Bitcoin's Quantum Conundrum: A Race Against Time to Prevent a 6.9 Million BTC Heist
Not all aspects of bitcoin are vulnerable to quantum computer attacks. The process of bitcoin mining, which utilizes a type of math known as hashing, is secure against quantum computers. This means that the blockchain ledger and the rule that new bitcoins can only be created through mining will remain intact even in the face of a quantum attack. However, the same cannot be said for bitcoin ownership. Bitcoin wallets rely on a different type of mathematical problem that converts a private key into a public address. While it is easy to perform this conversion in one direction, it is virtually impossible to reverse the process using a conventional computer. This is what currently prevents unauthorized individuals from spending someone else's bitcoins. A quantum algorithm, known as Shor's algorithm, has the potential to significantly reduce the time it takes to reverse this process. Recent research by Google has demonstrated that this attack could be carried out with far fewer resources than previously thought, and within a time frame that competes with bitcoin's own block times. This article, the final installment in a series, explores the potential consequences of a quantum attack on bitcoin and the efforts being made to mitigate this threat. Approximately 6.9 million bitcoins, equivalent to about one-third of all mined bitcoins, are stored in wallets whose public keys are already visible on the blockchain. This includes bitcoins from the network's early days, which were stored in an address format that published the public key by default, as well as any wallet that has ever been used for a transaction, as spending reveals the key for the remaining balance. A quantum attacker would not need to compete with an ongoing transaction but could instead work through the wallets with exposed keys at their own pace. This includes the approximately 1 million bitcoins held by bitcoin's pseudonymous creator, Satoshi Nakamoto, which have remained untouched since the network's early days. The 2021 Taproot upgrade inadvertently expanded the problem by making any bitcoin spent since its activation publish the key protecting the remaining balance at that address. Although this was not an error, it was a reasonable trade-off at the time, given the perceived longer timeline for quantum threats. Currently, there are no concrete plans from Bitcoin developers to address the quantum threat. In contrast, Ethereum, one of bitcoin's major competitors, has had a formal quantum-resistant program in place since 2018. The Ethereum Foundation has dedicated teams working on the migration and has published a roadmap for the upgrades. Bitcoin, on the other hand, lacks a unified strategy. There are, however, proposals from developers and researchers, such as BIP-360, which suggests introducing new quantum-safe address types that holders could migrate to voluntarily. Another proposal from BitMEX Research involves installing a detection system that triggers defensive actions in the event of a quantum attack on the network. Neither proposal has garnered broad support from bitcoin's core developers, and they address different aspects of the problem. The lack of urgency and coordination among bitcoin developers has been criticized by prominent advocates, such as Nic Carter, who has described Ethereum's approach as 'best in class' and bitcoin's as 'worst in class'. Adam Back, the CEO of Blockstream and an early contributor to bitcoin, agrees that while the urgency may not be immediate, bitcoin should prepare for the future by incorporating optional upgrades that allow the network to migrate when necessary. The main challenge in implementing effective solutions against the quantum threat lies in bitcoin's governance structure. Bitcoin's development culture is based on the principle that any central authority is a failure mode, and changes to the protocol should be rare and difficult. This has kept the network stable for nearly two decades but also makes it structurally harder for bitcoin to address the quantum problem. The migration of the 6.9 million exposed coins requires decisions that the network has spent years avoiding. Questions such as whether old address formats should be frozen after a certain date to protect coins from future theft, or whether exposed coins should be allowed to move to new quantum-safe addresses using their original keys, need to be addressed. The fate of coins whose owners cannot or will not migrate also needs to be determined. The situation is further complicated by the fact that any solution will change bitcoin's character in ways the network has historically refused to change. The recent Google paper frames the industry's current stance, suggesting that a successful attack on bitcoin's math should not be seen as a wake-up call to adopt post-quantum cryptography, but rather as a potential signal that the adoption of post-quantum cryptography has already failed. This implies that by the time the threat becomes apparent, the window to respond may have already closed. Developers are now faced with the question of whether a network built to resist coordinated change can coordinate the biggest security upgrade in its history before the threat becomes a reality. Ethereum's eight-year head start in addressing the quantum threat suggests that starting now is the correct approach. However, bitcoin's governance culture indicates that the likely response will be to wait until the threat is demonstrated before taking action. Only one of these approaches will be effective if the timeline turns out to be shorter than estimated.