Venture Eleven’s 1 BTC Q-Day Prize was meant to sharpen the controversy over quantum threat to Bitcoin and different ECC-secured crypto belongings. As an alternative, a pointy critique from Google quantum researcher Craig Gidney has turned the competitors itself into the story.
In an April 25 weblog publish titled “The predictable failure of the QDay Prize,” Gidney, a analysis scientist on Google’s quantum computing group, argued that the profitable submission didn’t meaningfully show progress towards a cryptographically related quantum assault. His central declare was blunt: the competition was structured round a benchmark that present quantum computer systems are poorly suited to measure.
Bitcoin’s Quantum Risk Debate Explodes
Venture Eleven had introduced the day past that it awarded the Q-Day Prize to Giancarlo Lelli for breaking a 15-bit elliptic curve key on publicly accessible quantum {hardware}. The group described the end result because the “largest quantum assault on elliptic curve cryptography so far” and stated it represented a 512x leap from a previous 6-bit public demonstration.
For crypto markets, the framing mattered. Venture Eleven explicitly linked the end result to the long-term safety assumptions behind Bitcoin, Ethereum, and greater than $2.5 trillion in ECC-secured digital belongings.
However Gidney argued that the take a look at might have proved far lower than marketed. Gidney stated he was invited final yr to take part within the Q-Day Prize however declined as a result of he considered the premise as flawed. His first objection was that Shor’s algorithm requires quantum error correction for cryptographically significant situations.
“Present quantum computer systems expertise on the order of 1 error per thousand gates, however cryptographically related situations of Shor’s algorithm require billions of gates,” he wrote. “The one recognized technique to cross this chasm is quantum error correction. There are promising quantum error correction experiments being completed, however in the end quantum error correction remains to be a piece in progress.”
That distinction sits on the middle of the dispute. In Gidney’s view, operating small non-error-corrected circuits doesn’t present a helpful proxy for breaking real-world ECC keys, as a result of the scaling conduct is basically totally different from the programs that might be wanted to threaten Bitcoin-scale cryptography.
His second objection was extra damaging for the prize end result. Gidney argued that small Shor-style issues can seem to succeed even when the quantum {hardware} is just not contributing significant computational worth.
The difficulty, he stated, resembles a joke paper he printed for SIGBOVIK 2025, the place he claimed to issue all numbers as much as 255 utilizing a quantum laptop, solely to indicate that the identical success might be reproduced with randomness. He referred to as this the “Falling With Model” downside.
“For the close to future, the contribution of luck goes to massively outweigh any professional contribution of the quantum laptop,” Gidney wrote, quoting the warning he stated he gave when declining to take part. “So I believe the winner in 2026 can be whoever did the most effective job at obfuscating how they made themselves unavoidably fortunate. You’re going to seek out your self in a philosophical debate, with 100K$ on the road, over the place precisely the road for a quantum laptop ‘actually’ breaking a key’s.”
In keeping with Gidney, that’s successfully what occurred.
He pointed to work by GitHub consumer Yuval Adam, who reportedly changed the quantum calls within the profitable submission with random calls and located that the outcomes have been “indistinguishable” from the quantum model. Gidney stated the circuit building itself seemed legitimate, together with its implementation of the ELDPC circuit from Roetteler et al. 2017, however that this made the issue extra refined quite than much less severe.
“You make an accurate circuit, you get the anticipated end result, you rejoice… however you bought the correct reply for the fallacious purpose,” he wrote. “It is a worry that each competent experimentalist is aware of of their bones. It’s why they don’t simply verify that one thing works when it ought to work, they verify that it breaks when it ought to break.”
Venture Eleven Defends The Broader Intention
Venture Eleven framed the profitable end result as a sensible demonstration of the assault class that might finally threaten Bitcoin and Ethereum. In an response, CEO Alex Pruden stated the submission confirmed that “the useful resource necessities for this sort of assault preserve dropping” and that the barrier to operating such experiments was falling as a result of the work used cloud-accessible public {hardware} quite than non-public or national-lab programs.
The group additionally cited current theoretical useful resource estimates, together with Google’s April 2026 estimate of beneath 500,000 bodily qubits for a full 256-bit assault and a later Caltech and Oratomic paper that put the determine as little as 10,000 qubits in a neutral-atom structure. Venture Eleven argued that whereas the gap from 15 bits to 256 bits stays massive, the hole is more and more an engineering downside quite than a basic physics downside.
Pruden later acknowledged Gidney’s critique on X, writing that “small factoring issues are a really imperfect yardstick for Q-Day.” Nonetheless, he defended the aim of the competitors as an try and bridge a niche between quantum researchers who see fast acceleration and cryptographers or Bitcoin builders who need stronger proof earlier than treating present programs as near-term susceptible.
“So, since small factoring issues aren’t an excellent yardstick for Q-Day, then what’s?” Pruden wrote. “I’ll fortunately take suggestions on how we will higher incentivize open benchmarking in direction of Q-Day threat.”
A Credibility Downside For Quantum Danger Messaging
Gidney didn’t dismiss quantum threat to crypto outright. In truth, he wrote that there are “professional considerations” quantum computer systems may grow to be cryptographically related earlier than the top of the last decade, pointing to post-quantum migration efforts at corporations equivalent to Google and Cloudflare.
His argument was narrower, however consequential: a weak benchmark can undermine the case it’s attempting to make. If a contest designed to boost consciousness produces a end result that critics can reproduce with randomness, it dangers turning into ammunition for skeptics quite than a warning sign for the business.
At press time, BTC traded at $77,750.

Featured picture created with DALL.E, chart from TradingView.com
Editorial Course of for bitcoinist is centered on delivering completely researched, correct, and unbiased content material. We uphold strict sourcing requirements, and every web page undergoes diligent overview by our group of high expertise specialists and seasoned editors. This course of ensures the integrity, relevance, and worth of our content material for our readers.
