Time Running Out for Bitcoin to Mitigate Quantum Threat, 6.9 Million BTC at Risk

Not all aspects of Bitcoin are vulnerable to quantum computers. The process of mining new blocks and the rule that new Bitcoins can only be created through mining are secure due to the type of math used, known as hashing, which quantum computers cannot effectively break. However, ownership is at risk due to a different mathematical mechanism that protects wallets. This math, which converts a private key into a public address, is one-way, meaning it's easy to generate a public address from a private key but virtually impossible to do the reverse. A quantum algorithm known as Shor's algorithm can bypass this security, and recent research has shown that such an attack could be carried out with fewer resources than previously thought. This poses a significant threat, particularly to the approximately 6.9 million Bitcoins that have public keys exposed on the blockchain, including those belonging to Bitcoin's pseudonymous creator, Satoshi Nakamoto. The exposed pool of Bitcoin is large, partly due to early Bitcoin stored in address formats that published public keys by default and any wallet that has been spent from, as spending reveals the key for the remaining balance. The 2021 Taproot upgrade has also expanded the problem by making any Bitcoin spent since its activation publish the key protecting the remaining balance at that address. While there are efforts to address the quantum threat, such as proposals for new quantum-safe address types and detection systems, these have not yet gained broad support from Bitcoin's core developers. The lack of a formal governance process and central authority in Bitcoin makes coordinating a response more challenging compared to other blockchains like Ethereum, which has had a formal quantum-resistant program in place since 2018. The Ethereum Foundation is actively working on migrating Ethereum's security to quantum-resistant cryptography, with a dedicated website to track progress. In contrast, Bitcoin's approach to addressing the quantum threat is less coordinated, with different proposals that solve different parts of the problem but lack broad support. The urgency of the situation has been highlighted by prominent Bitcoin advocates, who argue that the current state of elliptic curve cryptography used in Bitcoin wallets is on the brink of obsolescence. The path forward for Bitcoin involves difficult decisions about how to migrate exposed coins to quantum-safe addresses without compromising the network's decentralized nature and stability. Setting a migration deadline, freezing old address formats, or allowing exposed coins to move to new addresses using original keys all present challenges that change Bitcoin's character in ways it has historically avoided. The question remains whether Bitcoin can coordinate the necessary security upgrade before the threat becomes reality, or if it will wait until the threat is demonstrated, by which time it might be too late.