The emergence of quantum computing has sparked intense discussion, particularly after Google's statement that a sufficiently powerful quantum machine could potentially exploit traditional blockchains with less effort than initially thought. For XRP holders, the answer to the question of vulnerability is nuanced, with experts suggesting that XRP's architecture offers better protection against quantum threats than Bitcoin's.
XRP operates on the XRP Ledger, an open-source, decentralized blockchain used by Ripple for cross-border transactions. Let's break down the details step by step. The primary concern with quantum computing is its potential to reverse-engineer private keys from exposed public keys, thereby draining funds from accounts.
Typically, a public key is exposed when a transaction is sent, and the wallet address, derived from the public key, is shared to receive funds. This exposure is what makes an account vulnerable to quantum attacks, not the balance or the duration the address has been held. Recently, a quantum vulnerability audit of the XRP Ledger found that approximately 300,000 accounts holding 2.4 billion XRP have never sent funds, only receiving them, which means their public keys have never been exposed to the network. These accounts are inherently quantum-safe.
However, there are dormant 'whale' accounts that have transacted in the past, exposing their public keys, but these transactions occurred at least five years ago. If a quantum computer were to emerge, these accounts would be at risk. The audit identified two such accounts holding 21 million XRP, which, although significant, constitutes only 0.03% of the circulating supply.
The vulnerability of these accounts is based on the assumption that they are dormant and not actively managing their keys. The XRP Ledger offers a 'key rotation' feature, allowing users to change their signing key without moving funds, thus keeping their accounts safe. This feature is technically available to all users, but the issue arises with long-dormant accounts whose owners may have lost their keys, passed away, or are simply not attentive to their accounts, making them vulnerable. Mayukha Vadari, a staff software engineer at Ripple, highlighted the 'escrow feature' as another defense mechanism.
Funds locked in escrow with a time lock are safe due to logical constraints rather than cryptography, as the time lock prevents withdrawal until a specified time has passed. While the time lock protects the funds, the account holding the escrow can still carry quantum risks.
In comparison, the quantum threat to Bitcoin appears more severe. A significant portion of early bitcoin was mined using a format that directly exposed public keys, including Satoshi Nakamoto's 1 million BTC, which has never been moved. Google estimates that about 6.9 million BTC are vulnerable, equating to nearly 35% of Bitcoin's circulating supply, a significantly larger figure than XRP's 0.03%.
These accounts are highly vulnerable to quantum attacks. Even holders aware of the threat face a structural issue that XRP holders do not: Bitcoin's blockchain lacks a key rotation feature, forcing holders to move funds to a new address to protect them.
However, during the transfer, the old address's public key is exposed, potentially allowing a strong quantum machine to exploit it. While this risk is still theoretical, it underscores the relative vulnerability of Bitcoin holders.
It's worth noting that Bitcoin developers have initiated proposals to develop quantum resistance.