The rise of quantum computing has sparked intense discussion, particularly after Google suggested that a powerful enough machine could compromise legacy blockchains with less effort than previously thought. For holders of XRP, the answer to the quantum threat is nuanced. Experts argue that XRP's architecture offers more protection against quantum attacks than Bitcoin's. XRP operates on the XRP Ledger, an open-source and decentralized blockchain, which is utilized by Ripple for facilitating cross-border transactions.
Let's examine the details step by step. The primary concern with quantum computing is its potential to exploit the cryptographic foundations of blockchain technology.
Every major blockchain, including Bitcoin and XRP, relies on a private key for transaction signing and execution. This private key is used to derive a public key, which in turn generates a wallet address that can be shared to receive funds. The quantum vulnerability arises from the possibility of a powerful machine using Shor's algorithm to reverse-engineer a private key from an exposed public key, thereby allowing an attacker to drain funds from a wallet. Typically, a public key is exposed during transaction sending, and when receiving funds, only the wallet address is visible on the blockchain.
This means that account activity, such as sending transactions, increases quantum vulnerability, whereas the balance or the duration of holding an address does not. Recently, a quantum vulnerability audit of the XRP Ledger revealed that approximately 300,000 accounts holding 2.4 billion XRP have never sent funds, only receiving them.
As a result, these accounts have never exposed their public keys to the network, making them quantum-safe by default. However, there are dormant whale accounts that have transacted in the past, exposing their public keys, but have been inactive for at least five years. If a quantum computer were to be developed, these whales would be at risk.
The audit found two such accounts on the XRP Ledger, holding a combined total of 21 million XRP, which is only 0.03% of the circulating supply. It's worth noting that this vulnerability assumes these accounts are dormant and not utilizing the 'key rotation' feature of the XRP Ledger, which allows users to change their signing key without moving funds. This feature is available to all users but poses a problem for long-dormant accounts that may have lost access to their keys or are no longer active. Mayukha Vadari, a staff software engineer at Ripple, highlighted the 'escrow feature' as an additional defense mechanism against quantum risks.
According to Vadari, funds locked in escrow with a time lock are protected not by cryptography, but by logic, as the time lock prevents withdrawal until a specified time has passed. While the time lock safeguards the funds, the account that locked them can still carry quantum risks. In comparison, the quantum threat to Bitcoin appears more significant.
A substantial portion of early Bitcoin was mined using a format called P2PK, which directly exposed public keys in transaction outputs. This includes Satoshi Nakamoto's 1 million BTC, which has never been moved. Google estimates that about 6.9 million BTC are vulnerable, accounting for nearly 35% of Bitcoin's circulating supply, a much larger figure than XRP's 0.03%.
These vulnerable BTC are essentially sitting targets for potential quantum attackers. Furthermore, Bitcoin holders face a structural problem that XRP holders do not: the lack of a key rotation feature. To protect their funds, Bitcoin holders must move them to a new address with an unseen public key.
However, during the transfer process, the old address's public key is exposed for about 10 minutes, providing a window of opportunity for a sufficiently powerful quantum machine to exploit. Although this risk is still theoretical, it highlights the relative vulnerability of Bitcoin holders. It's worth noting that Bitcoin developers have already begun proposing solutions to develop quantum resistance.