The emergence of quantum computers poses a significant threat to Bitcoin's security, with the potential to compromise the blockchain's core cryptography. According to recent research by Google, a sufficiently powerful quantum computer could crack Bitcoin's encryption in under nine minutes, which is faster than the average time it takes to settle a Bitcoin block.

This has sparked concerns among developers, who are now considering various proposals to mitigate this threat and ensure the long-term security of the Bitcoin network. Approximately 6.5 million bitcoin tokens, valued at hundreds of billions of dollars, are currently at risk of being targeted by a quantum computer. These coins are stored in addresses that are vulnerable to quantum attacks, including those belonging to Bitcoin's pseudonymous creator, Satoshi Nakamoto.

The potential compromise of these coins would not only result in significant financial losses but also undermine the fundamental principles of Bitcoin, including 'trust the code' and 'sound money.' To address this challenge, developers are exploring two primary methods by which a quantum machine could attack Bitcoin. The first method involves a long-exposure attack, where a quantum computer can derive a private key from a public key that is exposed on the blockchain.

This type of attack is particularly concerning for coins stored in older addresses, such as pay-to-public key (P2PK) addresses, which are used by Satoshi and early miners. The second method involves a short-exposure attack, where a quantum computer can access a public key and signature that are visible in the mempool, which is the waiting room for unconfirmed transactions.

Several proposals are currently being considered to mitigate the quantum threat. One such proposal, known as BIP 360, involves removing the public key from the blockchain and replacing it with a new output type called Pay-to-Merkle-Root (P2MR).

This would prevent a quantum computer from deriving a private key from a public key, thereby reducing the risk of a quantum attack. Another proposal, known as SPHINCS+ or SLH-DSA, involves using hash-based post-quantum signatures, which are not vulnerable to quantum attacks.

However, this proposal has the drawback of increasing the size of bitcoin signatures, which could lead to higher transaction fees. Other proposals, such as Tadge Dryja's Commit/reveal scheme and Hourglass V2, aim to protect transactions in the mempool and slow the spending of old coins, respectively.

While these proposals are still in the development stage, they demonstrate the proactive approach being taken by Bitcoin developers to address the quantum threat and ensure the long-term security of the network.