Bitcoin's Quantum Conundrum: Can the Network Mitigate the Looming Threat?

Not all aspects of bitcoin are vulnerable to quantum computing. The process of bitcoin mining, which involves adding new blocks to the blockchain, utilizes a form of mathematics known as hashing that quantum computers are unable to effectively breach. The blockchain itself, along with the rule that new bitcoins can only be created through mining, would remain intact in the face of a quantum attack. However, what would be compromised is ownership. Bitcoin wallets rely on a different type of mathematics that converts a private key into a public address. This mathematics is straightforward in one direction but virtually impossible in the other, and it is the sole barrier preventing unauthorized individuals from spending someone else's coins. A quantum algorithm known as Shor's algorithm bridges this gap, and a recent paper by Google demonstrated that such an attack could be executed with fewer resources than previously estimated, within a window that competes with bitcoin's block times. This article, the final installment in a series, examines the response to this threat, including what is at risk, the measures bitcoin has taken, and whether a network designed to resist coordinated change can implement the most significant security upgrade in its history before the advent of quantum hardware. The pool of exposed bitcoin is substantial, with approximately 6.9 million coins, or about one-third of all mined bitcoin, stored in wallets whose public keys are permanently visible on the blockchain. This includes early bitcoin from the network's inaugural years, which was stored in an address format that published the public key by default, as well as any wallet that has been spent from, as spending reveals the key for the remaining balance. A quantum attacker would not need to compete with an ongoing transaction; instead, they could methodically work through wallets with exposed keys at their own pace. Bitcoin's pseudonymous creator, Satoshi Nakamoto, holds roughly 1 million bitcoin, which has remained untouched since the network's early days and now falls into the exposed category. The 2021 Taproot upgrade inadvertently expanded the problem by changing how bitcoin addresses function, with the intention of making transactions more efficient and private. A side effect of this upgrade was that any bitcoin spent since its activation has published the key protecting the remaining balance at that address. While this was not an error, it was a reasonable trade-off at the time, given that quantum timelines appeared much longer than they do now. Currently, there are efforts underway to address the quantum threat, although nothing concrete has emerged from bitcoin developers yet. Ethereum, one of bitcoin's largest competitors among institutional investors, has had a formal quantum-resistant program in place since 2018. The Ethereum Foundation operates four teams that work on the migration full-time, with over ten independent developer groups releasing weekly test networks. The plan involves specific upgrades across four upcoming network-wide changes, migrating Ethereum's security to new mathematics that quantum computers cannot breach. In contrast, bitcoin lacks a comparable strategy. There are, however, formal proposals aimed at solving the issue, such as BIP-360, which would introduce new quantum-safe address types that holders could voluntarily migrate to, and a competing proposal from BitMEX Research that would implement a detection system triggering defensive action if a quantum attack is observed on the network. Neither proposal has garnered broad support from bitcoin's core developers, and they address different aspects of the problem. Nic Carter, a prominent bitcoin advocate, has highlighted the issue, stating that the mathematics securing bitcoin wallets is on the verge of obsolescence and describing Ethereum's approach as 'best in class' and bitcoin's as 'worst in class.' Adam Back, the CEO of Blockstream and an early bitcoin contributor, disagrees on the urgency but concurs on the direction, suggesting that bitcoin should prepare now by incorporating optional upgrades in advance, allowing the network to migrate when necessary rather than reacting in a crisis. The biggest challenge in implementing effective solutions against bitcoin's quantum threat lies in coordination. Bitcoin's migration is more complex than Ethereum's due to reasons unrelated to the mathematics itself. Ethereum has a foundation that funds engineering work and a governance process that regularly passes major upgrades, whereas bitcoin has neither. Its development culture views any central authority as a failure mode, and its social consensus holds that changes to the protocol should be rare and difficult. These principles have maintained the network's stability for nearly two decades but also make the quantum problem structurally harder for bitcoin to solve. Migrating the 6.9 million exposed coins requires decisions that the network has spent twenty years avoiding. The Google paper's framing serves as a summary of the industry's current stance, suggesting that a successful attack on bitcoin's mathematics should not be seen as a wake-up call to adopt post-quantum cryptography but rather as a potential signal that the adoption of post-quantum cryptography has already failed. This implies that by the time the threat becomes apparent, the window to respond may already have closed. Developers are now faced with the question of whether a network designed to resist coordinated change can coordinate the most significant security upgrade in its history before the hardware catches up to the theory. Ethereum's eight-year head start suggests that the correct approach is to start now, while bitcoin's governance culture indicates that the likely response is to wait until the threat is demonstrated before taking action. Only one of these approaches will be effective if the timeline proves shorter than the optimists' estimate.