ECDSA.Fail Cut Its secp256k1 Point-Addition Benchmark Score 86 Percent on 9 September 2026; a Day Later Scripps Found 32 US States Without a Confirmed Post-Quantum Plan

Board-ready intelligence on quantum innovation · Biomedical discovery · Post-quantum transition
A 36-author arXiv paper puts the best-scoring contest circuit at its 26 July cutoff at 1,151 logical qubits. A 50-state investigation confirms four states with an active migration plan and finds no confirmed plan in 32. The two numbers were published one day apart.

Post-Quantum Transition

A 36-author arXiv paper puts the best-scoring contest circuit at its 26 July cutoff at 1,151 logical qubits. A 50-state investigation confirms four states with an active migration plan and finds no confirmed plan in 32. The two numbers were published one day apart.

Published by Quentir Systems LLC · September 11, 2026 · 8 min read

In August 1977 Martin Gardner's Scientific American column printed a 129-digit number and a ciphertext, and passed on the RSA inventors' estimate that factoring it would take on the order of forty quadrillion years. In April 1994 about six hundred volunteers, coordinating over the internet for eight months, factored it and read the message. Three things had changed in the seventeen years between: factoring algorithms, above all the quadratic sieve, had improved by orders of magnitude; computers had become far faster and far more numerous; and a hard problem had been turned into a public, checkable challenge that a crowd could join. The 1977 estimate had priced none of the three.

On 9 September 2026, 36 authors led by Jieyi Long posted arXiv:2609.09582, “ECDSA.Fail: Open Autoresearch for Optimizing Elliptic-Curve Point Addition in Shor's Algorithm”. It reports an eight-week public contest run by Eigen Labs in which humans and AI agents submitted improvements to a public leaderboard, each one verified by an evaluator before it counted. The target was the reversible secp256k1 point-addition circuit, the subroutine that Shor's algorithm calls over and over when it attacks the elliptic-curve signatures under Bitcoin and Ethereum. Participants cut the benchmark score by 86.1 percent. The following day, 10 September 2026, the Howard Center for Investigative Journalism at Arizona State University and Scripps News published a 50-state analysis showing that four US states have an active plan to migrate to post-quantum cryptography and 32 gave the reporters no confirmation of one. This post asks one question about those two publications: did the first one change what the 32 states in the second one should do?

Practical takeaway. The ECDSA.Fail figures describe one subroutine of one attack under one benchmark's accounting; they lower the best public circuit width and gate count for that subroutine and say nothing about physical hardware or a date. They do show that one public contest, in eight weeks, moved a component of the attack estimate by 86 percent through algorithm design alone. A migration plan whose schedule depends on a specific Q-Day year inherits that volatility; a plan whose schedule follows the lifetime of the data it protects does not, and 32 states have confirmed neither.

What the 36 authors published on 9 September 2026, and how the contest was scored

The paper proposes a method it calls Open Autoresearch: humans and AI agents publish evaluator-verified improvements to a public leaderboard, so that every step in the optimization is reproducible and attributable. The benchmark it instantiates minimizes a spacetime score S = Q × T, where Q is the peak number of logical qubits the circuit holds at once and T is the average number of Toffoli gates it executes. Toffoli gates are the expensive operations in fault-tolerant quantum computing. The authors call the score spacetime-inspired and are explicit that it is a benchmark for comparing circuits, and that it is not an estimate of the physical resources an attack would consume.

The starting score was about 10.75 billion. At the data cutoff of 26 July 2026 the best circuit used 1,151 qubits and 1,299,453 average executed Toffoli gates, for a score of about 1.496 billion. After the cutoff the score fell further to 1.259 billion, and a separate low-width circuit reached 813 qubits. The paper places these numbers more than 50 percent below the point-addition thresholds in Google's March 2026 resource estimate for elliptic-curve cryptocurrencies (arXiv:2603.28846), while stating in the same sentence that the two results use different accounting conventions. Because the benchmark supplied one addend classically, the authors also built a windowed-addition variant that implements the interface a full Shor run needs: 1,162 qubits, 1,684,161 Toffoli gates, and an empirical success probability of 0.99809 on 100,000 random inputs. They describe the resulting figure as a per-call sensitivity model and, in their own words, not a full-Shor success estimate.

What 1,151 logical qubits measures, and what it leaves out

The number that traveled from this contest into corporate disclosures, and now into headlines, is a width. It is the peak count of logical qubits held during one point addition. The physical qubit count a machine would need depends on the error-correction code, the physical error rate and the run time, and is a separate calculation the paper does not make. The gate count moves the other way as width falls: the 813-qubit design pays for its narrowness in Toffoli operations. A full attack strings together many of these additions and has to keep every one of them error-free for the duration. The same techniques may carry to the NIST P-256 curve that signs TLS certificates and software updates, since the two curves differ in their constants, but the figures themselves belong to secp256k1 and to this benchmark. Quentir's Defense Monitor covered the first of these misreadings on 7 September, when Circle's 31 August disclosure lifted the 813 figure off the leaderboard without the gate count or the error-correction overhead that give it meaning.

What the paper does establish is narrower and more durable than a date. Circuit-level attack cost is now something a public crowd, augmented by coding agents, can compress by a large factor in weeks, with each step verified and published. The authors are careful about what that proves: the public record, they write, shows AI agents complementing human judgment on objectives that are efficiently evaluable and machine-checkable. Point addition is such an objective. Building a fault-tolerant processor is not. The hardware side of the estimate moves on the timetable of physics and manufacturing; the circuit side has now been shown to move, at least once, on the timetable of a leaderboard.

What the Howard Center found in the 50 states on 10 September 2026

The Howard Center's reporters, Grant Johnson, Emily Mosier and Gaige Davila, used open-records requests and direct inquiries to every state. Four states confirmed an active plan to migrate to post-quantum cryptography: New Jersey, whose security manual requires all agencies to identify vulnerable systems and develop a migration plan; New York, whose statewide encryption policy requires an inventory of vulnerable systems for the purpose of migrating; Missouri, whose Office of Administration described a multi-step implementation roadmap run by a cross-functional planning team; and Maryland, whose Department of Information Technology provided a redacted executive briefing on a statewide rollout. Fourteen more states are committed to or developing a plan.

The other 32 fall into three groups. Seven are aware of the risk and researching whether they need a plan. Nine either did not fulfill the records request or cited security concerns in refusing to say whether a plan exists. Sixteen said they had no records of any post-quantum plan, roadmap or migration timeline. Mississippi's Department of Information Technology Services wrote that the state “has not adopted, nor is it currently developing” one. New Hampshire's said it had “not begun any research or planning.”

The human scale of that gap is in St. Paul, Minnesota. In July 2025 a ransomware group published the Social Security numbers, addresses, birthdays and phone numbers of more than 12,000 residents after breaching the city's systems; the governor declared a state of emergency and deployed the National Guard's cyber protection team for the first time in the state's history. The city's 2026 budget sets aside one million dollars for cybersecurity upgrades. None of it goes to post-quantum cryptography. The city's chief information officer, Jaime Wascalus, told the reporters that she has had no direction on post-quantum readiness from the federal government or from the state, and that the systems she worries about first are the ones that identify and alert police, fire and sheriff's units to an emergency.

Why executive order 14412's 2030 and 2031 deadlines stop at the federal boundary

The federal instrument that exists is executive order 14412 of 22 June 2026. It directs agencies to move their high-value and high-impact systems, excluding National Security Systems, to post-quantum cryptography for key establishment by 31 December 2030 and for digital signatures by 31 December 2031, to submit a plan for doing so, and it orders a proposed Federal Acquisition Regulation rule requiring covered contractors to comply by the end of 2030. The order cites adversaries collecting encrypted US data now to decrypt it later, and that exposure attaches to intercepted traffic whose key establishment is vulnerable, while a signature scheme is attacked at the moment of forgery; the order sets the signature date a year later without stating a reason. For everyone outside the federal estate the order goes as far as asking Sector Risk Management Agencies to work with CISA in helping critical-infrastructure owners and operators develop their own plans. It contains no direction to states, counties or cities, and the Howard Center found no comparable mandate for most state or local governments, which hold medical, criminal and voting records and run 911 dispatch, election systems and utilities. Under OMB memorandum M-26-15, the agencies' own migration plans are due on 22 October 2026. Dustin Moody, who leads NIST's post-quantum project, told the reporters he does not expect every federal agency to make the 2030 date, and described the migration as “incredibly complex, difficult, complicated, costly.” A 2024 White House report to Congress priced the federal high-priority systems alone at 7.1 billion dollars, excluding national security systems. Garfield Jones, who led CISA's post-quantum migration effort for five years before leaving in late 2025, spent his last year meeting state officials and found that many did not understand the urgency; his forecast for the pace of change was that aircraft carriers turn more easily.

This is the same structural gap Quentir described in the financial sector when the Treasury stood up a task force for ciphertext already on deposit: the federal clock runs, the entities that hold the longest-lived personal data sit outside it, and the money to close the gap has not been appropriated. Representative Suhas Subramanyam's bill for a federal assessment of national quantum readiness, folded into the National Quantum Initiative Reauthorization Act in April, specifies no funding; a Senate version would authorize roughly 2.7 billion dollars over five years for federal quantum programs, which is a research figure, not a migration one.

How Quentir Reads It

The honest answer to this post's question is that the ECDSA.Fail paper did not change what the 32 states should do, and that is the finding worth keeping. A state that holds birth records, criminal histories and voter files is protecting data with a useful life measured in decades. Wherever that data has crossed a network under vulnerable key establishment and been intercepted, the harvest-now-decrypt-later exposure already exists, and no revision of a circuit benchmark, up or down, alters it. Of the four states with confirmed plans, New York's policy starts with an inventory of vulnerable systems, and New Jersey's manual with identifying vulnerable systems, which is the step every later decision depends on. The reporting does not say whether any of the 32 states has an inventory; it says they confirmed no plan, and that seven of them are researching whether they need one.

What the paper does change is the credibility of any plan whose schedule rests on a Q-Day year. Google's March estimate was the public reference for point addition for six months; one contest cut that component by more than half under its own accounting, and the authors report further gains after the cutoff. An organization that set 2035 as its migration horizon on the strength of a 2026 forecast now has to explain which parts of that forecast it expects to hold still. The RSA-129 result of 1994 carried the same lesson: the 1977 estimate had been made without pricing algorithmic progress, faster machines or a crowd. The 100-plus participants and their agents on the ECDSA.Fail leaderboard are that crowd for elliptic curves, and they now publish on arXiv.

The paid editions that continue this file, every Signature Brief and Signature Report as it publishes together with both Registers, sit under one organization-wide All-access membership.

The next number to watch sits outside the leaderboard: how many of the 14 states that told the Howard Center they are committed to or developing a plan have published one by 22 October 2026, when the federal agencies' own plans are due, and whether any of the 16 states with no records at all has started an inventory. The attack side reported its progress in public within seven weeks of its cutoff. The defense side, for 32 states, has not yet confirmed a migration plan.

Sources. Jieyi Long et al., “ECDSA.Fail: Open Autoresearch for Optimizing Elliptic-Curve Point Addition in Shor's Algorithm”, arXiv:2609.09582, submitted 9 September 2026 — the Open Autoresearch method, the Q × T score, the 86.1 percent reduction, the 26 July 2026 cutoff figures (1,151 qubits, 1,299,453 Toffoli, about 1.496 billion), the windowed variant (1,162 qubits, 1,684,161 Toffoli, success probability 0.99809), the post-cutoff 1.259 billion score and 813-qubit circuit, the comparison with Google's thresholds under different accounting conventions, and the authors' statement that the figure is not a full-Shor success estimate. The roughly 10.75 billion starting score is derived from the stated 86.1 percent reduction. Google Quantum AI, “Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities: Resource Estimates and Mitigations”, arXiv:2603.28846, 30 March 2026 — the point-addition thresholds the ECDSA.Fail paper compares against. Grant Johnson, Emily Mosier and Gaige Davila, Howard Center for Investigative Journalism at Arizona State University and Scripps News, “The Coming Q-Day: US states largely unprepared as quantum computing threats loom”, published 10 September 2026 — the 4/14/32 state breakdown and its 7/9/16 sub-groups, the named states and their policies, the St. Paul budget and July 2025 breach, the Wascalus, Moody and Jones quotations, the 22 June 2026 order as the reporters describe it, the 7.1 billion dollar 2024 White House estimate, and the Subramanyam bill. The White House, Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks, 22 June 2026 — section 4(b): key establishment by 31 December 2030 and digital signatures by 31 December 2031 for high-value and high-impact systems excluding National Security Systems; section 6(c): the proposed FAR rule for covered contractors; section 5(a): the critical-infrastructure assistance provision. Office of Management and Budget, M-26-15, Execution of the Migration to Post-Quantum Cryptography — the 22 October 2026 date for agency migration plans. Quentir Defense Monitor, Circle's August 31 Disclosure Reads 813 Logical Qubits Off Eigen Labs' ECDSA.fail Leaderboard, 7 September 2026, and A Task Force for the Ciphertext Already on Deposit. Historical: Martin Gardner, “Mathematical Games”, Scientific American, August 1977 (the RSA-129 challenge); D. Atkins, M. Graff, A. K. Lenstra and P. C. Leyland, “The Magic Words Are Squeamish Ossifrage”, ASIACRYPT 1994 (the April 1994 factorization by about 600 volunteers over eight months using the multiple-polynomial quadratic sieve); C. Pomerance, “A Tale of Two Sieves”, Notices of the AMS 43 (1996), 1473–1485 (the algorithmic history). Sources checked 11 September 2026.

Published intelligence, built to inform your own decisions. Published: September 11, 2026.

© 2026 Quentir Systems LLC
Previous
Previous

GPT-6 Astra Is the First OpenAI Model Rated Critical for Cyber: From the 18 August 2026 Training Pause to the 3 September System Card, and What EU AI Act Article 55 and California SB 53 Ask of It

Next
Next

FIPS 203 and FIPS 204 Do Not Specify the Silicon: the 9 September 2026 NTT Patent Screening, and the Two Portfolios NIST's Royalty-Free Licenses Cover