The emergence of quantum computing has sparked intense discussion, particularly after Google's assertion that a sufficiently powerful machine could potentially exploit legacy blockchains with less effort than previously thought. For holders of XRP, the answer to the question of vulnerability is nuanced. Experts suggest that XRP's architecture may be better equipped to handle the threat than Bitcoin's. XRP operates on the XRP Ledger, an open-source, decentralized blockchain, which is utilized by Ripple for facilitating cross-border transactions.
Let's examine the details step by step. The primary concern with quantum computing is its potential to reverse-engineer private keys from exposed public keys, thereby allowing unauthorized access to funds. Typically, a public key is exposed when a transaction is sent, and the wallet address, derived from the public key, is shared to receive funds. This exposure is what makes an account vulnerable to quantum attacks, not the balance or the duration for which the address has been held.
Recently, a quantum vulnerability audit of the XRP Ledger revealed that approximately 300,000 accounts, holding around 2.4 billion XRP, have never sent funds and thus have never exposed their public keys to the network. These accounts are inherently quantum-safe. However, there are dormant accounts, known as 'whales,' which have transacted in the past, exposing their public keys, but have been inactive for at least five years. If a quantum computer were to emerge, these accounts would be at risk.
The audit found two such accounts holding 21 million XRP, which, although significant, accounts for only 0.03% of the circulating supply. The XRP Ledger's account-based system and the feature of signing key rotation provide additional protection.
This feature allows users to change their signing keys without moving funds, thus maintaining the security of their accounts. However, this feature is only beneficial if users are active and able to rotate their keys.
The problem arises with long-dormant accounts that may have lost access to their keys or are no longer active. Mayukha Vadari, a staff software engineer at Ripple, highlighted the 'escrow feature' as another line of defense against quantum risks. Funds locked in escrow with a time lock are protected not by cryptography, but by logic, as the time lock prevents withdrawal until a specified time has passed.
While the time lock safeguards the funds, the account that locked the funds can still carry quantum risks. In comparison, the quantum threat to Bitcoin appears more severe.
A significant portion of early Bitcoin was mined using a format that directly exposed public keys, including Satoshi Nakamoto's 1 million BTC, which has never been moved. Google estimates that about 6.9 million BTC are vulnerable, equating to nearly 35% of Bitcoin's circulating supply.
This is significantly higher than XRP's 0.03%. Bitcoin holders face a structural problem due to the lack of a key rotation feature, forcing them to move funds to a new address to protect against quantum attacks. However, this process exposes the public key of the old address, making it vulnerable to exploitation.
Although the risk is still theoretical, it highlights the relative vulnerability of Bitcoin holders. It's worth noting that Bitcoin developers have initiated proposals to develop quantum resistance.