Bitcoin Faces Looming Quantum Threat: Can It Adapt to Prevent Catastrophic Losses?

Not all aspects of bitcoin are vulnerable to quantum computing. The process of bitcoin mining, which involves adding new blocks to the blockchain, utilizes a type of mathematics known as hashing that quantum computers are unable to breach effectively. The blockchain itself and the rule that new bitcoins can only be created through mining would remain intact in the face of a quantum attack, ensuring the continuous production of blocks and the operation of the chain. However, what is at risk is ownership. Bitcoin wallets are secured by a different mathematical mechanism that converts a private key into a public address. This math is straightforward in one direction but virtually impossible in the other, and it is the sole barrier preventing unauthorized individuals from spending your coins. The first part of this series delved into the physics of quantum computing, explaining that a quantum computer is fundamentally different from a regular computer, operating at extremely low temperatures and small scales where particles exhibit unique behaviors not observed elsewhere. The second part examined the implications of pointing a quantum machine at bitcoin, highlighting that bitcoin wallets rely on a one-way mathematical problem. While converting a private key into a public address takes milliseconds, reversing this process would take a conventional computer longer than the universe's age. A quantum algorithm known as Shor's algorithm dramatically reduces this time gap. A recent paper by Google demonstrated that such an attack could be executed with fewer resources than previously estimated, racing against bitcoin's block times. This final piece in the series addresses the response, discussing what is at risk, the measures bitcoin has taken, and whether a network designed to resist coordinated change can implement the largest security upgrade in its history before quantum hardware becomes a reality. The exposed and safe assets are significant concerns. Approximately 6.9 million bitcoins, roughly one-third of all mined coins, are stored in wallets with public keys that are permanently visible on the blockchain. This includes early bitcoins from the network's first years, stored in an address format that published the public key by default, as well as any wallet that has been spent from, as spending reveals the key for the remaining balance. A quantum attacker would not need to compete with an ongoing transaction; instead, they could systematically work through wallets with exposed keys at their leisure. This includes the approximately 1 million untouched bitcoins held by bitcoin's pseudonymous creator, Satoshi Nakamoto, which now fall into the exposed category. The 2021 Taproot upgrade inadvertently expanded the problem. Taproot is a change to how bitcoin addresses function, aimed at making transactions more efficient and private. However, a side effect was that any bitcoin spent after Taproot's activation has published the key protecting the remaining balance at that address. Although this was not a mistake, it was a reasonable tradeoff at the time, given the perceived longer timelines for quantum threats. Current developments are underway but lack concrete direction from Bitcoin developers. In contrast, Ethereum, a significant competitor among institutional investors, has had a formal quantum-resistant program since 2018. The Ethereum Foundation supports four full-time teams working on the migration, with over ten independent developer groups releasing weekly test networks. Ethereum has outlined specific upgrades across four upcoming network-wide changes, transitioning its security to quantum-resistant mathematics. It has even launched a dedicated website to track its progress. Bitcoin lacks an equivalent strategy. Despite the absence of a unified approach, efforts are being made to address the issue. One formal proposal, BIP-360, from a group of developers and researchers, suggests introducing new quantum-safe address types that holders could migrate to voluntarily. Another proposal from BitMEX Research would implement a detection system that triggers a defensive response if a quantum attack is observed on the network. Neither proposal has garnered broad support from bitcoin's core developers, and they address different aspects of the problem. Prominent bitcoin advocate Nic Carter has voiced concerns, stating that elliptic curve cryptography, which secures bitcoin wallets, is on the verge of obsolescence. He praised Ethereum's approach as 'best in class' and criticized bitcoin's as 'worst in class,' citing developers who deny, downplay, or ignore the problem rather than addressing it. Adam Back, CEO of Blockstream and an early bitcoin contributor, disagrees on the urgency but agrees on the need for preparation. He advocates for optional upgrades to be built in advance, allowing the network to migrate when necessary, rather than reacting in crisis mode. The primary challenge in implementing effective solutions against the quantum threat is coordination. Bitcoin's migration is more complex than Ethereum's due to reasons unrelated to the mathematics involved. Ethereum has a foundation that funds engineering work and a governance process that regularly passes major upgrades. In contrast, bitcoin lacks a central authority and treats any form of governance as a potential failure mode, making the quantum problem structurally harder to solve. Migrating the exposed 6.9 million coins requires decisions that the network has historically avoided. Questions arise about whether old address formats should be frozen to protect coins, whether exposed coins can be moved to quantum-safe addresses using their original keys, and what happens to coins whose owners cannot or will not migrate. The fate of Satoshi's coins is a sharp example, as freezing old formats protects the coins but makes them inaccessible, including to Satoshi, while leaving the formats open leaves the coins vulnerable to quantum attack. Setting a migration deadline forces Satoshi to either move the coins, revealing ownership, or risk losing them. Every option changes bitcoin's character in ways the network has historically refused to alter. The future is uncertain, with the Google paper framing the industry's stance. A successful attack on bitcoin's mathematics should not be seen as a call to adopt post-quantum cryptography but as a potential signal that such adoption has already failed. This implies that by the time the threat becomes apparent, the window for response may have closed. Developers face the question of whether a network built to resist coordinated change can implement the largest security upgrade in its history before quantum hardware catches up. Ethereum's head start suggests starting now is the correct approach, while bitcoin's governance culture indicates a likelihood of waiting until the threat is demonstrated before acting. Only one of these approaches will be effective if the timeline proves shorter than estimated.