The Quantum Threat to Bitcoin: How Your Coins Can Be Stolen in Under 10 Minutes

This series previously explored the physics behind quantum computing. Here, we delve into the specifics of how a quantum computer can be used to compromise bitcoin's security. To understand the threat, it's essential to grasp how bitcoin's encryption works and where its weaknesses lie. Bitcoin relies on elliptic curve cryptography, which uses a one-way function to derive a public key from a private key. This function is virtually impossible for classical computers to reverse, but a quantum algorithm known as Shor's algorithm can break it. Shor's algorithm exploits the properties of quantum mechanics to find the period of a function, which is essential for deriving the private key. The recent paper by Google's Quantum AI division has significantly reduced the estimated number of qubits required to run Shor's algorithm against bitcoin's elliptic curve, from millions to fewer than 500,000. The team designed two quantum circuits that can implement Shor's algorithm, one using approximately 1,200 logical qubits and the other using approximately 1,450 logical qubits. The attack scenario presented in the paper introduces a new threat, where a quantum computer can precompute parts of the algorithm and then finish the calculation in approximately nine minutes once a target public key appears. This timing is critical, as it coincides with bitcoin's average block confirmation time, giving the attacker a roughly 41% chance of succeeding. The bigger concern, however, is the 6.9 million bitcoin that are already vulnerable to an 'at-rest' attack, as their public keys have been permanently exposed on the blockchain.