AI Agents Helped Cut a Bitcoin Quantum-Attack Resource Benchmark by 86% — Here’s What That Actually Means

The claim making the rounds: “AI agents just cut the cost of a quantum attack on Bitcoin by 86%.” That headline is technically accurate and also easy to badly misread. Here’s what actually happened, and what it doesn’t mean.
What was actually measured
The research comes out of a crowdsourced competition called ECDSA.Fail, launched by Eigen Labs in late May 2026 and treated as an open leaderboard: contributors submitted circuit designs, an automated evaluator checked and scored each one, and the best submissions climbed the board over roughly eight weeks. More than 100 contributors, working alongside AI coding agents rather than purely by hand, submitted over 400 promoted designs before the competition’s formal cutoff on July 26. The resulting paper, led by Theta Labs co-founder and CTO Jieyi Long, was posted publicly in early September.
The specific thing being optimized is narrow: a single arithmetic operation called elliptic-curve point addition, repeated many times inside Shor’s algorithm when it’s used to try to recover a private key from a public key on the secp256k1 curve — the curve underlying Bitcoin and Ethereum signatures. The benchmark score combines two resource costs multiplied together: the number of logical qubits a circuit needs, and the average number of Toffoli gates it executes. Lower is better on both.
The numbers, precisely
The competition’s starting reference circuit needed 2,715 logical qubits and about 3.96 million average Toffoli gates. By the July 26 cutoff, the leading submitted design had cut that to 1,151 logical qubits and about 1.3 million Toffoli gates — a 57.6% reduction in qubits, a 67.2% reduction in Toffoli gates, and an 86.1% reduction on the combined score that multiplies the two together. That combined-score result is also roughly 50% below a comparable point-addition benchmark separately reported by a Google research team. Submissions kept improving after the formal cutoff too, with post-deadline designs reportedly pushing the combined score down further, to around 1.259 billion.
Note: the embedded posts above are Eigen Labs’ own updates tracking the ECDSA.Fail leaderboard’s progress at earlier points in the competition (referencing a 47.2% gap versus Google’s circuit and an 846-qubit minimum at that stage); they illustrate the project’s open, incremental nature but predate the specific 86.1%/1,151-qubit figures from the final July 26 paper cited in this article.
What this doesn’t mean
No Bitcoin private key was recovered, and no wallet was compromised. The benchmark isolates one arithmetic subroutine inside a much larger algorithm; it explicitly excludes the overhead of physical quantum error correction, magic-state factories, hardware-specific compilation, and the rest of what a genuine end-to-end key-recovery attack would require on top of the point-addition step alone. Reducing the resource cost of one component of a theoretical attack is meaningfully different from making that attack practical on hardware that doesn’t yet exist at the scale required. Today’s largest quantum computers remain many orders of magnitude away from running Shor’s algorithm against Bitcoin’s cryptography in any form.
What the result does demonstrate is something separate and arguably more interesting: that opening frontier cryptographic research to public competition, with contributors using AI coding agents to iterate faster than manual circuit design typically allows, can compress research timelines that might otherwise take years into a few months. That’s a statement about how research gets done, not a countdown clock on Bitcoin’s security.
Readers wanting deeper background on quantum computing’s real relationship to Bitcoin’s cryptography, including coin680’s earlier coverage of related proposals, can browse the Bitcoin Academy.
This article is for informational purposes only and is not financial advice. This research does not demonstrate a practical attack on Bitcoin or Ethereum; it measures a narrow theoretical resource benchmark. Always distinguish between benchmark research and demonstrated real-world capability before drawing conclusions about asset security.
