Skip to content
Sadiq Khan

june 24, 2026 · 2 min read · quantum, cryptography, verification, byzllm

When the verifier is cheaper than the generator

Google's hidden quantum optimisation, a public contest that grades circuits without revealing the answer, and why any verifiable problem is now on a clock.

Bitcoin's transaction confirmation window is 10 minutes. Google's optimised quantum attack on the signature takes 9. The US government wouldn't let them publish how.

So Google posted a zero-knowledge proof instead: math that says "we have it" without showing what "it" is. Craig Gidney, the world's top expert on Shor's algorithm, later admitted he'd been sitting on the same optimisation for a year under the same pressure.

A French researcher rediscovered the secret anyway. Two months. No insider access. Just arXiv and stubbornness. His name is André Schrottenloher, and the optimisation he derived drops the qubit count needed to crack Bitcoin's signatures by an order of magnitude.

But the part I keep thinking about is ecdsa.fail.

It's an open contest run by Eigen Labs. Anyone can submit a candidate Shor circuit. The clever bit is the scoring: Google's ZK verifier, originally built to hide the answer, does double duty as the submission filter. It grades your circuit without ever revealing Google's. No false positives. A reward signal that cannot be lied to.

The community is 8.4% past Google and climbing. Trail of Bits separately rebuilt the proof from scratch and squeezed roughly 49% off the operation count with a different technique. Three teams, three methods, same direction.

I've been chest-deep in a related corner of this for months. byzllm, my recent work, makes the same case for multi-agent LLM consensus that ecdsa.fail demonstrates for quantum circuits: when the verifier is cheaper and more reliable than the generator, the generator doesn't need to be smart. It just needs to be persistent.

The headline most people are writing: "AI is breaking quantum crypto faster than expected."

The headline they should be writing: any problem with a verifiable answer is now on a clock. Theorem proving. Protein folding. Compiler optimisation. Materials discovery. If you can score it, a feedback loop is going to beat the human record. The only open question is how soon.

Your bank's encryption isn't broken tonight. But Google's optimisation existed for a year before anyone outside Google knew. Schrottenloher took two months to rediscover it. The contest is shaving more off every week.

The question is no longer when we get the quantum computer. It's how long Google's next paper stays a secret.


Originally posted on LinkedIn.

← All writing

Contact

sadiqkhan795@gmail.com

Say hello. I read everything.