The Quantum Threat to Bitcoin: How Your Cryptocurrency Could Be Stolen in Under 10 Minutes

The first part of this series explored the principles of quantum computing, but understanding how it works is not enough to comprehend the threat it poses to Bitcoin. To grasp this, one must delve into the mechanics of Bitcoin's security and where its vulnerabilities lie. This piece will examine the encryption methods used by Bitcoin, why a quantum algorithm can break them, and the implications of Google's recent research on the timeline of this threat. Bitcoin's security relies on elliptic curve cryptography, which utilizes a one-way function to derive a public key from a private key. This function is virtually impossible for classical computers to reverse, making it the foundation of Bitcoin's security model. However, the advent of quantum computing, particularly with the development of Shor's algorithm, poses a significant threat to this model. Shor's algorithm can efficiently solve the discrete logarithm problem, which underlies the security of Bitcoin's elliptic curve cryptography. The algorithm works by exploiting the principles of quantum mechanics, including superposition, entanglement, and interference, to find the period of a function related to the elliptic curve. This period is crucial for deriving the private key from the public key. Although Shor's algorithm has been known for over 30 years, its implementation has been hindered by the need for a large number of stable qubits. Recent research by Google has reduced the estimated number of qubits required, making the threat more tangible. The study designed two quantum circuits that can implement Shor's algorithm against Bitcoin's specific elliptic curve, using fewer than 500,000 physical qubits. This reduction in qubit count, along with the introduction of a practical attack scenario, has significant implications for the security of Bitcoin. The attack scenario involves precomputing parts of Shor's algorithm that depend on the elliptic curve's fixed parameters, allowing the quantum computer to sit in a primed state. When a target public key appears, the machine only needs to finish the second half of the calculation, which Google estimates takes approximately nine minutes. This timeframe is alarming, as it gives a quantum attacker a roughly 41% chance of deriving a private key and submitting a competing transaction before the original transaction confirms. Furthermore, the 6.9 million Bitcoin sitting in wallets with exposed public keys are vulnerable to an 'at-rest' attack, which does not require a race against the clock. The development of quantum computers capable of running Shor's algorithm poses a significant threat to the security of Bitcoin, and understanding the implications of this threat is crucial for the future of cryptocurrency.