The Quantum Threat to Bitcoin: How a Powerful Computer Can Steal Your Cryptocurrency in Under 10 Minutes
The first part of this series explored the fundamentals of quantum computing, including its unique properties and capabilities. However, understanding how a quantum computer operates does not necessarily reveal how it can be utilized to compromise bitcoin security. To grasp this, one must comprehend the target of such an attack: the encryption method used by bitcoin and the weaknesses it may possess. This piece will examine the specifics of bitcoin's encryption, the role of elliptic curve cryptography, and the potential vulnerabilities that could be exploited by a quantum algorithm. The security of bitcoin is based on a one-way function, which allows for easy verification of transactions but makes it virtually impossible for classical computers to reverse-engineer the private key from the public key. However, the advent of quantum computing and algorithms like Shor's has introduced a new level of risk. Shor's algorithm can efficiently solve the discrete logarithm problem, which is the foundation of bitcoin's encryption, potentially allowing a quantum computer to derive a private key from a public key. The implications of this are profound, as it could enable a malicious actor to steal bitcoin from vulnerable wallets. Recent research by Google has reduced the estimated number of qubits required to perform such an attack, making it more feasible in the near future. The study also introduced a practical attack scenario, which involves precomputing parts of the algorithm and then using a quantum computer to finish the calculation once a target public key is identified. This could potentially allow an attacker to derive a private key and submit a competing transaction within a narrow time frame, approximately nine minutes. The average block confirmation time for bitcoin is 10 minutes, which means an attacker has a roughly 41% chance of succeeding if they can derive the private key and submit a transaction before the original transaction is confirmed. While the immediate threat is still largely theoretical due to the current limitations of quantum computing hardware, the long-term implications are significant. Approximately 6.9 million bitcoin, or about one-third of the total supply, are potentially vulnerable to an 'at-rest' attack, where an attacker can take as long as needed to derive the private key once the public key is exposed.