Markets
BTC— —
ETH— —
SOL— —
XRP— —
BNB— —
ADA— —
DOGE— —
MCap— —
BTC— —
ETH— —
SOL— —
XRP— —
BNB— —
ADA— —
DOGE— —
MCap— —
Tech

A Researcher Just Broke a 15-Bit Elliptic Curve Key on a Quantum Computer and Won a Bitcoin for It

Giancarlo Lelli used a variant of Shor's algorithm on publicly accessible quantum hardware to derive a private key from its public counterpart, claiming Project Eleven's Q-Day Prize and advancing the timeline for practical quantum attacks on cryptographic systems.

By Aubrey Swanson··3 min read
A Researcher Just Broke a 15-Bit Elliptic Curve Key on a Quantum Computer and Won a Bitcoin for It

Key Points

  • Giancarlo Lelli used a variant of Shor's algorithm on publicly accessible quantum hardware to derive a private key from its public counterpart, claiming Project Eleven's Q-Day Prize and advancing the timeline for practical quantum attacks on cryptographic systems.

Giancarlo Lelli has won one bitcoin — worth roughly $77,500 at current prices — for breaking a 15-bit elliptic curve key on a publicly accessible quantum computer, the largest such attack ever executed on real hardware.

The bounty came from Project Eleven, a post-quantum security firm that launched the Q-Day Prize in late 2025 to incentivise researchers to push the boundary of what quantum machines can actually do to the cryptography underpinning bitcoin and most of the internet. Lelli used a variant of Shor's algorithm to derive a private key from its corresponding public key across a search space of 32,767 possibilities. The previous record — a 6-bit demonstration by Steve Tippeconnic in September 2025 — covered a search space of just 64.

That 512-fold increase matters more than it might sound. Quantum computing progress isn't measured in the tidy doublings that classical hardware follows; each additional bit of key length exponentially increases the computational burden. Lelli's result doesn't threaten bitcoin's 256-bit elliptic curve security — the gap between 15 bits and 256 bits is astronomical — but it demonstrates that practical quantum attacks on real cryptographic systems are accelerating faster than many in the industry assumed.

Advertisement

728×90

Project Eleven, which raised $20 million in a Series A earlier this year, designed the prize to produce empirical benchmarks rather than theoretical estimates. Most projections for when quantum computers will crack bitcoin's cryptography rely on extrapolations from laboratory conditions and unpublished hardware specifications. The Q-Day Prize demands that entrants use publicly accessible machines and publish their methods, creating a verifiable record of what current technology can and cannot do.

The timing adds weight to a debate that has consumed bitcoin's developer community for months. Roughly 6.9 million bitcoin — about a third of total supply, including Satoshi Nakamoto's estimated one million coins — sit in wallets whose public keys are already visible on-chain. These coins are stored in older address formats that published the public key by default, or in wallets that have been spent from at least once, which reveals the key for whatever balance remains. A sufficiently powerful quantum computer could, in theory, derive the private keys for all of them.

Ethereum has responded with a coordinated, well-funded post-quantum migration plan. Bitcoin has not. The network's anti-centralisation culture makes large-scale protocol changes exceptionally difficult to push through; its governance, such as it is, treats any central authority as a design failure. The result is a slow-moving standoff in which everyone agrees the threat is real but nobody can agree on what to do about it.

Resource estimates for a full-scale attack on 256-bit elliptic curve cryptography have been falling. Current projections suggest a quantum computer would need fewer than 500,000 physical qubits to break bitcoin's key scheme — still far beyond the capabilities of today's machines, which top out in the low thousands, but no longer the kind of number that allows the industry to dismiss the problem as a concern for the next generation. IBM's roadmap targets 100,000 qubits by 2033; Google has made similar commitments.

Lelli's achievement won't keep anyone at Coinbase or Fidelity up at night. But it moves the conversation from "if" to "when" in a way that theoretical papers and conference talks do not. A working demonstration on publicly accessible hardware carries a rhetorical force that equations on whiteboards lack — it is the difference between knowing a lock can be picked and watching someone pick it.

The Q-Day Prize remains open for further submissions. Project Eleven has said it will increase the bounty as researchers push into higher bit ranges, though it hasn't specified by how much. The firm is also working with the Solana Foundation on post-quantum security for that network, and its Series A backers include several institutional investors who have publicly expressed concern about the quantum timeline.

For bitcoin, the uncomfortable fact is that the network's greatest strength — its resistance to top-down change — is also the quality that makes it most vulnerable to a threat requiring coordinated, urgent action. The 15-bit key Lelli broke is a toy by cryptographic standards. The 256-bit keys protecting $1.5 trillion in value are not.

MiningPool content is intended for information and educational purposes only and does not constitute financial, investment, or legal advice.

Advertisement

728×90

Related Stories

NEAR Intents Says an Omni Bridge Bug Cost It About $3.8 Million
Markets

The protocol halted services, patched the contract-side flaw and promised to compensate users in full, naming eleven networks whose deposits and withdrawals would stay down for another 12 hours. Investigators who traced the outflows do not agree on where the money went.

·MiningPool Staff
Buterin Expects Hegotá to Be Ethereum's Last Normal Fork
Tech

Buterin's post puts Ethereum's 2030 target at four to eight second slots and finality in eight to 32 seconds, against 12-second slots and about 13 minutes today. It also has nodes checking a proof instead of re-executing every block.

·MiningPool Staff
Bitget Says Its Own Approval Process Released $351.6 Million
Tech

The exchange's security notice declined to name an attack vector, and hours later its chief executive said the attacker spoofed transaction data through a compromised backend system, ruling out private key theft. Withdrawals remain suspended, and the loss is close to 76 percent of the User Protection Fund Bitget says covers it.

·MiningPool Staff
Only Agave Can Run Alpenglow as Solana Starts the Testnet Phase
Tech

Anza is targeting about 150 milliseconds to finality, down from the roughly 12.8 seconds it attributes to TowerBFT, but Firedancer and Frankendancer cannot run the code yet. No mainnet date has been announced, and September 28 is a feature-gate processing date rather than a confirmed Alpenglow launch.

·MiningPool Staff
Solana's Slots Are 250ms Now and Still Run About 16ms Long
Tech

Network-reported block times put the new slots at about 267 milliseconds on average, the same roughly 16-millisecond overhead that sat on top of the 400, 350 and 300 millisecond targets before it. Block limits fell in proportion, so throughput stays at 150 million compute units a second.

·MiningPool Staff
Celsius's Estate Wants 6,360 Bitcoin Back From a Closing BitMEX
Business

Blockchain Recovery Investment Consortium filed in the Southern District of New York on September 12, eleven days before BitMEX stops trading, over positions liquidated on March 12 and 13, 2020. The complaint alleges the exchange controlled both the liquidation engine and the insurance fund that took the positions over.

·MiningPool Staff

Stay informed

Verifiable crypto journalism, delivered to your inbox.

Weekday mornings. No hype. No financial advice. Just what happened and why it matters.

No spam. Unsubscribe anytime. Read our privacy policy.