it costs to break this cryptography is being cut in half, as it is in this paper, then every timeline anyone has quoted you for Q-Day needs to be cut too. You don't get to keep the old comfortable number just because the computer isn't built yet."
That rate of improvement is the material signal for financial professionals. Resource benchmarks in early-stage cryptographic research do not improve by 86% over two months routinely. The fact that a public, open challenge with a standardised verifier enabled this pace of progress suggests that further optimisation is likely, and that future benchmarks may be lower still.
The exposure universe: 7 million BTC at risk
The research sits within a broader disclosure landscape. Coinbase's Independent Advisory Board on Quantum Computing and Blockchain noted in June that approximately 7 million BTC sit in addresses where the public key is already visible on-chain, covering legacy address formats and any address reused after an initial spend. A quantum attacker with sufficient capability could, in theory, derive the corresponding private key from that public data. Ethereum is targeting full post-quantum security across its execution, consensus, and data layers by December 2029, a deadline discussed in our earlier coverage of Ethereum's 2029 quantum-resistance deadline and what it means for digital asset accounting.
After the paper's formal cutoff, contributors continued submitting improvements. One design reached 952,707 Toffoli gates; another reached 813 logical qubits. The optimisation frontier is still moving.
Accounting and Audit Implications
For accounting firms, auditors, and CFOs responsible for crypto bookkeeping software deployments and digital asset portfolios, this development has layered implications across financial reporting, custody governance, and disclosure.
Going-concern and risk disclosure
Under both IFRS and US GAAP, auditors are required to assess risks that could affect the recoverability and integrity of material assets. Digital assets held in exposed address formats, particularly large quantities of legacy Bitcoin addresses, now carry a better-quantified (and lower) barrier to attack than they did six months ago. While that barrier remains very high in absolute terms, the direction and speed of change is a factor a prudent auditor should document in working papers.
Boards and CFOs preparing annual reports or interim disclosures should consider whether quantum cryptographic risk warrants explicit mention in risk factor sections, particularly for treasury positions exceeding materiality thresholds. The G7 quantum warning and its implications for crypto financial statements set out a broader framework for how international standard-setters are approaching this question.
Custody policy and internal controls
Custodians and treasury teams using legacy Bitcoin address formats or any address structure with an exposed public key should treat this benchmark reduction as a trigger for a formal policy review. Key considerations include whether holdings should be consolidated into addresses that have never broadcast a public key, what the migration timeline looks like given operational constraints, and who in the governance chain owns the decision. For firms using digital asset accounting software to track wallet-level positions, now is the time to request address-level exposure reports and cross-reference them against the categories of exposed addresses identified in the Coinbase advisory board analysis.
Impairment and fair value considerations
Under ASC 350-60 (the FASB's fair value model for crypto assets) and the IASB's guidance, fair value reflects the price a market participant would pay at the measurement date, incorporating known risks. If the market progressively prices in quantum exposure for certain address types, that discount could become measurable. Auditors applying fair value hierarchy assessments to significant crypto holdings should at minimum document their rationale for concluding that quantum risk is not yet a Level 2 or Level 3 fair value adjustment, and revisit that conclusion at each reporting date.
Practical Next Steps for Finance and Compliance Teams
This is not a call to panic or to liquidate. It is a call to act on planning that should already have started, and to do so faster than previously scheduled.
Immediate actions
First, obtain an address-level exposure map from your custody provider or internal crypto accounting software stack. Identify the proportion of holdings in legacy or reused addresses. Second, review any quantum risk language in existing risk disclosures and assess whether the compressed benchmark warrants an update. Third, open a dialogue with your custody provider about their post-quantum migration roadmap and contractual commitments. If they do not have a documented roadmap, that itself is a disclosure consideration.
Medium-term planning
Bitcoin's own developers are working on post-quantum address standards, though no finalised protocol change has been adopted at the time of writing. Ethereum's 2029 deadline provides a concrete regulatory and technical anchor for Ethereum-denominated treasury positions. Both timelines, however, were set before this benchmark reduction. Risk committees should revisit their internal Q-Day assumptions and model what a further 50% reduction in resource requirements would mean for their own exposure horizon.
Frequently Asked Questions
Does this mean Bitcoin or Ethereum could be attacked today?
No. The circuit described in the research is not a deployable attack. It does not account for physical error correction, which vastly increases real-world hardware requirements, and no quantum computer with sufficient capability exists. The research refines the estimated cost of a future attack, it does not enable one now.
What does the benchmark score reduction mean in plain terms?
The combined score of logical qubits multiplied by Toffoli gates fell from roughly 10.75 billion to 1.496 billion over two months. A lower score means the hypothetical quantum machine needed to execute the attack would require fewer computational resources. It is a measure of efficiency progress, not proof that a capable machine is close to being built.
Which Bitcoin addresses are most exposed?
Addresses where the public key is already visible on-chain carry the highest theoretical exposure. This includes legacy Pay-to-Public-Key (P2PK) outputs and any address that has been used to send a transaction, because spending reveals the public key. Coinbase's advisory board estimated approximately 7 million BTC sit in such addresses.
How should auditors treat this in a current-period engagement?
At a minimum, auditors should document in working papers that they have considered quantum cryptographic risk, assessed the client's address-type exposure, and concluded whether or not it is material to the going-concern assessment or fair value hierarchy. Given the pace of benchmark improvement, that documentation should note the date of assessment and flag it for reassessment at the next reporting period.
Is there a regulatory requirement to disclose quantum risk for crypto assets?
No specific regulation currently mandates quantum risk disclosure for crypto assets. However, general disclosure obligations under securities law, IFRS 7 financial instruments risk disclosures, and equivalent GAAP requirements cover material risks to asset integrity. As quantum resource benchmarks continue to fall, the threshold at which quantum risk becomes a disclosable material risk will move closer. Firms should monitor guidance from the SEC, IASB, and FASB on this point.
Source: The Block
