A Public Quantum Claim Built on a Private Attack Circuit
Post-Quantum Transition Henry Quentir Post-Quantum Transition Henry Quentir

A Public Quantum Claim Built on a Private Attack Circuit

A claim with a missing circuit

Google Quantum AI researchers published lower resource estimates for using Shor’s algorithm against ECDLP-256, a cryptographic problem that protects many cryptocurrency systems. Their March 30 preprint describes two compiled circuits: one below 1,200 logical qubits and 90 million Toffoli gates, another below 1,450 logical qubits and 70 million Toffoli gates. Under stated assumptions, the authors estimate execution in minutes on fewer than 500,000 physical superconducting qubits. They did not publish the underlying attack circuits. That makes this a distinctive case of quantum vulnerability disclosure: the public receives a serious technical claim and a migration warning while a potentially useful attack roadmap stays private.

Zero knowledge changes the bargain

The proof makes a narrower statement than the headline resource estimate. It attests that the authors possess size-bounded reversible circuits that correctly compute secp256k1 point addition across 9,024 pseudorandom inputs derived from each circuit’s hash. Additional reasoning connects that subroutine to the overall Shor resource estimate. Google’s March 31 account says the team engaged with the U.S. government before publication. Zero-knowledge verification can expose a bounded proposition to checking while preserving sensitive implementation detail. It does not validate every hardware assumption, predict the arrival of a cryptographically relevant machine or supply a universal “Q-Day.”

The revision carries its own warning

The April 15 revision acknowledges that Keegan Ryan of Trail of Bits found a software flaw that allowed an attack on the soundness of the earlier proof. Version 2 corrects the proof layer and credits the finding. That repair belongs at the center of the story: cryptographic attestation can narrow a disclosure problem, while its software and statement still require hostile review. The case links cryptography, scientific reproducibility, market confidence and public oversight without treating the current proof as wider than it is.

Read More