The emergence of quantum computers poses a significant threat to Bitcoin's security, with the potential to compromise the blockchain's core cryptography. Although quantum computers capable of breaking Bitcoin's encryption do not yet exist, developers are proactively considering upgrades to mitigate this risk. Recent research by Google suggests that a sufficiently powerful quantum computer could crack Bitcoin's core cryptography in under nine minutes, which is faster than the average time it takes for a Bitcoin block to be settled. This has prompted concerns that such a threat could become a reality by 2029.
Approximately 6.5 million bitcoin tokens, valued at hundreds of billions of dollars, are vulnerable to quantum attacks, including coins belonging to Bitcoin's pseudonymous creator, Satoshi Nakamoto. The potential compromise of these coins would not only result in significant financial losses but also undermine Bitcoin's core principles of trust and sound money. To address this threat, several initiatives are being considered.
One key vulnerability is the exposure of public keys, which can be used by quantum computers to derive private keys and steal coins. There are two primary ways a quantum machine could attack Bitcoin: through long-exposure attacks, which target coins sitting idle on the blockchain, and short-exposure attacks, which target coins in transit or waiting in the memory pool.
To mitigate these risks, proposals such as BIP 360, which removes public keys from the blockchain, and SPHINCS+/SLH-DSA, a post-quantum signature scheme, are being explored. Additionally, Tadge Dryja's commit/reveal scheme and Hourglass V2, which aims to slow the spending of old coins, are being considered as interim measures to protect against quantum attacks. While these proposals are still in the development stage, they demonstrate the proactive efforts of Bitcoin developers to address the quantum computing threat and ensure the long-term security of the blockchain.