In a recent research report, Grayscale, a digital asset management firm, expressed support for expediting efforts to render public blockchains resistant to quantum computing threats, emphasizing that although technical solutions are readily available, the more daunting task lies in securing agreement among decentralized communities to implement these solutions. This report comes on the heels of a week-long industry response to a paper by Google Quantum AI, which demonstrated that compromising bitcoin's elliptic curve cryptography would necessitate fewer than 500,000 physical qubits, a reduction of approximately 20 times from prior estimates, and could be executed in roughly nine minutes once the necessary machinery is in place. An analysis by CoinDesk revealed that such an attack would afford the attacker a probability of approximately 41% of pilfering funds prior to the confirmation of a bitcoin transaction. Grayscale's report highlighted four key takeaways from Google's research, including the potential for progress toward a cryptographically relevant quantum computer to occur in discrete increments rather than linearly, thereby rendering timelines unpredictable.
Furthermore, the report noted that technical solutions, specifically post-quantum cryptography, are mature and already securing internet traffic and certain blockchain transactions, and that quantum risk varies significantly across different blockchains depending on their transaction models, consensus mechanisms, and block times. From a purely engineering perspective, it was argued that bitcoin possesses a lower quantum risk compared to other chains due to its utilization of a UTXO model, proof-of-work consensus, absence of native smart contracts, and specific address types that are not vulnerable to quantum attacks if not reused after spending. However, the more pressing question pertains to the fate of the approximately 6.9 million BTC residing in wallets with publicly exposed public keys on the blockchain, including an estimated 1 million believed to belong to bitcoin's pseudonymous creator, Satoshi Nakamoto.
Binance co-founder Changpeng Zhao recently posed a similar query, suggesting that if Satoshi's coins are moved during a potential migration, it would indicate that he is still active, which would be an interesting revelation, and that if they remain unmoved, it might be preferable to lock or effectively burn those addresses. Grayscale presents similar options – burning the coins, taking no action, or deliberately slowing their release by limiting the spending rate from vulnerable addresses – but notes that the bitcoin community has a history of contentious debates surrounding protocol changes, citing last year's dispute over image data stored in blocks as an example.
In contrast, Ethereum's situation is noteworthy, with Google's paper identifying five separate attack vectors against Ethereum, totaling over $100 billion in combined exposure, spanning account keys, admin keys on stablecoins, smart contract code, consensus mechanisms, and data availability. Ethereum Foundation researcher Justin Drake, a co-author of the Google paper, estimated a minimum 10% probability of quantum key recovery by 2032, and while the foundation has been aggressively staking, depositing $93 million of ether into validators in a single day, it has not publicly addressed quantum migration timelines.