Recently, Google's Quantum AI team announced that a future quantum computer could potentially derive a bitcoin private key from a public key in approximately nine minutes. This revelation has sparked widespread concern and raised questions about the security of the bitcoin network.
To understand the implications, it's essential to grasp how bitcoin transactions work. When a bitcoin transaction is made, the sender's wallet uses a private key to sign the transaction, which is then broadcast to the network and verified by miners.
The private and public keys are linked through a complex mathematical problem known as the elliptic curve discrete logarithm problem. While classical computers are unable to reverse this math in a practical timeframe, a sufficiently powerful quantum computer could potentially do so using an algorithm called Shor's. The recent study found that a quantum computer could be 'primed' in advance by pre-computing parts of the attack that don't depend on a specific public key. Once a public key appears in the mempool, the quantum computer would only need around nine minutes to derive the private key.
This gives the attacker a roughly 41% chance of stealing the funds before the original transaction is confirmed. However, this type of attack, known as a mempool attack, requires a quantum computer that does not yet exist. A more pressing concern is the approximately 6.9 million bitcoin that are already vulnerable to quantum attacks due to exposed public keys.
This includes early bitcoin addresses and wallets that have reused addresses, making them susceptible to theft. The recent Taproot upgrade has inadvertently expanded the pool of vulnerable wallets.
While the bitcoin network itself would continue to function, the ability to derive private keys from public keys would undermine the ownership guarantees that make bitcoin valuable. The solution lies in post-quantum cryptography, which would replace the vulnerable math with algorithms that quantum computers cannot crack.