Today a crazy quantum story just got wilder.
On March 31, the Google Quantum AI team published a landmark result on Shor's algorithm for elliptic curve cryptography. Technically, the paper was a bombshell: a dramatic 10x improvement over the state-of-the-art. As a stunt and wakeup call to the blockchain space, those optimisations were illustrated on secp256k1, the elliptic curve underlying Bitcoin and Ethereum signatures.
But perhaps the most striking part of the paper was sociological, not technical. Instead of following standard academic process, the optimisations were kept secret, hidden behind a zero-knowledge (ZK) proof. Google's accompanying blog post mentions they "engaged with the U.S. government". The ZK proof demonstrates the existence of algorithmic improvements without leaking details. Academic censorship with ZK, a historic first!
As a co-author of the Google paper I witnessed some of the context surrounding this censorship. To be honest, multiple aspects of that context don't sit well with me. As much as I believe the general public ought to know more, I am limited in my ability to whistleblow. Though let me be clear about one thing: the Google team's professionalism has been absolutely exemplary, and they deserve nothing but praise.
Censorship has a way of backfiring. The Streisand effect, where an attempt to bury something only draws more attention to it, is exactly what's unfolding today. First, Google's key optimisation has been rediscovered by the French. And in a thrilling turn of events, a collaborative Shor-at-home challenge just launched. The initiative, available at ecdsa[.]fail, breached a new Shor world record in a matter of hours.
Let's start with the rediscovery. Just two months after Google's paper, French quantum expert André Schrottenloher cracks the main secret optimisation. His paper, titled "Optimized Point Addition Circuits for Elliptic Curve Discrete Logarithms", landed on the arXiv today. Big congrats to André, who beat several other nerdsnipped experts to it. In a blog post also published today, Craig Gidney, the world expert on Shor optimisations, revealed that he'd been sitting on this very optimisation for a whole year under censorship pressure.
Interestingly, André missed a handful of minor optimisations, both from Google's original publication and from improvements found since. It's plausible there's still plenty of juice left to squeeze out of Shor, and this is exactly what the ecdsa[.]fail challenge is about. The verifier program developed for the ZK proof does double duty, automatically filtering for valid submissions. Dozens of compounding small and micro improvements are rolling in. As of the time of writing there's an 8.4% improvement to Google's circuit, as measured by the product of logical qubit count and Toffoli gate count. Nice!
The nerdsnipping ran deeper than anyone expected. Over the last few weeks it became clear it extended well beyond André and other quantum experts. Behind the scenes, a small army of amateurs quietly got to work. Inspired by Karpathy-style autoresearch, they turned AI on Shor. Ironically, the verifier program for the ZK proof makes an ideal reward function for AIs. The barrier to entry for this modern style of research is refreshingly low, with several non-experts, even a teenager, finding nice optimisations. Get in touch if you'd like to join a Telegram group with fellow autoresearchers :)
Part 2: neutral atoms and qday
The story doesn't end with Google. On the same day Google went public, a stealthy startup called Oratomic published its own Shor paper in a coordinated release. It made a splash, ultimately becoming the most upvoted paper on scirate[.]com, a website ranking arXiv papers.
Oratomic's claim was wild. By building on Google's logical optimisations and applying custom physical optimisations for neutral atoms, they claimed just 10K physical qubits were sufficient to run Shor's algorithm on secp256k1. That number is mind-bogglingly low.
Knowing essentially nothing about neutral atoms when Oratomic's paper landed, I was intrigued and decided to learn more about the tech. I fell straight down the rabbit hole and spent a couple hundred hours on the topic. I got a little obsessed and watched every YouTube video I could find and spoke to a bunch of experts.
My conclusion? The tech is real, very real. Even Google recently decided to start a neutral atom lab, a notable pivot from their sole focus on superconducting qubits. If you care about qday, i.e. the day a quantum computer will break the first piece of cryptography in production, neutral atoms demand your attention. I shared some of my learnings on Shor and neutral atoms in a 30min talk at the ZKProof cryptography conference. You can find it on YouTube by searching "zkproof neutral atom".
Here's an interesting observation about this duo of breakthrough papers: neither Google nor Oratomic say a word about what their results mean for qday. No timelines. Zero. Nada. That is especially baffling given that the whole point of whitehat quantum cryptanalysis is to inform qday estimations and help the general public make good decisions.
So let me attempt to partially fill the silence, similarly to what Scott Aaronson did in his April 29 post. Given everything I know, including scary non-public information, I now put the odds of qday by 2032 at 50%. 10% by 2030.
Anecdotally, the US government has its own date: 2035. Originating at the NSA and later adopted by NIST, it's when branches of the US government will be disallowed from using quantum-vulnerable cryptography. In plain language: with hindsight, that date is a joke and should be discounted entirely. I don't see how NIST avoids being forced to pull it forward by years.
Part 3: post-quantum cryptography
There are good reasons to sound the alarm today, but please do not panic. Rushing carelessly towards immature post-quantum cryptography is a recipe for disaster. IMO a good target date for migration is 2029, roughly 3.5 years out. 2029 happens to be the date selected by Google, Cloudflare, and the Ethereum Foundation.
These days most of my time goes to safely migrating Ethereum towards post-quantum cryptography as part of the broader lean Ethereum effort. There's a lot to do. We need to rip out and replace BLS signatures at the consensus layer, KZG commitments at the data layer, and ECDSA signatures at the execution layer.
The plan to get there is compelling, and is based on hash-based cryptography. Within the Ethereum Foundation we've developed a Swiss army knife called leanVM (github[.]com/leanEthereum/leanVM) powered by the magic of hash-based SNARKs. Thanks to truly exceptional work by Emile, Thomas, and others, its performance is derisked. Regarding security, leanVM is a jewel, a minimal zkVM crafted for end-to-end formal verification and maximum security.
Want to help? There are two $1M initiatives. First, the Proximity Prize (proximityprize[.]org). Solve a long-standing mathematical conjecture in coding theory, improve hash-based SNARKs, and go home a millionaire. Second, the Poseidon Initiative (poseidon-initiative[.]info), offers $1M for breaking Poseidon, the SNARK-friendly hash function.
Show more
many have highlighted several valid reasons why Robinhood chain will succeed
for example:
• Robinhood's massive brand advantage, a $100B+ company with tens of millions of users
• the sheer number of vested interests that want to see it succeed, from Uniswap and Arbitrum to wealthy ETH OGs and the broader Ethereum ecosystem, all of whom finally have a chance to put Ethereum back in the spotlight
but i think one of the most underrated reasons is
@vladtenev and his team
many assume Vlad simply got lucky building the biggest and most influential retail trading platform in history as some kid from Bulgaria
everything he's done with Robinhood chain so far suggests otherwise
he has shown himself to be incredibly strategic, with every move feeling deliberate and carefully calculated
you can see it in the announcements the team makes, the projects he engages with, and both his personal and corporate communication
as someone who's been in this space for multiple cycles, i genuinely can't think of another blockchain founder who's played things this well
for example:
• Ethereum's biggest breakout came after CryptoKitties, DeFi Summer, and ultimately the memecoin boom led by $SHIB, yet Vitalik has repeatedly come across as tone deaf toward memecoins and has openly dismissed the community
• Solana only truly exploded once memecoin traders embraced the chain, yet its founders and official accounts have repeatedly alienated the very community that helped drive its growth
• i don't even need to get into Base's recent fiasco and years of similarly tone deaf messaging
too many founders treat memecoins as slop or a plague on their ecosystem
when in reality, it's a $25B sector that has proven to be one of crypto's most durable sources of attention and activity
what is Vlad doing?
he's leaning hard into memecoins and even went as far as shouting them out and saying he likes them on Robinhood's recent earnings call
the irony is that memecoins have consistently been the biggest catalyst for getting new chains noticed
people pay attention when a chain is hot
and the fastest way to make a chain hot is to have an army of retail users trading, posting, and generating excitement around it
that drives transactions, wallets, onchain activity, early TVL, and liquidity
developers notice that momentum and start building
and the fastest way to create that momentum is through memecoins
Vlad seems to understand this better than almost anyone
you can see it in how he communicates, who he interacts with, and how Robinhood chain engages with the community
i think that's one of Robinhood chain's biggest and most underrated advantages
and one of the reasons i believe it'll dominate this cycle
Show more
LINK is back under $8, right where it traded in the 2022-2023 bear market, when Terra and FTX were blowing up.
back then
@chainlink was basically just a price feed for DeFi apps. today SWIFT, DTCC, UBS, JPMorgan and Mastercard all use it. its cross-chain protocol CCIP is now the default way to move tokenized assets between chains.
after a LayerZero exploit this year, over $4 billion moved off rivals and onto it. the network has powered over $27 trillion in transactions and runs most of DeFi.
the business won, and the token is priced like it's still 2022.
they even built a machine to fix this. the Chainlink Reserve takes the real money from those big deals and buys ethereum:0x514910771af9ca656af840dff83e8264ecf986ca with it. sounds like a company buying back its own stock.
since August it has turned about $49.5M of revenue into roughly 4.5 million LINK. that's about 0.6% of the supply, locked away for years. staking pays holders about 4.75% a year, and that's paid in new LINK. the real revenue from the big deals goes into the Reserve and stays locked.
all that institutional money flows to one place, and it walks right past LINK holders.
every deal with SWIFT and JPMorgan makes Chainlink Labs more valuable, the private company that holds the revenue, the contracts and the actual ownership. the LINK army handed this thing its brand, its liquidity and years of free marketing, and got a utility token back. scraps.
the exit that matters belongs to the company, and the whispers about a Chainlink Labs IPO keep getting louder.
and it's more than talk. people already trade shares of Chainlink Labs on private markets like EquityZen and Forge, before any public listing exists. the day it lists is the day the real money and deep liquidity show up, plus the status of a public company, and all of it lands on the equity. LINK holders are left with a completely different asset.
no crypto company this big, with a token held by this many people, has ever gone public and then bought its own token back to reward holders.
so which way does it go?
does Chainlink do what no crypto company has done, buy the token back when it goes public, and reward the people who held LINK for years? or do the shares go public, LINK stays a utility coin, and everyone who held through a 2022 price becomes exit liquidity for a company that never owed them a share?
Show more