The notion that quantum computing poses an imminent threat to bitcoin's security has been a topic of discussion in recent times. However, a more nuanced analysis of the situation reveals that the actual risk is more complex and multifaceted. Bitcoin's security relies on two distinct types of mathematics, and quantum computers pose a threat to them in different ways. One type, known as Shor's algorithm, targets the security of wallets, while the other, known as Grover's algorithm, applies to the mining process.
The two threats are often conflated in headlines, but they have distinct implications when real-world constraints are taken into account. Two recent research papers highlight the challenges of launching a quantum attack on bitcoin. The first paper examines the feasibility of using Grover's algorithm to outmine bitcoin, while the second paper replicates major quantum factoring breakthroughs using a 1981 home computer and a dog, demonstrating that many claimed breakthroughs are overstated. The research suggests that the energy required to launch a quantum attack on bitcoin is equivalent to that of a small star, making it physically unattainable.
Furthermore, the papers argue that many quantum factoring records are exaggerated, with researchers often using simplified problems or cheating by picking easy-to-guess numbers. The real vulnerability lies in bitcoin wallets, not mining, with millions of bitcoins stored in older or reused addresses that are more susceptible to quantum attacks. While the threat is real, it is essential to recognize that building machines capable of launching such attacks is currently physically impossible and requires significant engineering advancements.
Developers are already working on solutions to mitigate the risk, including reducing key exposure and developing new types of signatures that can withstand quantum attacks.