Bitcoin's Quantum Conundrum: Can the Network Mitigate the Looming Threat?
Not all aspects of bitcoin are vulnerable to quantum computer attacks. The process of mining, which involves adding new blocks to the blockchain, utilizes a type of mathematics known as hashing that quantum computers are unable to compromise. The blockchain itself and the rule that new bitcoins can only be created through mining would remain intact in the event of a quantum attack. However, ownership is a different matter. Bitcoin wallets rely on a distinct type of mathematics that converts a private key into a public address. This math functions seamlessly in one direction but is virtually impossible to reverse, which is the primary obstacle preventing unauthorized individuals from spending someone else's coins. A quantum algorithm known as Shor's algorithm can bridge this gap, and a recent paper by Google demonstrated that this attack could be executed with far fewer resources than previously estimated, potentially within a timeframe that competes with bitcoin's block times. This article, the final installment in a series, explores the potential consequences, the measures bitcoin has taken to address the issue, and whether a network designed to resist coordinated change can implement the most significant security upgrade in its history before quantum computing technology advances. Approximately 6.9 million bitcoins, equivalent to one-third of all mined bitcoins, are stored in wallets whose public keys are already visible on the blockchain. This includes early bitcoins from the network's inaugural years, which were stored in an address format that published the public key by default, as well as any wallet that has been spent from, as spending reveals the key for the remaining balance. A quantum attacker would not need to compete with an ongoing transaction; instead, they could systematically compromise wallets with exposed keys at their own pace. Bitcoin's pseudonymous creator, Satoshi Nakamoto, holds roughly 1 million bitcoins that have remained untouched since the network's early days and are now classified as exposed. The 2021 Taproot upgrade inadvertently expanded the problem by introducing a change to how bitcoin addresses function, aiming to make transactions more efficient and private. While the quantum threat has sparked intense debate in recent months, and other blockchains are preparing for the potential risks, bitcoin developers have yet to propose a concrete plan. Ethereum, a major competitor, has had a formal quantum-resistant program in place since 2018, with four dedicated teams working on the migration and multiple independent developer groups testing networks on a weekly basis. In contrast, bitcoin lacks a comparable strategy. Although there are efforts to address the issue, such as the BIP-360 proposal, which suggests introducing new quantum-safe address types, and a proposal by BitMEX Research to implement a detection system, neither has garnered broad support from bitcoin's core developers. The primary challenge in implementing effective solutions lies in bitcoin's governance structure, which is designed to resist coordinated change. Ethereum's foundation and governance process enable it to pass significant upgrades regularly, whereas bitcoin's development culture views any central authority as a potential failure mode, making the quantum problem more difficult to address. The migration of 6.9 million exposed coins requires decisions that the network has avoided for twenty years, including whether to freeze old address formats, allow exposed coins to move to new quantum-safe addresses, and determine the fate of coins whose owners are unable or unwilling to migrate. The future of bitcoin hangs in the balance, as the Google paper's warning suggests that by the time the threat becomes apparent, the window for response may have already closed. Developers are now faced with the question of whether a network built to resist change can coordinate the most significant security upgrade in its history before the advent of quantum computing technology.