According to Google's Quantum AI team, a future quantum computer could potentially derive a bitcoin private key from a public key in roughly nine minutes. This has sparked widespread concern and raised questions about the security of the bitcoin network. To understand the implications, it's essential to grasp how bitcoin transactions work. When a bitcoin transaction is made, the sender's wallet uses a private key to sign the transaction, which is then verified by the network.
The private key is linked to a public key, which is shared publicly and can be used to receive bitcoin. However, if a quantum computer were to pre-compute the necessary components of an attack, it could potentially derive the private key from the public key in about nine minutes. This timeframe is significant because it's shorter than the average time it takes for a bitcoin transaction to be confirmed, which is around 10 minutes. As a result, an attacker with a sufficiently powerful quantum computer could potentially redirect funds before the original transaction is confirmed.
This type of attack is known as a 'mempool attack.' Although this is a concern, it's worth noting that such a quantum computer does not yet exist. Google's study estimates that it would require fewer than 500,000 physical qubits, whereas current quantum processors have around 1,000. A more pressing concern is the 6.9 million bitcoin that are already vulnerable to a quantum attack due to exposed public keys. This includes early bitcoin addresses that used a format called pay-to-public-key, as well as wallets that have reused addresses, making their public keys visible on the blockchain.
These coins are at risk of being cracked by a sufficiently powerful quantum computer without any time pressure. The bitcoin network itself would continue to function, but the security guarantees that make bitcoin valuable would be compromised if private keys can be derived from public keys.
The solution to this problem is to implement post-quantum cryptography, which would replace the vulnerable math with algorithms that quantum computers cannot crack. While Ethereum has been working towards this migration for eight years, bitcoin has yet to start.