Bitcoin Faces Looming Quantum Threat: Can It Adapt to Prevent Catastrophic Losses?
Not all aspects of Bitcoin are vulnerable to quantum computer attacks. The process of mining, which involves adding new blocks to the blockchain, relies on a type of mathematics known as hashing that quantum computers are unable to break. As a result, the ledger itself and the rule that new Bitcoins can only be created through mining would remain intact in the event of a quantum attack. Blocks would continue to be produced, and the chain would remain operational. However, ownership would be severely compromised. Bitcoin wallets are secured by a different mathematical approach that converts a private key into a public address that can be seen by anyone. This math works efficiently in one direction but is extremely difficult to reverse, which is the primary factor preventing unauthorized individuals from spending someone else's coins. The first part of this series on quantum computing delved into the physics behind it, explaining how a quantum computer is fundamentally different from a traditional computer, with its operations based on the unique behavior of particles at extremely low temperatures and small scales. The second part examined the implications of pointing a quantum computer at Bitcoin, highlighting how Bitcoin wallets rely on a one-way mathematical problem. Converting a private key into a public address takes mere milliseconds, but reversing this process would take a conventional computer longer than the universe's current age. A quantum algorithm known as Shor's algorithm significantly reduces this time gap. A recent paper by Google demonstrated that such an attack could be executed with far fewer resources than previously estimated, and within a timeframe that competes with Bitcoin's block creation times. This final piece in the series focuses on the response to this threat, discussing what is at risk, the measures Bitcoin has taken so far, and whether a network designed to resist coordinated changes can implement the largest security upgrade in its history before quantum computers become capable of exploiting this vulnerability. The pool of at-risk Bitcoin is substantial, with approximately 6.9 million Bitcoins - roughly one-third of all mined Bitcoins - stored in wallets whose public keys are permanently visible on the blockchain. This includes early Bitcoins from the network's first years, which were stored in an address format that published the public key by default, as well as any wallet that has been spent from, as spending reveals the key for the remaining balance. A quantum attacker would not need to compete with ongoing transactions but could systematically target wallets with exposed keys at their leisure. This includes the approximately 1 million Bitcoins held by Bitcoin's pseudonymous creator, Satoshi Nakamoto, which have remained untouched since the network's early days and are now in the exposed category. The 2021 Taproot upgrade inadvertently expanded the problem by changing how Bitcoin addresses function, aiming to make transactions more efficient and private. However, a side effect of Taproot is that any Bitcoin spent since its activation has had its protecting key published, making the remaining balance at that address vulnerable. While this was a deliberate design choice at the time, considering the perceived longer timeline for quantum threats, the situation has since evolved. Efforts are underway to address this issue, although nothing concrete has emerged from Bitcoin developers yet. In contrast, Ethereum, a major competitor, has had a formal quantum-resistance program in place since 2018, with the Ethereum Foundation supporting four full-time teams and numerous independent developer groups working on the migration. Ethereum has outlined specific upgrades across four upcoming network-wide changes, aiming to transition its security to quantum-resistant mathematics. It has also launched a dedicated website to track its progress. Bitcoin lacks a comparable strategy at present. There are, however, proposals and efforts from various groups and researchers. For instance, BIP-360 proposes introducing new quantum-safe address types that holders could migrate to voluntarily. Another proposal from BitMEX Research suggests implementing a detection system that would trigger defensive measures if a quantum attack is detected on the network. Neither proposal has garnered broad support from Bitcoin's core developers, and they address different aspects of the problem. Prominent Bitcoin advocate Nic Carter has emphasized the urgency of the situation, stating that the elliptic curve cryptography securing Bitcoin wallets is on the verge of becoming obsolete. Carter praised Ethereum's approach as "best in class" and criticized Bitcoin's as "worst in class," citing a lack of engagement with the issue among some developers. Adam Back, CEO of Blockstream and an early Bitcoin contributor, disagrees on the immediacy of the threat but agrees that preparation is necessary. Back suggests that Bitcoin should prepare optional upgrades in advance, allowing the network to migrate when needed without scrambling in response to a crisis. The primary challenge in implementing effective solutions against Bitcoin's quantum threat lies in coordination. Bitcoin's migration is more complex than Ethereum's due to its lack of a central authority and formal governance process. Ethereum's foundation and governance structure facilitate funding for engineering work and the passage of significant upgrades. In contrast, Bitcoin's development culture views any central authority as a potential failure point and prefers rare and difficult changes to the protocol. While this approach has maintained network stability for nearly two decades, it complicates addressing the quantum problem. Migrating the exposed 6.9 million Bitcoins requires decisions that the network has historically avoided. Questions include whether old address formats should be frozen after a certain date to protect coins from future theft, whether exposed coins should be allowed to move to new quantum-safe addresses using their original keys, and what should happen to coins whose owners cannot or will not migrate. The situation with Satoshi's coins is particularly poignant, as freezing old formats would protect them from theft but make them permanently inaccessible, including to Satoshi. Leaving the old formats open means those coins are at risk of being stolen by the first entity to develop a working quantum computer or gain access to one. Setting a migration deadline would force Satoshi to either move the coins, thereby revealing ownership, or lose them. Every option would change Bitcoin's character in ways the network has historically refused to alter. The Google paper frames the industry's current stance, suggesting that a successful attack on Bitcoin's mathematics should not be seen as a wake-up call to adopt post-quantum cryptography but rather as a potential signal that the window for such adoption has already closed. This implies that by the time the threat becomes apparent, it may be too late to respond. Developers are now faced with the question of whether a network built to resist coordinated change can coordinate the largest security upgrade in its history before quantum computers become a reality. Ethereum's head start of eight years suggests that starting now is the correct approach, while Bitcoin's governance culture indicates that waiting until the threat is demonstrated may be the more likely path. Only one of these approaches will be effective if the timeline proves shorter than optimists predict.