Time Runs Out for Bitcoin to Counter Quantum Threat, Putting 6.9 Million BTC at Risk
Not all aspects of bitcoin are vulnerable to quantum computer attacks. The process of bitcoin mining, which involves a type of mathematics known as hashing, is resistant to quantum breaches. This means the blockchain ledger and the rule that new bitcoins can only be created through mining are safe. Blocks will continue to be produced, and the blockchain will remain operational. However, ownership is a different story. Bitcoin wallets rely on a specific type of mathematics that converts a private key into a public address. This math is straightforward in one direction but virtually impossible in the other, which is what prevents unauthorized individuals from spending your coins. The first part of this series on quantum computing delved into the physics behind it, explaining how a quantum computer is fundamentally different from a regular computer, leveraging unique properties of particles at extremely low temperatures. The second part examined the implications of pointing a quantum machine at bitcoin. It highlighted how bitcoin wallets depend on a one-way math problem, where converting a private key to a public address is quick, but reversing the process would take an ordinary computer longer than the universe's age. A quantum algorithm known as Shor's algorithm significantly reduces this time gap. Recently, a paper by Google demonstrated that such an attack could be executed with fewer resources than previously thought, racing against bitcoin's block times. This final piece in the series focuses on the response to this threat, discussing what is at risk, the measures bitcoin has taken, and whether the network can coordinate a significant security upgrade before quantum hardware advances. A substantial portion of bitcoin is at risk, with roughly 6.9 million coins - about one-third of all mined bitcoins - stored in wallets with publicly visible keys on the blockchain. This includes early bitcoins and any wallet that has been spent from, as spending reveals the key. A quantum attacker wouldn't need to rush against ongoing transactions; instead, they could methodically work through exposed wallets at their own pace. This includes the approximately 1 million bitcoins held by Satoshi Nakamoto, the pseudonymous creator of bitcoin, which have remained untouched since the network's early days. The 2021 Taproot upgrade inadvertently expanded the problem by making transactions more efficient and private but also publishing the key protecting any remaining balance at an address after a spend. While the quantum threat has sparked intense debate, with other blockchains like Ethereum preparing for the challenge, concrete actions from Bitcoin developers are yet to emerge. Ethereum has had a formal quantum-resistant program since 2018, with the Ethereum Foundation running teams dedicated to the migration and a clear plan for upgrades to secure the network against quantum computers. In contrast, Bitcoin lacks a similar strategy. There are proposals, such as BIP-360, which suggests adding new quantum-safe address types for voluntary migration, and a competing proposal from BitMEX Research for a detection system to trigger defensive actions against quantum attacks. However, neither proposal has broad support from core developers and addresses only part of the problem. Prominent bitcoin advocates like Nic Carter have highlighted the urgency, criticizing bitcoin's approach as 'worst in class' compared to Ethereum's 'best in class' strategy. Others, like Adam Back, agree on the need for preparation but disagree on the immediacy of the threat, suggesting that while quantum computing has much to prove, bitcoin should prepare with optional upgrades to migrate when necessary. The biggest challenge in implementing effective solutions against the quantum threat is not the math itself but bitcoin's governance structure. Ethereum's foundation and regular upgrade process make such migrations easier, whereas bitcoin's development culture, which treats central authority as a failure and prefers rare and hard changes, makes coordination difficult. Migrating the exposed coins requires decisions that the network has historically avoided, such as whether to freeze old address formats or allow exposed coins to move to new quantum-safe addresses. Every option changes bitcoin's character in ways the network has refused to change. The future of bitcoin's security against quantum threats hangs in the balance, with the question being whether the network can overcome its governance challenges to implement necessary upgrades before it's too late.