Time Runs Out for Bitcoin to Counter Quantum Threat, Putting 6.9 Million BTC at Risk, Including Satoshi's Holdings
Not all aspects of bitcoin are vulnerable to quantum computer attacks. The process of bitcoin mining, which involves adding new blocks to the blockchain, utilizes a type of mathematics known as hashing that quantum computers are unable to effectively breach. As a result, the blockchain itself and the rule that new bitcoins can only be created through mining would remain intact in the event of a quantum attack. However, ownership of bitcoins is a different story. Bitcoin wallets rely on a distinct mathematical approach that converts a private key into a public address that can be seen by anyone. This math works seamlessly in one direction but is impractical in the other, and it is the only barrier preventing unauthorized individuals from spending your coins. A significant portion of bitcoin, approximately 6.9 million, is stored in wallets with publicly visible keys, making them susceptible to quantum attacks. This includes early bitcoins from the network's inception, stored in an address format that publicly disclosed the key by default, as well as any wallet that has been spent from, as spending reveals the key for the remaining balance. The 2021 Taproot upgrade inadvertently expanded the issue by making transactions more efficient and private, but as a side effect, any bitcoin spent since Taproot's activation has exposed the key protecting the remaining balance at that address. While the quantum threat has sparked intense debate, concrete solutions from bitcoin developers have yet to emerge. In contrast, Ethereum has had a formal quantum-resistant program in place since 2018, with four teams working full-time on the migration and multiple independent developer groups releasing weekly test networks. Ethereum's plan involves specific upgrades across four upcoming network-wide changes, transitioning its security to quantum-resistant mathematics. Bitcoin, on the other hand, lacks a comparable strategy. There are proposals, such as BIP-360, which suggests introducing new quantum-safe address types that holders could voluntarily migrate to, and a competing proposal from BitMEX Research that would implement a detection system triggering defensive action if a quantum attack is observed. However, neither proposal has garnered broad support from bitcoin's core developers, and they address different aspects of the problem. The challenge in implementing effective solutions lies in bitcoin's coordination problem, stemming from its lack of a central authority and governance process. Ethereum's foundation and governance structure allow for more streamlined decision-making and implementation of upgrades. Bitcoin's development culture, which treats central authority as a failure mode and emphasizes rare and difficult changes to the protocol, has maintained network stability but complicates the process of addressing the quantum threat. The migration of 6.9 million exposed coins requires decisions that the network has historically avoided, such as whether to freeze old address formats to protect coins from future theft or allow exposed coins to move to new quantum-safe addresses using their original keys. Each option would alter bitcoin's character in ways the network has traditionally resisted. The future of bitcoin's security in the face of quantum computing threats depends on its ability to coordinate a significant security upgrade, a challenge that its governance culture may not be equipped to handle.