Technology

Chinese Researchers Push Quantum Attack Benchmark to 835 Logical Qubits

A Chinese research team has set a new low-water mark for the quantum resources needed to attack Bitcoin's elliptic curve cryptography: 835 logical qubits, down from 2,124 three years ago.

5 min read
A cluster of quantum computing hardware modules — cylindrical cryogenic chambers trailing silver wiring and copper tubing — hangs suspended inside a dimly lit laboratory, bathed in cold blue
Share

The algorithmic target for breaking Bitcoin's elliptic curve cryptography keeps falling, and no new quantum hardware is required to move it.

Key takeaways

  • A Chinese research team published a quantum circuit for attacking secp256k1 (Bitcoin and Ethereum's signature curve) requiring only 835 logical qubits, the lowest figure on record for a 256-bit elliptic curve discrete logarithm attack, per arXiv:2607.13816.
  • The benchmark has dropped from 2,124 logical qubits (Häner et al., 2020) to roughly 1,193 (EUROCRYPT 2026) to 835 today, entirely through algorithmic improvement, with no meaningful advance in quantum hardware.
  • No quantum computer can execute this attack today. The best fault-tolerant machines operate around 94 logical qubits. But the finish line is moving closer from both directions simultaneously, and Bitcoin's post-quantum soft fork needs an active path forward now.

A Chinese team spanning multiple research institutions has published a quantum algorithm targeting secp256k1, the elliptic curve underpinning Bitcoin and Ethereum signatures, that requires only 835 logical qubits to execute a full attack. That is the lowest resource estimate on record for a 256-bit prime-field elliptic curve discrete logarithm problem, first reported by The Block. The attack cannot be run on any hardware that exists today, but the number itself matters: it has been cut by more than 60 percent in roughly four years through math alone.

The paper, arXiv:2607.13816, improves on the EUROCRYPT 2026 result from Chevignard, Fouque, and Schrottenloher at INRIA Rennes, whose width-minimized circuit brought the count to approximately 1,193 logical qubits for a 256-bit prime-field curve. That was itself a halving of the Häner et al. baseline of 2,124, which had stood as the academic floor since 2020. The new paper's abstract cites 1,098 as the Chevignard comparison point, but that figure corresponds to Chevignard's P-224 result; the P-256 figure is ~1,193. The paper also compares against Google Quantum AI's secp256k1 whitepaper benchmark of ~1,175 logical qubits (low-qubit variant). At 835, the new result is roughly 71 percent of Google's 1,175 figure, a meaningful reduction, though not "less than half" of Google's estimate. The two papers also use different circuit-accounting methods, so direct numerical comparisons carry caveats.

The Algorithmic Clock Is the One Moving

The progression deserves a direct reading: 2,124 to 1,193 to 835. None of those steps required a new quantum computer. They required better circuit construction, smarter space-time tradeoffs, and incremental improvements to point-addition primitives. The hardware threshold, not the algorithm, is what protects Bitcoin today.

The best fault-tolerant quantum processors demonstrated as of 2026 operate around 94 logical qubits. Google's Willow chip sits at 105 physical qubits. The 835-logical-qubit attack also requires millions of Toffoli gate operations at error rates current machines cannot sustain. The practical gap is still large.

But the two clocks run independently. Hardware capability rises with fabrication and engineering investment. Algorithmic targets fall every time a smarter research team rewrites the circuit. The 2026 research record shows three significant algorithmic drops in a single year: Google's March whitepaper, the EUROCRYPT result, and now this. Nothing about the hardware gap prevents the algorithmic target from reaching 500 qubits or lower before a machine capable of running it exists.

A significant portion of BTC supply sits in wallets with already-exposed public keys: legacy Pay-to-Public-Key outputs and reused Pay-to-Public-Key-Hash addresses. Coins secured by unused SegWit or Taproot addresses, where the public key has not yet been broadcast, face a materially harder attack. The exposure is not uniformly distributed. Knowing which bucket a holder is in matters.

Bitcoin's Defense Requires Lead Time

The quantum policy clock is now formally ticking at the federal level too, but the technical defense for Bitcoin specifically runs through the soft-fork process. BIP-360 proposes quantum-resistant address types built on NIST post-quantum signature standards. BTQ Technologies deployed the first working implementation on a dedicated Bitcoin Quantum testnet in March 2026; BIP-360 remains a draft proposal and is not active on mainnet. Full network protection requires broad ecosystem consensus, a soft fork, and a migration window long enough for holders of exposed coins to move.

That process is slow by design. A feature, not a bug. But it means the advocacy work, the technical review, the miner signaling, and the wallet-software upgrades all need to start years before the hardware gap closes. On the path from paper to mainnet, this algorithmic compression is the argument for urgency. The post-quantum signature scheme literature makes clear there are real tradeoffs to navigate; those tradeoffs take time to resolve through the proposal process.

The falsifiable thesis: if the algorithmic descent stalls and BIP-360 or an equivalent reaches a clear activation timeline before logical qubit counts reach fault-tolerant hardware scale, the emergency framing softens and orderly migration becomes realistic. If the descent continues at 2026's pace and no activation path materializes, the window for an orderly transition compresses toward a crisis dynamic.

What to Watch

The next threshold to watch is whether any research group pushes below 700 logical qubits or demonstrates a meaningful reduction in gate depth, since gate count, not just qubit count, determines when hardware can actually run the attack. On the defense side, the status of BIP-360 on testnet and any movement toward a formal activation proposal are the concrete signals that the Bitcoin development community is treating this as a live engineering problem rather than a distant theoretical one.

Sources

Frequently Asked Questions

No. The 835-logical-qubit benchmark still requires error-corrected logical qubits and sustained gate fidelity that no hardware in existence can deliver. The best demonstrated fault-tolerant systems sit around 94 logical qubits. The concern is trajectory, not present capability.

The primary at-risk category is legacy Pay-to-Public-Key outputs and reused Pay-to-Public-Key-Hash addresses where the public key is already on-chain. Coins held in unused SegWit or Taproot addresses, where the public key has not been broadcast, require a harder attack to reach. Holders who have never reused a Taproot address and hold keys in cold storage with a fresh derivation path are in a materially different position from those sitting on decade-old P2PK outputs.

BIP-360 proposes adding quantum-resistant address types to Bitcoin using post-quantum signature schemes from the NIST PQC standards process. BTQ Technologies deployed the first working implementation on a dedicated Bitcoin Quantum testnet in March 2026. BIP-360 remains a draft proposal; mainnet activation requires a soft fork with broad consensus across miners, developers, and the broader ecosystem, a process that historically takes years from proposal to activation.

News and analysis, not financial, investment, legal, or tax advice. Figures and quotes are verified against primary sources where possible. See our editorial and financial disclosures.

Keep reading

All of TFTC

The Bitcoin Brief

Bitcoin, markets, energy, and the tech reshaping all three.

A daily brief on the freedom tech building a parallel economy, written for the curious and the convicted alike. Signal, not noise. Truth for the Commoner.

Free, daily. Unsubscribe anytime.