Recently, Google's Quantum AI team announced that a future quantum computer could potentially derive a bitcoin private key from a public key in approximately nine minutes. This revelation sparked concern across social media and financial markets, but what does it actually mean in practical terms? To understand the implications, it's essential to grasp how bitcoin transactions work.
When a bitcoin transaction is made, the wallet uses a private key to sign the transaction, which is then linked to a public key. This public key is shared publicly and is used to verify the transaction.
However, if a quantum computer were to become powerful enough, it could potentially use this public key to derive the private key, allowing it to access the associated funds. The 'nine minutes' figure refers to the time it would take for a quantum computer to complete this process after being 'primed' with pre-computed information. This means that if a user's public key is exposed, a quantum computer could potentially derive their private key and redirect their funds before the original transaction is confirmed.
Although this is a significant concern, it's essential to note that such a powerful quantum computer does not yet exist. A more pressing issue is the 6.9 million bitcoin that are already at risk due to exposed public keys. This includes early bitcoin addresses and wallets that have reused addresses, making them vulnerable to quantum attacks.
The recent Taproot upgrade has inadvertently increased the number of wallets at risk. To mitigate this threat, the implementation of post-quantum cryptography is necessary. This would involve replacing the current encryption algorithms with ones that are resistant to quantum computer attacks. While Ethereum has been working towards this goal, bitcoin has yet to start this process.