Google Quantum AI: breaking ECDLP-256 needs ~1,200 logical qubits
Google Quantum AI, with co-authors from the Ethereum Foundation and Stanford, published optimized Shor's algorithm circuits targeting the 256-bit elliptic curve discrete logarithm problem (secp256k1) that secures Bitcoin and Ethereum wallet signatures. The estimate: under 1,200 logical qubits and 90 million Toffoli gates — roughly a 10x reduction in combined resources versus prior work. The attack circuits were not released; results were validated via a zero-knowledge proof.
- Under 1,200 logical qubits and 90M Toffoli gates for ECDLP-256
- Alternative: under 1,450 qubits and 70M Toffoli gates
- About 10x reduction in combined computational resources
- Attack circuits withheld, validated via zero-knowledge proof
Read next
Science