The Quantum Threat to Bitcoin: How a Powerful Computer Can Steal Your Cryptocurrency in Under 10 Minutes

In the first part of this series, we delved into the world of quantum computing, exploring the fundamental principles that govern its operation. However, understanding the inner workings of a quantum computer is only half the story - to truly grasp the threat it poses to Bitcoin, we need to examine the target itself, namely the encryption that underpins the cryptocurrency. In this piece, we will dissect the elliptic curve cryptography used by Bitcoin, explain how a quantum algorithm can break it, and discuss the recent developments that have significantly reduced the time it would take for a quantum computer to do so. The security of Bitcoin relies on a complex system of public and private keys, with the latter being used to create digital signatures that prove ownership of the cryptocurrency. The public key is derived from the private key through a mathematical operation on the elliptic curve, creating a one-way map that is easy to traverse in one direction but virtually impossible to reverse. This is the foundation of Bitcoin's security model, and it is precisely this aspect that a quantum computer can exploit. In 1994, mathematician Peter Shor discovered an algorithm that can efficiently solve the discrete logarithm problem, which is the backbone of Bitcoin's encryption. Shor's algorithm leverages the principles of quantum mechanics to find the period of a function, which is essential for breaking the elliptic curve cryptography. The algorithm uses superposition to evaluate the function on multiple inputs simultaneously, entanglement to correlate the inputs and outputs, and interference to filter out incorrect answers. The result is a period that can be used to derive the private key, effectively breaking the encryption. While Shor's algorithm has been known for over 30 years, its implementation has been hindered by the need for a large number of stable qubits. Recent estimates suggested that millions of physical qubits would be required, but a paper by Google's Quantum AI division has reduced this number to fewer than 500,000. The team designed two quantum circuits that can implement Shor's algorithm against Bitcoin's elliptic curve, using approximately 1,200 and 1,450 logical qubits, respectively. The introduction of a practical attack scenario has significant implications for the security of Bitcoin. The parts of Shor's algorithm that depend on the elliptic curve's fixed parameters can be precomputed, allowing the quantum computer to sit in a primed state, waiting for a target public key to appear. Once the public key is visible, the machine only needs to finish the second half of the calculation, which Google estimates takes around nine minutes. This creates a narrow window of opportunity for a quantum attacker to derive the private key and submit a competing transaction. The average block confirmation time for Bitcoin is 10 minutes, giving the attacker a roughly 41% chance of succeeding. The bigger concern, however, is the 6.9 million bitcoin that are already vulnerable to an 'at-rest' attack, where the public key has been permanently exposed on the blockchain. These coins can be targeted without any time constraint, making them a prime target for a quantum attacker. The implications of this threat are far-reaching, and the next piece in this series will explore the practical consequences of a quantum attack on Bitcoin, including the impact of Taproot and the rapidly advancing hardware that is closing the gap.