A team of researchers from Google's Quantum AI division has made a groundbreaking discovery, claiming that a future quantum computer could potentially crack a bitcoin private key in under nine minutes. This revelation has sent shockwaves throughout the cryptocurrency community, prompting concerns about the security of the bitcoin network.

But what exactly does this mean, and how does it impact the average user? To understand the implications, it's essential to delve into the inner workings of bitcoin transactions. When a user sends bitcoin, their wallet uses a private key to sign the transaction, which is then broadcast to the network and verified by miners. The private key is linked to a public key, which is shared with the network, through a complex mathematical equation known as the elliptic curve discrete logarithm problem.

Classical computers are incapable of reversing this equation in a timely manner; however, a sufficiently powerful quantum computer could potentially crack the code using an algorithm called Shor's. The recent breakthrough by Google's team has shown that a quantum computer can be 'primed' in advance by pre-computing parts of the attack, allowing it to derive a private key from a public key in approximately nine minutes once the public key appears in the mempool.

This gives the attacker a roughly 41% chance of stealing the funds before the original transaction is confirmed. To put this into perspective, consider a thief building a universal safe-cracking machine that can be used to crack any safe. While the machine takes hours to build, it only needs a few final adjustments to crack a specific safe, which takes around nine minutes.

Although this 'mempool attack' is alarming, it requires a quantum computer that does not yet exist. Google's paper estimates that such a machine would need fewer than 500,000 physical qubits, whereas current quantum processors have around 1,000. A more pressing concern is the 6.9 million bitcoin, approximately one-third of the total supply, that are already vulnerable to quantum attacks due to exposed public keys.

This includes early bitcoin addresses that used a format called pay-to-public-key, as well as wallets that have reused addresses, making their public keys visible on the blockchain. These coins can be cracked at leisure by an attacker with a sufficiently powerful quantum computer, without any time pressure. The 2021 Taproot upgrade has inadvertently expanded the pool of vulnerable wallets, making the situation even more critical.

While the bitcoin network itself would continue to function, as mining uses a different algorithm that is resistant to quantum attacks, the ability to derive private keys from public keys would undermine the security guarantees that make bitcoin valuable. The solution to this problem lies in post-quantum cryptography, which involves replacing the vulnerable math with algorithms that are resistant to quantum attacks. Ethereum has been working towards this migration for eight years, while bitcoin has yet to start.