On September 10, 2024, a paper appeared online with no peer review, no public circuit repository, and one number that will be screenshotted out of context for the next six months: a composite score of 1.5 billion, set against Google's own published estimate of 3 billion for the same class of attack.
Halved. A 50% reduction in the estimated resources required to break the signature scheme sitting underneath every Bitcoin and Ethereum address ever generated.
Within hours the framing was locked, and the framing was wrong in one very specific way. The cost of the attack fell. The machine did not get built.
The authors come from Theta Labs, the Ethereum Foundation, and StarkWare. First author Jieyi Long is Theta Labs' CTO. Their target is not Shor's algorithm in its entirety, but one subroutine inside it: the point addition step used to compute discrete logarithms over an elliptic curve. In a circuit that breaks ECDSA, point addition is where depth accumulates, where Toffoli gate counts explode, where error-correction overhead turns a number you can hold in your head into a number you cannot.
Strip the headline away and one figure is left standing. Roughly 1,151 logical qubits, before a single one of them is made fault tolerant.
That figure is the story. Everything else is distribution.
1,151 is not a smaller number than it sounds. It is a bigger number than it sounds.
Here is the part that gets lost. A logical qubit is not a physical qubit. A logical qubit is an abstraction that only exists because thousands of physical qubits are being continuously measured, corrected, and stitched together by an error-correction code that itself consumes enormous resources. The conversion ratio depends on gate fidelity and code distance, but for hardware in the range we actually have, the realistic overhead runs somewhere between a thousand and ten thousand physical qubits per reliable logical qubit.
Run the arithmetic. A 1,151-logical-qubit attack lands somewhere between a million and eleven million physical qubits, all of them coherent, all of them wired, all of them cooled, all of them running a circuit deep enough that the accumulated error budget has to stay below threshold for the entire duration of the computation.
Now look at what exists. IBM's Osprey shipped 433 physical qubits in 2022. Condor reached 1,121 in 2023. Google's Sycamore held 53. Willow, in late 2024, demonstrated something genuinely important: error correction operating below threshold, meaning adding qubits reduces error rather than increasing it. That is a real milestone and it deserves the attention it got.
It is also a demonstration at roughly a hundred physical qubits. The distance between below-threshold-at-100 and fault-tolerant-at-a-million is not a scaling factor you can extrapolate on a napkin. It is a materials and infrastructure problem โ dilution refrigerator capacity, cryogenic wiring density, multiplexed control electronics, fabrication yield across thousands of wafers. Quantum researchers have been honest about this. The constraint is not cleverness. The constraint is plumbing.
I have spent enough time reading circuit papers to know what a circuit paper can and cannot do. It can reduce the gate count for a specific arithmetic operation. It cannot cool a dilution refrigerator. It cannot fabricate a chip. It cannot fix a two-qubit gate fidelity that drifts by a fraction of a percent across a wafer.
The paper improved a design. It did not move a timeline.
And this genre has a track record. In 2019, Gidney and Ekerรฅ published an estimate putting RSA-2048 at roughly 20 million noisy qubits and eight hours of runtime. That number was subsequently revised downward more than once, each revision producing a fresh wave of headlines announcing that RSA was finished, and each time RSA remained exactly as broken as it was the day before: not at all, unless you count the fact that its key sizes were always going to grow anyway.
This paper is the same shape of news. Composite score down from 3 billion to 1.5 billion. A 50% headline that is technically accurate and functionally meaningless to anyone holding coins in a bear market.
What the paper's authors aren't saying.
They aren't saying the attack is practical. They aren't saying the timeline compressed. Jieyi Long's public framing was explicit: this is not imminent, and the transition to post-quantum systems takes years. There is no line in the abstract containing the word practical. There is a circuit, an estimate, and a set of assumptions about a fault-tolerant machine that does not currently exist and has no committed delivery date from anyone building one.
So if the threat did not materially change, what actually changed? The vulnerability surface came into slightly sharper focus, and it is not the surface the headlines describe.
Start with what quantum attack on ECDSA can and cannot do. It cannot retroactively recover a private key from a signature. Recorded transactions are not a harvest-now-forge-later problem, because signature verification does not leak the scalar. What an attacker with a fault-tolerant machine can do is attack any public key that is already exposed on-chain and whose owner has not rotated.
On Bitcoin, that means the old pay-to-public-key outputs. The 2009 to 2012 era. Early miner rewards. A long tail of wallets that published the public key directly into the locking script, where it sits permanently visible and permanently attackable by anyone who eventually has the hardware.
Estimates of the quantity sitting in exposed-key outputs run in the vicinity of 1.7 million BTC, and a meaningful portion of it is in a form where upgrading the wallet software of anyone alive will not help, because the owner may be gone, may not have the keys, and may never see the migration notice.
A quantum attacker would not need to break Bitcoin. They would need to break the subset of the supply whose public keys are already published and whose owners cannot or will not move. Some of them can move. Some of them cannot. Some of them are Satoshi's and some of them are simply lost.
That is a governance problem dressed as a cryptography problem, and it is why post-quantum migration on Bitcoin is genuinely hard. Any serious proposal to freeze, fork, or invalidate exposed-key outputs becomes a debate about property rights on a network whose entire social contract is that nobody may seize coins. That fight makes the block size war look like a polite disagreement about a restaurant bill.
Ethereum has the easier path, and this is a real structural difference, not a tribal one. Ethereum has hashed public keys into addresses since genesis. The public key is generally revealed only in the moment of signing, which means a careful user can rotate to a fresh account and be done. EIP-7702 delegated accounts and the general move toward account abstraction add surface area โ a delegated EOA reveals more, more permanently โ but the base primitive is far more forgiving than a chain that stamps raw public keys into unspent outputs.
I didn โ I didn't need to be right about the mechanism in 2022, and I'm not claiming to be right about it now. I needed to be right about the fragility. Two days before Terra's algorithmic stablecoin broke, the flaw was not a secret. It was in the documentation. The bond mechanism, the mint-and-burn reflexivity, the assumption that demand for the peg asset would always outrun the supply of the derivative โ all of it was written down, in public, in plain language, by people who believed their own math.
The lesson transferred cleanly. The danger in this paper is not the circuit. It is the assumption stack underneath it, and the assumption stack is not hidden. It is one page of prerequisites about a machine nobody has built.
Now the part that matters for the next six weeks.
We are watching this land in a market that has spent the year bleeding sideways. Perpetual open interest is thin. Funding sits near zero for long stretches. Exchange volumes are down substantially from the cycle highs. In that environment, a story that lets someone justify a short for an afternoon is worth more than the story's content, and the quantum narrative is structurally perfect for that trade.
It cannot be falsified inside a news cycle. It sounds technical enough that most readers will not attempt a rebuttal, and the ones who do will be drowned out by the percentage. It has a single memorable number โ 50% โ that survives every attempt to summarize it and loses all its caveats on contact with a group chat.
Every crash is just a story that hasn โ it hasn't finished its telling, and this is not a crash. It is a story being loaded into position ahead of one.
In the DeFi winter, we didn โ we watched this exact mechanism wearing different costumes. Yield was the number. TVL was the number. Every one of those figures was real, and every one of them circulated with its assumptions detached. A pool advertising four digits of APR was not lying. It was simply quoting the part of the equation that fit in a tweet, and the part that did not fit was the emissions schedule that funded it and the exit liquidity that didn't exist when everyone left at once.
I hold 5 NFT assets through a 60% drawdown for exactly this reason. The community was real. The engagement was real. Liquidity was not, when it mattered. Social capital and exit liquidity are different assets, and only one of them shows up on the bid.
There is an incentive layer here too, and ignoring it would be naรฏve. Theta Labs builds consensus and validator infrastructure, where quantum resistance is a legitimate selling point for any new design. StarkWare builds STARK provers, and hash-based proof systems are comparatively post-quantum friendly โ Grover's algorithm only halves the effective security of a hash function, so you double the output length and carry on, which is a far cheaper migration than replacing an elliptic curve signature scheme. That is a genuine technical advantage and also a genuine commercial one. The Ethereum Foundation has spent years arguing it needs room to move on the roadmap.
None of this is a conspiracy. It is just how research gets funded, and it is the same instinct that made me read unlock schedules before narratives in 2017. When three organizations with aligned incentives co-author a paper that makes their own roadmaps look prescient, the paper can still be correct. You just have to read it, not the press release.
So where does that leave the two obvious retail responses?
The first is to sell. That is the panic trade, and it is almost always wrong on a long-horizon risk that has no delivery mechanism attached. Nothing about the hardware roadmap changed on September 10. The qubit counts that would signal a real inflection are published by IBM, Google, Quantinuum, and others on their own schedules, and none of them moved.
The second response is more common and more expensive: rotate into quantum-resistant tokens. QANplatform, Algorand, IOTA, QRL โ the labels fit, the narratives fit, and the volumes spike for about a week. In 2023, the same cycle ran roughly the same course. No protocol changed its signature scheme. No user migrated. The volume decayed, the charts round-tripped, and the people who bought the label at the top of the spike learned the difference between a feature and a flow.
A credible quantum timeline is observable, not inferable. You do not need to read papers. You need to read hardware roadmaps, and the roadmaps are all saying the same thing: not yet.
The smarter response is to do nothing with your position sizing and something with your attention. Watch for the first hardware wallet that ships a post-quantum address format. Watch for a serious Bitcoin Core proposal touching P2PK migration, because that discussion, whenever it starts, will be a multi-year consensus fight and its existence will be the first real signal that the industry has begun to take the problem seriously. Watch the NIST post-quantum standards work its way into production libraries โ the standards are already finalized, and adoption is the bottleneck, not the mathematics.
And correct one thing that keeps circulating. Verkle trees are not a quantum defense. They are a state commitment scheme, and they improve proof sizes and stateless client viability. They do nothing for signature security. If you see Verkle trees cited as part of a post-quantum migration, you are reading someone who copied the talking point without reading the roadmap.
Long-horizon risk deserves long-horizon attention right now. But attention is cheap and panic is not, and a bear market is exactly the environment where the two get confused. Very few people have the emotional bandwidth left to hold a position through a grind lower and then absorb a headline about a machine that does not exist. That is precisely the setup where survivable mistakes get made.
The number to carry forward is not 50%. It is 1,151 โ and more usefully, the fact that almost nobody in this ecosystem has started the work that number implies. The migration to post-quantum signatures is a decade-long infrastructure project, and it does not begin with a paper. It begins with a wallet release.
When that release ships, that will be the story.
This one wasn't.
So what exactly do you do with a 1.5 billion composite score on an ordinary Tuesday in a market that already took everything it was going to take this year? Probably nothing. Which is exactly why it will be quoted back at you next month, wearing a new headline, and asking you to feel something.
You do not have to.