Elliptic Curve Cryptography Explained for Crypto Users
The basic idea
Your wallet has a private key, a secret number, and a public key derived from it. The math is easy in one direction and believed to be extremely hard in reverse. Anyone can see the public key, but should not be able to work out the private key. See what is a crypto wallet.
Where blockchains use it
- Bitcoin: signs transactions using the secp256k1 curve, with ECDSA and, more recently, Schnorr signatures.
- Solana: signs transactions using Ed25519, another elliptic curve scheme. See what is Solana.
- Ethereum: also uses secp256k1 for account signatures.
Why ECC is popular
It gives strong security with small keys and fast signing, which suits blockchains where every byte costs space. Compared with RSA, ECC needs much shorter keys for similar classical security.
The quantum problem
The hard problem behind ECC is called the discrete logarithm problem on a curve. A variant of Shor's algorithm can solve it on a large enough error corrected quantum computer. Such a machine does not exist today, and experts expect it to need many high quality qubits.
What it means for holders
The risk is mainly for keys whose public key is exposed on chain. Researchers and developers are discussing migration paths, including quantum resistant signatures. Read will quantum computers break Bitcoin and Solana for context. QUANTUM (QNT) is a memecoin that uses the same underlying Solana signatures.
A small worked example
On an elliptic curve you can add points to get new points. Take a starting point G and add it to itself k times to reach a point K. Computing K from k is fast. Finding k from G and K is the discrete logarithm problem on the curve, and nobody knows a fast classical way for well chosen curves. Your private key is k and your public key is K. Shor's algorithm has a variant that finds k efficiently on a large enough quantum computer.
What the newest estimates say
In March 2026 a team from Google Quantum AI with collaborators from Berkeley, the Ethereum Foundation and Stanford posted a paper on the 256-bit curve secp256k1 used by Bitcoin and Ethereum. They report that Shor's algorithm could run with at most 1,200 logical qubits and 90 million Toffoli gates, or 1,450 logical qubits and 70 million Toffoli gates. On superconducting hardware with a 0.1 percent physical error rate they estimate it could take minutes with fewer than half a million physical qubits. They also released a zero knowledge proof so others can check the claim without the circuit details. This is an estimate and no such machine exists. Google's Willow chip has 105 qubits. See the estimates guide and logical vs physical qubits.
Comparison
| Chain | Curve | Signature |
|---|---|---|
| Bitcoin | secp256k1 | ECDSA, Schnorr |
| Ethereum | secp256k1 | ECDSA |
| Solana | Curve25519 (Ed25519) | EdDSA |
What is changing in 2026
Bitcoin proposal BIP-360 (Pay-to-Merkle-Root) was merged into the BIP repository in February 2026 as a draft, which is not an activation. Solana has an optional Winternitz Vault, published in January 2025, which only protects people who choose it. See BIP-360 and BIP-361 and Ethereum and Solana plans.
Common mistakes
- Thinking an address hides everything. Many address types hide the public key until you spend, but not all, and reused addresses expose it.
- Moving funds in a panic. Be careful with scam sites claiming to be quantum safe wallets.
- Mixing signatures and hashing. Hashes are much less affected. See hashes and quantum computers.
How to check this yourself
Read the project's own improvement proposal, not only news. Nothing here is financial advice.
Sources and further reading
- Google Quantum AI and collaborators 2026: Securing elliptic curve cryptocurrencies against quantum vulnerabilities (IACR ePrint 2026/625)
- The Quantum Insider: Solana Winternitz Vault, January 2025
- Cointelegraph: BIP-360, what it changes and what it does not
- Encryption Consulting: NIST IR 8547 plan (secondary summary of a draft)
Checked 2026-10-09. Research and standards change often, so check the primary documents. Nothing here is financial advice. The QNT memecoin is independent of Quantinuum Ltd, the real company, and of every lab, company and standards body named on this page.
Frequently asked questions
What curve does Solana use?
Solana uses Ed25519, an elliptic curve signature scheme.
What curve does Bitcoin use?
Bitcoin uses the secp256k1 curve for its signatures.
Is ECC safer than RSA?
Against normal computers it is efficient with small keys. Against a large quantum computer, both are vulnerable to Shor-type attacks.
Can quantum computers steal my crypto today?
No. No existing quantum computer can break elliptic curve keys.
What is a discrete logarithm?
It is the problem of finding how many times a starting point was added to itself to get a given point.
What is an on-spend attack?
It is a scenario in which a very fast quantum computer derives a private key from a public key revealed in a pending transaction, before the transaction is confirmed. The 2026 Google paper discusses it for fast clock machines.
Are Solana wallets quantum safe?
Not by default. An optional Winternitz Vault exists, and broader plans are being discussed. See the plans guide.
Is ECC being phased out by standards bodies?
NIST's draft transition report proposes deprecating it after 2030 and disallowing it after 2035. This is a draft as reported by secondary sources.
Keep reading
- What Is RSA and Why Can Quantum Computers Break It?
RSA encryption relies on the difficulty of factoring big numbers. Learn how RSA works in plain English and why a large quantum computer could break it. - Quantum-Resistant Signatures Explained
What are quantum-resistant digital signatures? Learn the main families, the NIST standards and the trade-offs blockchains face when upgrading. - Will Quantum Computers Break Bitcoin and Solana?
A calm, factual look at the quantum threat to Bitcoin, Solana and other blockchains, what is safe now, and what could change. - What Is a Crypto Wallet? Hot Wallets, Cold Wallets and Recovery Phrases
A crypto wallet holds your keys, not your coins. Learn the difference between hot and cold wallets and how to keep yours safe.
All Quantum computing guides | Back to top | Search the site
Main pages: Quantum computing explained | Quantum and crypto | Companies | Quantum news | Glossary