Time Running Out for Bitcoin to Counter Quantum Computing Threat, 6.9 Million Bitcoins at Risk
Not all aspects of bitcoin are vulnerable to quantum computers. The process of bitcoin mining, which involves adding new blocks to the blockchain, relies on a type of mathematics known as hashing, which quantum computers are unable to compromise effectively. As a result, the bitcoin ledger and the rule governing the creation of new bitcoins through mining would remain intact in the event of a quantum attack. However, ownership of bitcoins would be at risk. Bitcoin wallets are secured by a different mathematical approach that converts a private key into a public address. This math is simple in one direction but virtually impossible in the other, and it is the primary barrier preventing unauthorized individuals from spending someone else's bitcoins. A previous article in this series explored the physics behind quantum computing, explaining how it differs fundamentally from traditional computing. Another article discussed the potential impact of quantum computing on bitcoin, highlighting the vulnerability of bitcoin wallets to quantum algorithms like Shor's algorithm. This final piece in the series examines the response to the quantum threat, including what is at risk, the measures bitcoin has taken so far, and whether the network can coordinate a significant security upgrade before quantum computers become a reality. Approximately 6.9 million bitcoins, or about one-third of all mined bitcoins, are stored in wallets with publicly visible keys, making them potential targets for quantum attacks. This includes early bitcoins from the network's inception, stored in an address format that published public keys by default, as well as any wallet that has been spent from, as spending reveals the key for any remaining balance. A quantum attacker would not need to compete with ongoing transactions but could instead work through wallets with exposed keys at their own pace. The 2021 Taproot upgrade inadvertently expanded the problem by making bitcoin addresses more efficient and private, but as a side effect, any bitcoin spent since Taproot's activation has published the key protecting the remaining balance at that address. While the quantum threat has sparked intense debate, concrete solutions from bitcoin developers have yet to emerge. In contrast, Ethereum has had a formal quantum-resistant program in place since 2018, with four teams working full-time on the migration and multiple independent developer groups testing networks weekly. Ethereum has also launched a dedicated website to track its progress. Bitcoin lacks a comparable strategy, although there are efforts underway to address the issue. One proposal, BIP-360, suggests introducing new quantum-safe address types that holders could migrate to voluntarily. Another proposal from BitMEX Research would implement a detection system to trigger defensive actions in the event of a quantum attack on the network. However, neither proposal has garnered broad support from bitcoin's core developers, and they address different aspects of the problem. Prominent bitcoin advocate Nic Carter has highlighted the urgency of the situation, stating that the elliptic curve cryptography securing bitcoin wallets is on the verge of becoming obsolete. He praised Ethereum's approach as 'best in class' and criticized bitcoin's as 'worst in class,' citing developers who deny or downplay the issue rather than engaging with it. Adam Back, CEO of Blockstream and an early bitcoin contributor, disagrees on the immediacy of the threat but agrees that bitcoin should prepare by implementing optional upgrades in advance. The primary challenge in addressing the quantum threat is not the math itself but rather the coordination problem within the bitcoin network. Bitcoin's migration is more complex than Ethereum's due to its lack of a central authority and governance process. The network's development culture views any central authority as a potential failure mode, and its social consensus emphasizes that changes to the protocol should be rare and difficult. This approach has maintained the network's stability for nearly two decades but also makes it structurally harder for bitcoin to address the quantum problem. Migrating the 6.9 million exposed coins requires decisions that the network has avoided for twenty years. Questions include whether old address formats should be frozen after a certain date to protect coins from future theft, whether exposed coins should be allowed to move to new quantum-safe addresses using their original keys, and what happens to coins whose owners cannot or will not migrate. The situation is particularly complicated for Satoshi Nakamoto's coins, which have remained untouched since the network's early days and are now at risk. Setting a migration deadline would force Satoshi to either move the coins, revealing their ownership, or lose them. Every option would change bitcoin's character in ways the network has historically refused to change. The recent Google paper frames the industry's stance, suggesting that a successful attack on bitcoin's math should not be seen as a wake-up call to adopt post-quantum cryptography but rather as a potential signal that such adoption has already failed. This implies that by the time the threat becomes apparent, the window to respond may have already closed. Developers are now faced with the question of whether a network built to resist coordinated change can coordinate the largest security upgrade in its history before quantum computers become a reality. Ethereum's eight-year head start suggests that starting now is the correct approach, while bitcoin's governance culture indicates that waiting until the threat is demonstrated may be the more likely course of action. Only one of these approaches will be effective if the timeline proves shorter than estimated.