Zero-Knowledge Proof Failed to Hide Google's Quantum Result
Input
Modified
Google hid a quantum result behind a zero-knowledge proof Researchers reproduced and improved it within sixty-three days AI agents make concealing benchmarkable results unreliable

The algorithm announced by Google in March 2026 to undermine elliptic curve cryptography needs 1,175 logical qubits and over two million Toffoli gates, while estimates circulating until then spoke of at least twenty times more qubits. The record for logical qubits in a real quantum computer was in July 2026 just under a hundred, so the distance from practice remains large. The company judged, however, that the risk of misuse, or rapid further development of the circuit, justified its non-publication. In place of the circuit, a zero-knowledge proof came out, a mathematical certificate that the circuit exists, without the circuit itself. Within 63 days, cryptographer André Schrottenloher, of the Inria center in Rennes, published a circuit at a similar cost and with slightly fewer Toffoli gates than the original. The secret that was planned to remain closed lasted less than three months.
How a Zero-Knowledge Proof Was Meant to Protect Google's Quantum Result
The idea was born in the mid-1980s and allows anyone who holds a proof to convince a third party that the proof exists, without revealing anything about its content. The process is interactive, since the claimant and the verifier repeatedly exchange messages, and with each round the verifier's certainty increases, while the leaked information remains zero. The exchange is actually undertaken by algorithms. For decades, the technique functioned as the foundation of cryptography and authentication systems, not as a way to publish scientific papers. Google's March 2026 paper took it into this very field, claiming that a certain form of elliptic curve cryptography can be broken by a quantum algorithm with 1,175 logical qubits, and that the algorithm's data will not be published.
The compromise emerged, as Google researcher Craig Gidney himself describes in his personal blog, after reactions to the expediency of the publication. The rationale was that those who plan defense would get the information they need for their programming, while those who wanted to attack would get nothing usable. Gidney estimates that a cryptographically relevant quantum computer within the next few years is possible, with a probability above 10%, though he does not consider it likely, meaning above 50%, and adds that for anyone who works in security, such a percentage is enough to settle the decision. He also admits that it didn't take much persuasion to follow the path of proof, as he was also interested in the technique.
Why the Secret Lasted Only 63 Days
According to Gidney, secrets are similar to lies in that they are transmitted, because in order to keep one closed, a second must be kept closed. Quantum circuits for elliptic curves are composed of the same basic elements that other circuits use, i.e. adders, multipliers, and lookup tables, so any technique that improves one necessarily improves the other. The most expensive operation in quantum point addition is a multiplication, and the same team had published four months earlier work on the Decoded Quantum Interferometry algorithm, which described a method of saving space precisely in multiplications. It was enough to read the two papers together, and Schrottenloher, as Gidney writes, did it: by putting two and two together he arrived at a circuit with common basic ideas but a different construction.
The proof had already shown cracks six weeks earlier. A team led by computer scientist Keegan Ryan identified errors in the public verification code, which allowed the proof to accept invalid circuits as well, including one that stated that the encryption was broken without any Toffoli gate, which was obviously impossible. In mid-April 2026, the authors corrected the implementation and the original claim was confirmed, since the error was in the code and not in the result. The episode showed that a zero-knowledge proof is also software, with software flaws, and that the publication of the verification code alone calls for experts to examine it with the utmost care.

AI Agents Turned the Hidden Circuit into a Public Contest
Layr Labs now hosts a public contest on GitHub called secp256k1 Point-Addition Challenge, with the goal of finding the cheapest reversible quantum circuit for point addition on the secp256k1 curve, the same one that protects Bitcoin and Ethereum. The score is the product of the number of Toffoli gates multiplied by the maximum number of qubits, and each candidate circuit is automatically checked at 9,024 random points. The repository's reference table lists the two points presented by Google: the first with 2.7 million Toffoli gates and 1,175 qubits and the second with 2.1 million gates and 1,425 qubits. The zero-knowledge proof, in other words, had made the target numbers public, and a goal with a measurable score is the most convenient form of problem for an optimization loop.
AI agents entered this loop. The repository's README states that the team lowered the score about 33 times compared to the textbook baseline, a figure that is self-reported, and warns that memory files and source code may come from different agents, so they must be checked before each use. According to a published description, within three days an online community using agent systems improved markedly on the published result, nearly halving the Toffoli gates required. The repository's own table, however, still lists its best circuit above both of Google's points. The lesson extends beyond speed. A problem formulated by numerical criteria and an automatic correctness check can be undertaken by non-stop seekers, and hiding the solution does not prevent anyone when the description of the problem and the desired result are known.

The Streisand Effect and the Cost to the Whole Research Sector
Gidney lists three structural problems of the method, and the first is the Streisand effect: the statement that someone has a solution but will not share it attracts attention more effectively than any publication. Quantum computing is a small discipline compared to computing as a whole, and in his estimation, which is an estimation rather than a measurement, this attention can easily multiply the number of people dealing with the problem by two orders of magnitude. A public point-addition challenge exists as a direct consequence of the work, according to Gidney. The second problem is that the mere knowledge that a solution exists is often enough to solve the problem, as in the case of George Dantzig, who solved two unsolved statistical problems because he passed them for exercises. The third problem is rubber-hose cryptanalysis, meaning physical coercion: a zero-knowledge proof does not reveal the solution, but it does reveal who knows it.
There is a counterargument, and it carries weight: the two months that the defense won is two months more than anyone. The argument does not stand up to the data, however. A 63-day period, at the cost of the public image of a method and a series of corrections to the verification code, leaves the defense essentially where it was, since the transition to new cryptographic systems belongs to governments and infrastructure agencies and is not completed in weeks. Gidney concluded that the benefits are negligible and the costs many, and that research should be published openly. For an industry looking for a way to manage outcomes that are both knowledge and capability, Google's experiment left a published precedent of failure, which will be mentioned whenever another team thinks of something similar.
Implications for Labs, Publishers and Security Teams
For research labs, the practical consequence is that the published cost of an attack should be perceived as a security ceiling that will fall, not as a fixed size, since a public scoring criterion and an automatic check are enough for agents to push it. If an outcome is to remain limited, the realistic path is coordinated disclosure to manufacturers, standards bodies and platform administrators, with an explicit timeline, rather than a public announcement inviting competition. Security teams that protect assets on the secp256k1 curve, i.e. the Bitcoin and Ethereum networks, cannot claim to be unaware of how quickly the circuits are improving.
Conference program committees, journal publishers and preprint server operators need a procedure for dual-use results prior to publication, because post-publication concealment now has a recorded history of failure. The same stakes apply to funders, who could require a risk assessment already at the research proposal stage. This need is not limited to cryptography, as any field where the result is described with a measurable goal will face the same seekers. The point is not to waive all restrictions, since Gidney himself recommends open publication for this case, but to determine the point where open publication begins to benefit the attacker more than the defender. This point remains unclear.
Schrottenloher's circuit is currently public and has slightly fewer Toffoli gates than Google's circuit, while the 1,175 logical qubits required by the attack are still more than eleven times the record of just under a hundred logical qubits recorded in July 2026. This distance is a protection that does not depend on any secret, and whether it is valid for many more years is the question to which the publication of the proof did not provide an answer.
This article reflects the analytical judgment of The SIAI Editorial Board and does not constitute policy advice or the official position of any affiliated institution.
References
Babbush, R., Zalcman, A., Gidney, C., Broughton, M., Khattar, T., Neven, H., Bergamaschi, T., Drake, J. and Boneh, D. (2026) ‘Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities: Resource Estimates and Mitigations’, arXiv, 2603.28846. Google Research
Bischoff, M. (2026) ‘Why mathematicians are hiding research results in zero-knowledge proofs’, Scientific American.
Gidney, Craig (2026) 'The French have the Quantum Circuits', Algorithmic Assertions, 1 June.
Layr Labs (2026) ‘The secp256k1 Point-Addition Challenge’, GitHub.
Ransford, A. et al. (2026) ‘A 98-qubit trapped-ion quantum computer with all-to-all connectivity’, Nature, 655, pp. 81–86. Nature
Ryan, K. (2026) ‘We beat Google’s zero-knowledge proof of quantum cryptanalysis’, Trail of Bits Blog. The Trail of Bits Blog
Schrottenloher, A. (2026) ‘Optimized Point Addition Circuits for Elliptic Curve Discrete Logarithms’, arXiv, 2606.02235.