For years, the message from the smartest people in the room has been the same: don’t worry about quantum. It’s 20 years away. It’s 30 years away. You’ll be dead before your coins are in danger.
Then Google quietly published a paper warning that quantum risk to crypto is real ahead of a 2029 timeline, and set a migration deadline for the whole industry. Then an IBM executive scared Jim Cramer into dumping his Bitcoin on national TV, and we all laughed at him (we still do — that was the most bullish signal of 2026).
Here’s what wasn’t funny this week.
A crowd of 100+ volunteers and AI agents just cut the estimated cost of attacking Bitcoin’s cryptography by 86.1%.
The project is called ECDSA.Fail, launched by Eigen Labs in late May 2026. The challenge: take the point-addition circuit that Shor’s algorithm runs against secp256k1 — the elliptic curve behind Bitcoin, Ethereum, and half the crypto world — and make it cheaper to compute. Over eight weeks, more than 400 submissions poured in from over 100 contributors. The winning circuits slashed the principal resource cost by 86.1%: logical qubits down from 2,715 to 1,151 (57.6% fewer), Toffoli gates down from ~3.96 million to ~1.3 million (67.2% fewer). Post-deadline entries pushed further — one memory-conserving circuit uses just 813 logical qubits.
And here’s the dagger: the team’s score sits more than 50% below a point-addition benchmark Google reported — the same Google that kept its circuits private while telling everyone else to migrate.
"Google kept its circuits private. ECDSA.Fail’s open community and AI agents more than halved Google’s benchmark score in about two months," said Oli Freuler of StarkWare.
Let’s be precise about what this is and isn’t, because the spin machine is already running.
This is not a working quantum computer cracking a wallet today. Nobody is draining your stack right now. The project optimized one crucial sub-circuit of Shor’s algorithm, not the full attack — full windowed implementations, error correction, hardware compilation, and end-to-end testing are still missing.
But that’s exactly the point. Every single one of those remaining steps is being attacked by the same open-source crowd + AI-agent playbook that just produced an 86% cut in eight weeks. The distance between "impossible" and "expensive" just got a lot shorter, and the people who told you to relax are not the people doing the math.
Now the part nobody wants to hear: the public key for roughly a third of all Bitcoin already sits permanently exposed on the ledger. Point addition isn’t the whole attack, but the exposed-key addresses are the ones that matter when the hardware arrives — and unlike the coins in your hardware wallet, they can’t be moved to safety after the fact.
When the first post-quantum Bitcoin transaction hit mainnet last month (no fork, no upgrade), everyone cheered. And when the community’s so-called "miracle fix" turned out to cost $200 per transaction and need a miner’s permission, the same crowd buried the story.
The migration you keep postponing isn’t a 20-year problem anymore. It’s an 86%-cheaper-in-two-months problem.
Buy Bitcoin on your own terms at loveisbitcoin.com/bull and use coupon LOVEISBITCOIN at checkout.
If 100 volunteers with AI agents can shave 86% off the cost of attacking Bitcoin’s cryptography in eight weeks — after Google spent years telling you its circuits were the gold standard — how comfortable are you with "quantum is decades away" as your whole security plan? And be honest: which part of YOUR stack is sitting in an address with an exposed public key?