Paper 2026/625
Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities: Resource Estimates and Mitigations
Abstract
The expected emergence of cryptographically relevant quantum computers (CRQCs) will represent a singular discontinuity in the history of digital security, with wide ranging impacts. This whitepaper seeks to elucidate specific implications that the capabilities of developing quantum architectures have on blockchain vulnerabilities and potential mitigation strategies. First, we provide new resource estimates for breaking the 256-bit Elliptic Curve Discrete Logarithm Problem over the secp256k1 curve, the core of modern blockchain cryptography. We demonstrate that Shor's algorithm for this problem can execute with either $\leq 1200$ logical qubits and $\leq 90$ million Toffoli gates or $\leq 1450$ logical qubits and $\leq 70$ million Toffoli gates. In the interest of responsible disclosure, we use a zero-knowledge proof to validate these results without disclosing attack vectors. On superconducting architectures with $10^{-3}$ physical error rates and planar connectivity, those circuits can execute in minutes using fewer than half a million physical qubits. We introduce a critical distinction between "fast-clock" (such as superconducting and photonic) and "slow-clock" (such as neutral atom and ion trap) architectures. Our analysis reveals that the first fast-clock CRQCs would enable "on-spend" attacks on public mempool transactions of some cryptocurrencies. We survey major cryptocurrency vulnerabilities through this lens, identifying systemic risks associated with advanced features in some blockchains such as smart contracts, Proof-of-Stake consensus, and Data Availability Sampling mechanism, as well as the enduring concern of "abandoned" assets. We argue that technical solutions would benefit from accompanying public policy and discuss various frameworks of "digital salvage" to regulate the recovery or destruction of dormant assets while preventing adversarial seizure. We also discuss implications for other digital assets and tokenization as well as challenges and successful examples of the ongoing transition to Post-Quantum Cryptography (PQC). Finally, we urge all vulnerable cryptocurrency communities to join the migration to PQC without delay.
Note: v2 patches software bug enabling exploit against ZKP soundness.
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- Published elsewhere. Minor revision. arXiv
- DOI
- 10.48550/arXiv.2603.28846
- Keywords
- Quantum CryptanalysisDiscrete LogarithmsElliptic CurvesCryptocurrency
- Contact author(s)
-
babbush @ google com
viathor @ google com
craiggidney @ google com - History
- 2026-04-15: revised
- 2026-03-30: received
- See all versions
- Short URL
- https://ia.cr/2026/625
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/625,
author = {Ryan Babbush and Adam Zalcman and Craig Gidney and Michael Broughton and Tanuj Khattar and Hartmut Neven and Thiago Bergamaschi and Justin Drake and Dan Boneh},
title = {Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities: Resource Estimates and Mitigations},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/625},
year = {2026},
doi = {10.48550/arXiv.2603.28846},
url = {https://eprint.iacr.org/2026/625}
}