Bitcoin Faces Quantum Threat: Can It Coordinate a Security Upgrade to Protect 6.9 Million BTC?

Not all aspects of bitcoin are vulnerable to quantum computer attacks. The process of bitcoin mining, which involves adding new blocks to the blockchain, utilizes a type of mathematical function known as hashing that quantum computers are unable to break. As a result, the blockchain ledger and the rule that new bitcoins can only be created through mining would remain intact in the event of a quantum attack. However, the ownership of bitcoins is at risk. Bitcoin wallets rely on a different type of mathematical function that converts a private key into a public address. This function is easy to perform in one direction but extremely difficult to reverse, which is the primary obstacle preventing unauthorized individuals from spending someone else's coins. The first part of this series on quantum computing delved into the physics behind it, explaining how a quantum computer is a fundamentally different machine that operates at extremely low temperatures and small scales, where particles exhibit unique behaviors. The second part examined the potential impact of quantum computing on bitcoin, discussing how bitcoin wallets rely on a one-way mathematical function. A quantum algorithm known as Shor's algorithm can significantly reduce the time required to break this function. A recent paper by Google demonstrated that a quantum attack could be launched with fewer resources than previously estimated, highlighting the need for bitcoin to upgrade its security. This final piece in the series focuses on the response to the quantum threat, including what is at risk, what bitcoin has done to address the issue, and whether the network can coordinate a major security upgrade. Approximately 6.9 million bitcoins, equivalent to one-third of all mined coins, are stored in wallets with publicly visible keys, making them vulnerable to quantum attacks. This includes early bitcoins stored in addresses that published public keys by default, as well as wallets that have been spent from, as spending reveals the key for any remaining balance. A quantum attacker would not need to compete with ongoing transactions but could instead work through the exposed wallets at their own pace. The 2021 Taproot upgrade inadvertently expanded the problem by making any bitcoin spent since its activation publish the key protecting the remaining balance at that address. While the quantum threat has sparked intense debate, no concrete solutions have emerged from bitcoin developers yet. In contrast, Ethereum has had a formal quantum-resistant program in place since 2018, with four teams working on the migration and a dedicated website to track progress. Bitcoin has no equivalent strategy, although there are efforts to address the issue, such as a proposal to add new quantum-safe address types and a competing proposal to install a detection system that triggers defensive action in the event of a quantum attack. However, neither proposal has gained broad support from bitcoin's core developers, and they only address half of the problem. The biggest challenge in implementing effective solutions is bitcoin's governance structure, which is designed to resist coordinated change. Ethereum's foundation and governance process allow for more straightforward upgrades, but bitcoin's development culture treats central authority as a failure mode, making it harder to implement changes. Migrating the 6.9 million exposed coins requires decisions that the network has avoided for twenty years, such as whether to freeze old address formats or allow exposed coins to move to new quantum-safe addresses. The outcome will depend on whether the network can coordinate a major security upgrade before the threat becomes a reality.