Time is Running Out for Bitcoin to Counter Quantum Threat

Not all aspects of bitcoin are vulnerable to quantum computer attacks. The process of bitcoin mining, which involves adding new blocks to the blockchain, utilizes a type of mathematics known as hashing that quantum computers are currently unable to compromise. As a result, the blockchain itself and the rule that new bitcoins can only be created through mining would remain intact in the event of a quantum attack. However, the ownership of bitcoins is at risk. Bitcoin wallets rely on a different type of mathematics that converts a private key into a public address. This math is easily performed in one direction but not the other, which is what prevents unauthorized individuals from spending someone else's coins. A quantum algorithm known as Shor's algorithm can bridge this gap, and a recent paper by Google demonstrated that such an attack could be executed with fewer resources than previously thought, within a timeframe that competes with bitcoin's block times. This article explores what is at risk, the measures bitcoin has taken so far, and whether a network designed to resist coordinated change can implement the largest security upgrade in its history before quantum computing technology advances. Approximately 6.9 million bitcoins, roughly one-third of all mined coins, are stored in wallets whose public keys are already visible on the blockchain. This includes early bitcoins from the network's first years, which were stored in an address format that published the public key by default, as well as any wallet that has been spent from, as spending reveals the key for the remaining balance. A quantum attacker would not need to compete with an ongoing transaction but could instead work through the wallets with exposed keys at their own pace. Bitcoin's pseudonymous creator, Satoshi Nakamoto, holds approximately 1 million bitcoins that have remained untouched since the network's early days and are now in the exposed category. The 2021 Taproot upgrade inadvertently expanded the problem by making transactions more efficient and private but also publishing the key that protects any remaining balance at an address after a transaction. While the quantum threat has sparked intense debate and other blockchains like Ethereum are preparing by working on quantum-resistant programs, Bitcoin developers have yet to propose a concrete plan. Ethereum has had a formal quantum-resistant program in place since 2018, with four teams working full-time on the migration and multiple independent developer groups testing networks weekly. In contrast, Bitcoin has no equivalent strategy, although there are proposals like BIP-360, which suggests adding new quantum-safe address types, and a proposal from BitMEX Research to install a detection system that triggers defensive action if a quantum attack is observed. However, neither proposal has broad support from core developers, and they address different parts of the problem. The biggest challenge in implementing effective solutions is not the math itself but the coordination problem due to Bitcoin's governance culture, which treats any central authority as a failure mode and prefers changes to the protocol to be rare and difficult. Migrating the exposed coins requires decisions that the network has avoided for twenty years, such as whether to freeze old address formats to protect coins from future theft or allow exposed coins to move to new quantum-safe addresses using their original keys. The fate of coins whose owners cannot or will not migrate, including Satoshi's coins, poses a significant dilemma. Setting a migration deadline would force Satoshi to either move the coins, revealing ownership, or lose them, which would change Bitcoin's character in ways the network has historically refused to change. The future of Bitcoin's security in the face of quantum threats hangs in the balance, with the question of whether the network can coordinate a massive security upgrade before the threat becomes real.