Research / Why ECC fails

Why ECC fails under Shor

Bitcoin, Ethereum, Solana, and almost every L2 and DeFi protocol authenticate spend with an elliptic-curve signature: ECDSA on secp256k1, Ed25519, or a close cousin. Those schemes are hard for classical computers because the elliptic-curve discrete logarithm problem (ECDLP) is hard. They are not hard for a large, error-corrected quantum computer.

Shor’s algorithm (1994) turns ECDLP into a period-finding problem that a quantum Fourier transform can solve. The public key, which is already on chain for any reused or spent address, and which is revealed at spend time for many others, is enough to recover the private key. Hash functions are a different story: Grover’s algorithm gives only a quadratic speedup, so SHA-256-class hashes are not the same cliff.

What is in scope

  • ECDSA and Schnorr on secp256k1 (Bitcoin, Ethereum, most EVM)
  • Ed25519 / EdDSA (Solana, many Cosmos and Move chains)
  • BLS and other pairing-based signatures used in consensus or aggregation, also discrete-log / pairing assumptions and also not PQ

What is not a fix by itself

  • ZK-SNARKs over elliptic curves. The proof system can still rest on the same broken groups.
  • Multisig, MPC, or social recovery that still authorizes with ECC keys.
  • “We will hard-fork later.” Migration is a product and governance problem. It is not a cryptographic defense today.

For current resource numbers and the Q-Day range, see Resource estimates and Q-Day. For what a real response looks like, see What “good” looks like.