IBM Quantum Hardware Cracks 15-Bit ECC Key, but Bitcoin Devs Say Random Bits Match the Result

2 hours ago

Post-quantum startup Project Eleven awarded its 1 BTC Q-Day Prize to autarkic researcher Giancarlo Lelli connected April 24, 2026, for breaking a 15-bit elliptic curve cryptography cardinal connected a publically accessible IBM quantum computer, a effect the institution called the largest nationalist objection of its benignant to date.

Key Takeaways:

  • Project Eleven awarded researcher Giancarlo Lelli 1 BTC ($78,000) for cracking a 15-bit ECC cardinal connected IBM quantum hardware connected April 24.
  • Bitcoin developers showed Lelli’s effect replicates with random noise, signaling zero quantum vantage implicit classical methods.
  • The spread from 15 bits to Bitcoin’s 256-bit secp256k1 remains a 2^241 engineering chasm, leaving BTC information intact for now.

Project Eleven Hands Giancarlo Lelli 1 Btc for 15-Bit ECC Quantum Break, but Software Developers Call It Noise

Project Eleven described the feat arsenic a 512-fold summation successful search-space complexity implicit a anterior 6-bit ECC interruption completed by technologist Steve Tippeconnic connected IBM hardware successful September 2025. CEO Alex Pruden framed the accomplishment arsenic grounds that quantum attacks connected ECC nary longer necessitate nationalist labs oregon proprietary hardware.

The prize, valued astatine astir $78,000 astatine the clip of award, was designed to connection reproducible nationalist measurements of quantum attacks connected ECC for cardinal sizes betwixt 1 and 25 bits. Lelli’s submission, including afloat codification and execution logs, is publically disposable connected Github.

IBM Quantum Hardware Cracks 15-Bit ECC Key, but Bitcoin Devs Say Random Bits Match the ResultProject Eleven’s X post. Source: X

Lelli implemented a two-register variant of Shor’s algorithm connected IBM Quantum unreality hardware, targeting elliptic curves of the signifier utilized successful Bitcoin’s secp256k1 standard. The circuit ran crossed aggregate IBM Heron r2 processors, including ibm_torino and ibm_fez, and relied connected techniques designed for noisy intermediate-scale quantum devices.

Bitcoin developers and cryptographers moved rapidly to disregard the result, contending that the quantum hardware added nary meaningful worth to the outcome. Project Eleven’s X station announcing the milestone present carries a Community Notes fact check, stating that the attack utilized to retrieve the 15-bit ECC cardinal depends connected classical verification of outputs indistinguishable from random noise, efficaciously amounting to classical guessing.

Former Bitcoin Core maintainer Jonas Schnelli analyzed Lelli’s submission and recovered that the IBM circuit, moving astir 98,000 gates astatine astir 99.5% per-gate fidelity, produced outputs statistically indistinguishable from random coin flips.

Schnelli reproduced the afloat cardinal betterment successful astir 20 lines of Python utilizing axenic random bits, with nary quantum hardware involved. His decision was direct: the quantum machine added nary detectable awesome implicit classical randomness.

Coinkite founder, Rodolfo Novak, insisted Project Eleven is misleading the public, calling its quantum claims “theater.” On X helium argued “the private key is classically solved earlier the quantum circuit adjacent runs” and that the strategy “isn’t uncovering thing — it’s being told the answer,” adding the results trust connected “a classical verify filter.” Novak concluded that portion “the quantum menace to Bitcoin is existent but distant,” today’s demos are “classical computations wearing quantum costumes.”

Researcher Yuval Adam confirmed the uncovering independently by swapping Lelli’s IBM quantum backend for /dev/urandom, Linux’s classical random fig generator, and recovering the people cardinal identically. The 15-bit curve carries a hunt abstraction of lone 32,767 imaginable private keys, tiny capable that a classical verifier checking candidates against the nationalist cardinal finds a lucifer done near-random sampling astatine precocious probability.

Bitcoin proponent Jimmy Song described the quantum machine arsenic performing the aforesaid relation arsenic /dev/urandom. The X relationship TFTC noted successful a wide work thread that each nationalist Shor’s algorithm objection connected ECC to day relies connected classical pre-computation that efficaciously encodes the reply into the circuit earlier quantum hardware runs.

IBM Quantum Hardware Cracks 15-Bit ECC Key, but Bitcoin Devs Say Random Bits Match the ResultSource: X

Critics besides pointed to a struggle of involvement successful the prize structure. Project Eleven, backed by Coinbase Ventures, Castle Island Ventures, Variant, and Balaji Srinivasan, created the prize, judged submissions done 3 autarkic physicists, awarded the bounty, and past issued property releases informing that astir 6.9 cardinal BTC held successful wallets with exposed nationalist keys faced imaginable semipermanent risk. The institution sells post-quantum cryptography tools.

Project Eleven Founder Addresses the Criticism

Pruden acknowledged successful a follow-up thread that the effect was not Q-Day and that NISQ-era experiments routinely beryllium connected classical assistance. He argued the demo inactive represented incremental, reproducible advancement connected accessible nationalist hardware and that migration readying for post-quantum cryptography remains a tenable semipermanent priority. The Project Eleven enforcement added:

“Bottom line: This is incremental advancement successful a noisy, aboriginal tract — not Q-Day. It highlights wherefore we way assets reductions and wherefore post-quantum migration readying matters for semipermanent security. Skepticism is healthy; moving goalposts isn’t. Happy to sermon the method details oregon stock the repo/judges’ feedback.”

The spread betwixt Lelli’s effect and immoderate applicable menace to Bitcoin is substantial. Bitcoin’s secp256k1 curve operates astatine 256-bit security. The region from 15 bits to 256 bits represents a origin of 2 to the powerfulness of 241 successful computational difficulty. Even optimistic caller research, including a Google paper published successful April 2026, estimates that breaking 256-bit ECC would necessitate less than 500,000 carnal qubits, a threshold that existent quantum hardware falls acold abbreviated of.

The occurrence illustrates a hostility that has persisted crossed quantum computing coverage: incremental hardware milestones make headlines, but the region betwixt toy-scale demonstrations and accumulation cryptographic systems remains an engineering spread without a near-term solution. Bitcoin’s information exemplary depends connected that gap, and developers accidental it remains intact.

View source