Time Runs Out for Bitcoin to Mitigate Quantum Threat, Putting 6.9 Million BTC at Risk, Including Satoshi's Holdings
Not all aspects of bitcoin are vulnerable to quantum computers. The process of bitcoin mining, which involves adding new blocks to the blockchain, utilizes a type of mathematics known as hashing that quantum computers are unable to compromise. The blockchain itself and the rule that new bitcoins can only be created through mining would endure a quantum attack, with blocks continuing to be produced and the chain remaining operational. However, ownership would be severely impacted. Bitcoin wallets are secured by a different form of mathematics that converts a private key into a public address visible to everyone. This mathematics functions effortlessly in one direction but is impractical in the other, which is the sole barrier preventing unauthorized individuals from spending your coins. A significant portion of bitcoin, approximately 6.9 million, is stored in wallets with publicly visible keys, making them susceptible to quantum attacks. This includes early bitcoin from the network's inception, stored in an address format that publicly disclosed the public key by default, as well as any wallet that has been spent from, as spending reveals the key for any remaining balance. A quantum attacker would not need to compete against an ongoing transaction but could instead work through the wallets with exposed keys at their own pace. Bitcoin's pseudonymous creator, Satoshi Nakamoto, holds roughly 1 million bitcoin that have remained untouched since the network's early days and now falls into the exposed category. The 2021 Taproot upgrade inadvertently expanded the issue. Taproot is a modification to how bitcoin addresses function, intended to make transactions more efficient and private. An unintended consequence was that any bitcoin spent since Taproot's activation has published the key protecting the remaining balance at that address. While the quantum threat has sparked intense debate in recent months, and other blockchains are preparing, bitcoin developers have yet to propose a concrete plan. Ethereum, a major competitor, has had a formal quantum-resistant program in place since 2018, with four teams working full-time on the migration and multiple independent developer groups releasing weekly test networks. Bitcoin, on the other hand, lacks a equivalent strategy. There are efforts to address the issue, including a formal proposal known as BIP-360, which would introduce new quantum-safe address types that holders could voluntarily migrate to. Another proposal from BitMEX Research suggests implementing a detection system that triggers defensive action if a quantum attack is observed on the network. However, neither proposal has garnered broad support from bitcoin's core developers, and they address different aspects of the problem. The biggest challenge in implementing effective solutions against the quantum threat lies in bitcoin's governance structure. The network's development culture is averse to centralized authority, and its social consensus dictates that changes to the protocol should be rare and difficult. This has kept the network stable for nearly two decades but also makes addressing the quantum problem structurally harder for bitcoin. Migrating the 6.9 million exposed coins requires decisions that the network has spent years avoiding. The question remains whether a network built to resist coordinated change can coordinate the largest security upgrade in its history before the threat becomes a reality.