Eighty-six percent. That's how much a crowd of volunteers and AI coding agents say they shaved off the estimated quantum cost of attacking Bitcoin's signature scheme — and by their own accounting, that lands meaningfully below a benchmark Google's own quantum team published back in March. Now, is a crowdsourced leaderboard actually out-optimizing Google's private lab work, and does that change how fast the countdown on breaking today's crypto really runs? That's our main story. Before that, in the headlines: a new report argues quantum investors have been pouring money into the wrong layer of the stack, and Swedish researchers just found a way to make certain quantum operations a thousand times faster. Welcome back to Quickly Quantum, your daily brief on the quantum frontier. It's Friday, September 11, 2026. Let's get into it. Now, where's the smart money in quantum actually going? The Quantum Insider reports on a new analysis from Novo Holdings — the investment arm behind the Novo Nordisk Foundation — arguing that quantum investing has to move past hardware and start funding the software and applications layer instead. The Quantum Insider reports that roughly seventy percent of the approximately thirteen point nine billion dollars invested in private quantum computing companies between 2014 and 2025 went to hardware and components — the processors and physical machines. That figure, per the outlet, doesn't include public-market deals or government funding, so the real tilt toward hardware could be even bigger than it looks. Novo Holdings' pitch, as reported: value won't just sit wherever a company builds the flashiest chip, it'll collect around what the report calls 'control points' — capabilities that are scarce, that customers become dependent on, and that one company can actually own. Think ASML's grip on lithography equipment, or Arm licensing its chip architecture to nearly everyone; the report leans on that same semiconductor-industry history as its model. And it singles out life sciences as the clearest opening for you to watch, since drug companies already pay real money to sharpen molecular decisions, quantum or not. This is a single-source report we haven't independently verified beyond The Quantum Insider's write-up, but it's a useful gut check on where the industry's hype-to-dollars ratio actually sits. Errors are still quantum computing's biggest enemy, and researchers in Sweden just bought engineers real time to fight them. A team at Chalmers University of Technology, publishing in Physical Review Letters, found a way to run a wide range of quantum operations more than a thousand times faster than before. The target here is bosonic codes — a way of storing quantum information not in single fragile qubits but spread across the microwave fields inside a superconducting circuit, which gives it sturdier natural protection against certain errors. The catch has always been speed: building these bosonic quantum states used to take thousands of repeated driving cycles, and every extra cycle is another chance for noise to wreck your calculation. Lead author Tangyou Huang and co-author Lei Du built what they call quantum lattice gates — pre-built shortcut operations that Huang compares to snapping together Lego modules instead of laying every brick by hand — letting the same operations finish in a single driving cycle instead of thousands. That's the fault-tolerance bottleneck, the trade-off between operation speed and error accumulation, getting meaningfully better. This is a theoretical and computational result, not a demonstration on a working chip, but it's exactly the kind of speed-up superconducting quantum computers need before they can run the long, error-corrected calculations everyone keeps promising you. Let's get into the specifics on our main story, because the framing here matters as much as the number itself. In March, a team at Google Quantum AI published an estimate of how many quantum resources it would actually take to break the elliptic-curve cryptography — the math locking up digital signatures — that underpins Bitcoin, Ethereum, and plenty of other blockchains. That paper became the benchmark everyone in this space measures against, even though Google never published the full circuit behind it. Now, Bitcoin and Ethereum both rely on a curve called secp256k1 to prove a transaction really came from the person holding the private key. It's a hard problem for an ordinary computer to reverse-engineer a private key from a public one — but it wouldn't be hard, in theory, for a large enough fault-tolerant quantum computer, one built with enough error-corrected qubits to run long calculations without noise wrecking the answer, running something called Shor's algorithm, a quantum method built specifically to crack this kind of math. This isn't an abstract worry, either. Security researchers have talked for years about a 'harvest now, decrypt later' threat — the idea that an adversary could grab public keys today and just wait for a quantum computer powerful enough to crack them later. For blockchains, that risk is baked into the design, because every public key ever used gets written permanently to a public ledger, sitting there, waiting. That's the backdrop for ECDSA.Fail, an open contest Eigen Labs launched in late May. The idea: instead of one closed lab quietly optimizing this attack, put the core arithmetic step — something called point addition, repeated over and over inside Shor's algorithm — on a public leaderboard, and let anyone try to improve it. More than a hundred human researchers signed up, some working directly, some directing AI coding agents to propose changes, and every submission got checked against a shared, machine-verifiable scoring rule: multiply the circuit's peak number of logical qubits — error-corrected units of quantum information built from many physical qubits — by its average number of Toffoli gates, a costly quantum operation commonly used to estimate how much work a fault-tolerant machine would actually have to do. The starting circuit needed 2,715 logical qubits and an average of 3,960,753 Toffoli gates. By the contest's July 26th data cutoff, over roughly eight weeks and more than 400 promoted submissions, the best entry had cut that down to 1,151 logical qubits and about 1,299,453 Toffoli gates. Run the math on the combined score and that's an 86.1% reduction from where the project started — about one-seventh of the original cost. The logical-qubit count alone dropped 57.6%, and the Toffoli count dropped 67.2%. And here's the number that got Eigen Labs and its contributors talking: by their own accounting, that final circuit lands more than 50% below the point-addition benchmark Google reported in March. Two things to hold onto before we go further, though. First, nobody broke a Bitcoin key — no quantum computer exists today that could run this circuit, this is still purely a paper exercise in resource accounting. Second, the paper's own authors, a mixed group from Theta Labs, MultiVM Labs, Eigen Labs, Trail of Bits, StarkWare, and the Ethereum Foundation, caution that their circuit and Google's use different interfaces, different assumptions, and different accounting methods. So how does that debate actually sound in the voices who lived it? Eigen Labs and its contributors are framing ECDSA.Fail as proof of concept for something bigger than one cryptography benchmark — what they call open autoresearch, humans and AI agents working against a shared, machine-checkable target instead of behind closed doors. Jieyi Long, the paper's lead author and co-founder and CTO of Theta Labs, put it this way in a statement: 'As quantum hardware advances, we need credible, reproducible estimates of the resources required to break deployed cryptography. Those estimates help us understand the remaining gap and plan migration before it closes. Across over a hundred contributors the collective effort halved the cost estimate of the central arithmetic step. The consequence falls hardest on blockchains, because a public key written to a ledger is exposed permanently and roughly a third of all bitcoin already sits in addresses where the key is visible. None of this is urgent because an attack is imminent. It is urgent because the remedy takes years and cannot be applied retroactively.' His conclusion, in other words: this isn't a fire alarm, it's a planning document. Oli Freuler, head of product growth at StarkWare, used the result to push a sharper argument, saying in a statement: 'Google kept its circuits private. ECDSA.fail's open community and AI agents more than halved Google's benchmark score in about two months. Starknet's proofs are hash-based and post-quantum by design. The industry must upgrade before quantum hardware catches up.' Freuler's read is blunt: stop waiting on hardware timelines and move to cryptographic schemes that don't rely on the math Shor's algorithm threatens in the first place. Not everyone in the same paper is quite that confident about the comparison itself, though. The authors' own caveat — that different interfaces and accounting methods make a direct 'we beat Google' claim shaky — is worth sitting with, because it means the specific percentage you hear floating around depends entirely on which baseline you're measuring against. The 86.1% figure is against ECDSA.Fail's own starting point. The 'more than 50% below Google' figure is a separate, less apples-to-apples comparison the authors flag themselves. It's not entirely clear from the coverage which of those two numbers the public conversation online is actually running with, and that ambiguity matters. The project didn't stop at its official cutoff, either. After July 26th, contributors kept going, pushing the combined score down further to about 1.259 billion, using 1,321 logical qubits and fewer than a million average Toffoli gates. A separate branch of the effort optimized for memory instead of speed, landing on a circuit that needs just 813 logical qubits, though it requires far more operations to get there. Which tells you this number isn't settled even by the contributors' own account — it's still moving under you as we speak. Meanwhile, the blockchain industry isn't just watching from the sidelines. NEAR Protocol posted on X this week laying out what it's calling its quantum-safe roadmap, writing that through something it calls Chain Signatures, a NEAR account holding a quantum-resistant signing key — ML-DSA, a post-quantum signature scheme — can hold and protect assets from other blockchains, even ones that haven't upgraded their own signing yet. That's the company's own announcement about its own product, so take it as exactly that, but it's a real, live example of the migration Long and Freuler are both talking about actually starting, ahead of any hardware that could force the issue. Here's my read. The technical achievement is real — cutting a resource estimate by more than four-fifths through an open, AI-assisted process, in about two months, with contributors nobody hand-picked, is a genuinely interesting result about how research itself might get done, independent of what it says about your Bitcoin. But the 'beat Google' framing is doing more work than the paper's own authors are willing to sign off on, and that gap matters more to me than the headline number. What would change my mind? A version of this circuit run end-to-end against Google's exact accounting rules, with both labs agreeing on the same scoring method. Until that exists, we're comparing two different rulers and calling it a race. Time for the Hype Check. On one side, this is a legitimate, peer-reviewable improvement to a well-defined subroutine, produced faster and more openly than a closed corporate lab managed on the same problem, and it genuinely strengthens the case for starting post-quantum migration now rather than later. On the other side, no quantum computer alive can run this circuit, no key has been broken, and the 'we beat Google' framing outran what the authors themselves will stand behind. Add it all up, and that's a five. If today's episode made you want the play-by-play on the post-quantum migration blockchains are already starting, follow Quickly Quantum wherever you get your podcasts — new episodes land every weekday morning. We'll be tracking whether anyone actually runs this circuit against Google's own accounting rules, because that's the comparison that would settle this argument for good. This has been Quickly Quantum, an AI-voiced podcast, created and built by a real human using today's cutting-edge technology. Nothing you heard on this show is financial advice. I'm Brian Lampert, and I'll catch you all tomorrow — take care! I also host Concrete Compute: a daily briefing on the AI buildout. The datacenters, the megawatts, and who actually pays for them. Find it wherever you get your podcasts.