Key takeaways
- Google researchers compiled quantum circuits that can break Bitcoin’s elliptic curve cryptography using fewer than 1,200 logical qubits, a 20x reduction from previous estimates.
- A sufficiently powerful quantum computer could crack a Bitcoin private key in about nine minutes once a public key is exposed, putting an estimated 6.9 million BTC at heightened risk.
- Bitcoin’s Taproot upgrade, while improving privacy and efficiency, made certain public key information more visible on-chain, widening the potential attack surface.
- Google recommends an urgent transition to post-quantum cryptography (PQC) and advises wallet holders to stop reusing addresses that expose public keys.
Published: March 31, 2026, 12:00 UTC
Google Quantum AI released a research paper on March 31 showing that breaking the encryption protecting Bitcoin and Ethereum wallets may require far fewer quantum computing resources than previously believed. The findings sent ripples through the crypto community and reignited debate over how quickly blockchains need to adopt post-quantum defenses.
Elliptic curve cryptography (ECC) is the mathematical system that secures private keys across most major blockchains. Anyone who can solve the underlying math problem, known as the elliptic curve discrete logarithm problem (ECDLP-256), can derive a wallet’s private key from its public key and drain its funds.
What Google found
The paper, authored by Ryan Babbush, Director of Research for Quantum Algorithms, and Hartmut Neven, VP of Engineering at Google Quantum AI, presents two compiled quantum circuits implementing Shor’s algorithm against ECDLP-256.
Circuit A uses fewer than 1,200 logical qubits and 90 million Toffoli gates. Circuit B trades qubit count for speed, requiring fewer than 1,450 logical qubits and 70 million Toffoli gates. Both can execute on a superconducting quantum computer with fewer than 500,000 physical qubits in a matter of minutes.
That 500,000-qubit threshold represents roughly a 20-fold reduction from earlier academic estimates, which placed the requirement in the millions. Google’s current Willow processor runs 105 qubits, so the gap remains large. But the trajectory matters: each hardware generation closes distance faster than linear projections suggest.
Why Taproot makes this worse
Bitcoin’s Taproot upgrade, activated in November 2021, improved transaction efficiency and privacy by introducing Schnorr signatures. But it also changed how public keys appear on the blockchain. Under Taproot, certain public key data is more visible on-chain, meaning a quantum attacker would have more targets to work with.
The research estimates that a quantum computer could crack an exposed private key with approximately 41% probability within nine minutes, the typical window for a Bitcoin block confirmation. That means an attacker could intercept a transaction mid-confirmation and redirect funds before the network finalizes the block.
Around 6.9 million Bitcoin currently sit in wallets with exposed public keys, either through address reuse or Taproot-style outputs. At current prices, that represents hundreds of billions of dollars in potential exposure.
How Google disclosed the findings
Google chose a responsible disclosure path rather than publishing a step-by-step attack playbook. The team developed a zero-knowledge proof method that allows third parties to verify the research claims without gaining access to implementation details that could be weaponized.
The company also engaged with U.S. government agencies before publication. The goal, according to the blog post from Babbush and Neven, is to give the cryptocurrency community time to upgrade defenses before quantum hardware catches up to the theoretical threat.
What the crypto community is doing about it
Ethereum co-founder Vitalik Buterin has backed post-quantum research efforts and endorsed EIP-8141, a proposal aimed at making privacy protocols more resistant to quantum attacks. Google itself is already migrating internal systems to quantum-resistant cryptography, with a target date of 2029. Android 17 uses quantum-resistant signatures, and Chrome supports post-quantum key exchange.
For Bitcoin, the path forward is more complicated. Upgrading Bitcoin’s signature scheme requires network-wide consensus, and the community has historically moved slowly on protocol changes. The researchers recommend three immediate steps: transitioning to post-quantum cryptography, avoiding address reuse that exposes public keys, and developing policy frameworks for abandoned coins sitting in vulnerable wallets.
None of this is an emergency today. Google’s Willow chip is roughly 5,000x short of the physical qubit count needed. But the paper’s central message is that the buffer is shrinking faster than most people assumed, and the time to start migrating is now, not when quantum computers are already powerful enough to attack.
Frequently asked questions
Can quantum computers steal Bitcoin right now?
No. Google’s current quantum processor has 105 qubits, and the attack requires around 500,000 physical qubits. The research shows the threat is closer than previously estimated, but no existing quantum computer can break Bitcoin’s encryption today.
Which Bitcoin wallets are most at risk from quantum attacks?
Wallets that have exposed their public keys are most vulnerable. This includes wallets that reuse addresses and those using Taproot outputs. An estimated 6.9 million BTC sit in wallets with visible public keys, making them potential targets once quantum hardware advances far enough.
What is post-quantum cryptography and how does it protect crypto?
Post-quantum cryptography (PQC) refers to encryption algorithms designed to resist attacks from quantum computers. These algorithms use mathematical problems that quantum processors cannot solve efficiently, unlike the elliptic curve math that secures current blockchain wallets.








