Time Runs Out for Bitcoin to Counter Quantum Threat, Putting 6.9 Million BTC at Risk
Not all aspects of bitcoin are vulnerable to quantum computers. The process of bitcoin mining, which utilizes a type of mathematics known as hashing, is secure against quantum attacks. The blockchain itself and the rule that new bitcoins can only be created through mining would remain intact in the event of a quantum attack. However, ownership of bitcoins is a different matter. Bitcoin wallets rely on a type of mathematics that converts a private key into a public address. This one-way math problem is the only thing preventing unauthorized access to a user's coins. A quantum algorithm known as Shor's algorithm can potentially break this math problem, and a recent paper by Google has shown that such an attack could be carried out with fewer resources than previously thought. This article, the final part of a series, explores the potential risks and the response of the bitcoin community to the quantum threat. Approximately 6.9 million bitcoins, or about one-third of all mined bitcoins, are stored in wallets whose public keys are already visible on the blockchain. This includes early bitcoins and any wallet that has been spent from, as spending reveals the public key. A quantum attacker would not need to race against a transaction in progress but could instead work through the wallets with exposed keys at their own pace. Bitcoin's pseudonymous creator, Satoshi Nakamoto, holds around 1 million bitcoins that are now at risk. The 2021 Taproot upgrade has expanded the problem, as any bitcoin spent since then has published its public key, making it vulnerable to quantum attacks. While there are some proposals to address the quantum threat, such as BIP-360 and a detection system proposed by BitMEX Research, none have gained broad support from bitcoin's core developers. Ethereum, on the other hand, has a formal quantum-resistant program in place and has made significant progress in migrating to quantum-safe cryptography. The biggest challenge for bitcoin is its decentralized nature, which makes it difficult to coordinate a response to the quantum threat. The network's development culture treats any central authority as a failure mode, and changes to the protocol are rare and hard to implement. Migrating the 6.9 million exposed coins requires decisions that the network has spent years avoiding. Setting a migration deadline would force owners of exposed coins, including Satoshi, to either move their coins or lose them. The future of bitcoin hangs in the balance, and the question remains whether the network can coordinate a massive security upgrade before the quantum threat becomes a reality.