In a recent development that could reshape the security outlook for the world’s leading blockchain platforms, a group of cryptographic researchers has published a paper—shared with CoinDesk—that dramatically reduces the projected timeline for quantum computers to pose a realistic threat to Bitcoin and Ethereum. The study demonstrates that a combination of human ingenuity and advanced artificial‑intelligence agents can solve a core sub‑problem of Shor’s algorithm significantly faster than the best result reported by Google in March. By achieving a 50 percent improvement over the previous benchmark, the researchers argue that the window during which quantum computers might break the elliptic‑curve signatures protecting most cryptocurrencies is considerably shorter than many industry forecasts have suggested. ### Background: Why Quantum Computing Matters to Crypto Bitcoin, Ethereum, and the majority of other blockchain networks rely on public‑key cryptography—specifically the Elliptic Curve Digital Signature Algorithm (ECDSA) for transaction validation and the Secp256k1 curve for key generation.

The security of these schemes rests on the mathematical difficulty of solving the discrete logarithm problem (DLP) on an elliptic curve. Classical computers would require an infeasible amount of time to compute a private key from a public key, making the system effectively unbreakable with today’s technology.

Enter quantum computing. In 1994, Peter Shor introduced an algorithm that can solve the DLP—and the related integer factorisation problem—exponentially faster than any known classical algorithm.

A sufficiently large, error‑corrected quantum computer running Shor’s algorithm could, in theory, derive a private key from its public counterpart in a matter of minutes, rendering current blockchain signatures obsolete. Because building a quantum machine with enough logical qubits and low enough error rates is an enormous engineering challenge, most experts have treated the quantum threat as a long‑term concern, often projecting a timeline of a decade or more before it becomes actionable.

Those timelines are based on estimates of how many physical qubits are needed to create a reliable logical qubit, the overhead required for quantum error correction, and the speed at which the algorithm’s critical sub‑routines can be executed. ### The Core Calculation: Order‑Finding in Shor’s Algorithm Shor’s algorithm consists of two major stages. The first stage prepares a superposition of states, and the second stage—known as the quantum Fourier transform (QFT) followed by measurement—extracts the period (or order) of a function related to the number being factored.

The order‑finding step is the computational bottleneck; its efficiency directly determines how many quantum gates must be applied and how long the coherence of the qubits must be maintained. In March, Google announced a breakthrough in this order‑finding sub‑routine, achieving a record‑setting depth‑reduction for a particular instance of the problem. Their result was widely interpreted as a milestone that nudged the quantum‑attack horizon forward by a few years.

However, the new paper shows that the same problem can be tackled more efficiently using a hybrid approach that leverages both human‑crafted heuristics and machine‑learning‑driven optimisation. ### The Study’s Methodology: Humans + AI Agents The research team, composed of cryptographers, quantum physicists, and AI specialists, set out to test whether the order‑finding step could be compressed further without sacrificing correctness.

They employed a two‑pronged strategy: 1. **Human‑Designed Circuit Optimisations** – Experienced quantum algorithm designers manually re‑examined the gate layout, identifying redundant operations and exploiting symmetries in the mathematical structure of the problem. By applying well‑known techniques such as gate cancellation, commutation rules, and ancilla reuse, they trimmed the circuit depth by roughly 15 percent.

2. **Reinforcement‑Learning Agents** – The team trained AI agents using reinforcement learning to explore the vast space of possible circuit configurations. The agents received a reward for each reduction in gate count and for maintaining fidelity above a predefined threshold.

Over thousands of simulated episodes, the AI discovered novel rearrangements that human designers had not considered, shaving an additional 20 percent off the depth. When the human and AI contributions were combined, the resulting circuit achieved a total depth reduction of approximately 50 percent compared with Google’s March benchmark.

Importantly, the authors verified the correctness of the optimized circuit through extensive classical simulation and small‑scale quantum hardware tests, confirming that the probability of successful order extraction remained high. ### Implications for Bitcoin and Ethereum The immediate implication of a 50 percent speed‑up in the order‑finding step is a proportional reduction in the number of logical qubits and total runtime required for a full Shor attack on the Secp256k1 curve. The researchers performed a detailed resource‑estimation analysis, taking into account contemporary error‑correction codes (such as the surface code) and realistic gate error rates projected for near‑future quantum processors. Their calculations suggest that a quantum computer capable of breaking Bitcoin’s ECDSA signatures could be built with roughly half the number of physical qubits previously estimated—dropping the requirement from around 20 million physical qubits to approximately 10 million.

Likewise, the total wall‑clock time needed to execute the attack falls from an estimated few weeks to just a few days, assuming the same level of parallelism. For Ethereum, which also relies on Secp256k1 for its transaction signatures, the impact is identical.

However, Ethereum’s broader ecosystem—smart contracts, layer‑2 solutions, and cross‑chain bridges—means that a quantum compromise could have cascading effects beyond simple fund theft, potentially disrupting decentralized finance (DeFi) protocols and governance mechanisms. ### A New Variable in the Quantum Clock The paper’s findings introduce an additional variable to the “quantum clock” that many blockchain projects have been watching. Previously, the clock was driven mainly by hardware progress (more qubits, lower error rates) and algorithmic breakthroughs in error correction. Now, optimisation of the algorithmic sub‑routines themselves—through human insight and AI‑assisted design—has emerged as a lever that can accelerate the timeline.

Industry response has been mixed. Some security analysts argue that even with the reduced qubit count, the engineering challenges of building a fault‑tolerant machine at that scale remain formidable, and that a decade‑long horizon is still realistic.

Others contend that the rapid pace of AI‑driven optimisation, combined with the accelerating pace of quantum hardware development, could compress the timeline to within the next five years. ### Mitigation Strategies and the Path Forward Given the heightened urgency, blockchain developers and custodians are urged to accelerate the transition to quantum‑resistant cryptography. Several post‑quantum signature schemes—such as Dilithium, Falcon, and Picnic—are already being standardised by the NIST Post‑Quantum Cryptography project. Implementing a hybrid approach, where transactions are signed with both classical ECDSA and a post‑quantum algorithm, could provide a safety net during the migration period.

Furthermore, the research underscores the importance of continuous monitoring of quantum‑algorithmic advances. Just as hardware roadmaps are tracked, the community should maintain a “quantum algorithmic watchlist” to assess breakthroughs in circuit optimisation, error‑correction techniques, and AI‑assisted design. ### Conclusion The newly released study, by demonstrating a 50 percent reduction in the critical order‑finding step of Shor’s algorithm through a blend of human expertise and AI optimisation, effectively halves the projected timeline for a quantum computer capable of compromising Bitcoin and Ethereum. While the practical construction of such a machine remains a massive technical hurdle, the result adds a fresh dimension to the risk assessment for blockchain security.

Stakeholders are now faced with a clearer imperative: to prioritize quantum‑resilient upgrades, to monitor algorithmic progress closely, and to prepare contingency plans that safeguard digital assets against a future where quantum computers are no longer a distant possibility.