Time is Running Out for Bitcoin to Counter Quantum Computing Threat
Not all aspects of bitcoin are vulnerable to quantum computers. The process of bitcoin mining, which involves adding new blocks to the blockchain, utilizes a type of mathematical operation called hashing that quantum computers are unable to break. As a result, the blockchain itself and the rule that new bitcoins can only be created through mining would remain intact in the event of a quantum attack. New blocks would continue to be produced, and the chain would remain operational. However, ownership of bitcoins would be at risk. Bitcoin wallets rely on a different type of mathematical operation that converts a private key into a public address. This operation is easy to perform in one direction but extremely difficult to reverse, which is what currently prevents unauthorized individuals from spending someone else's coins. In the first part of this series on quantum computing, we explored the underlying physics. A quantum computer is fundamentally different from a classical computer, operating at extremely low temperatures and small scales where particles exhibit unique behaviors. The second part examined the implications of quantum computing for bitcoin. Bitcoin wallets depend on a one-way mathematical problem that takes milliseconds to solve in one direction but would take a classical computer longer than the age of the universe to solve in the other direction. However, a quantum algorithm known as Shor's algorithm can collapse this time gap. A recent paper by Google demonstrated that such an attack could be carried out with far fewer resources than previously estimated, and within a time frame that competes with bitcoin's block times. This final piece in the series focuses on the response to this threat. We will discuss what is at risk, what bitcoin has done so far, and whether a network designed to resist coordinated change can implement the largest security upgrade in its history before quantum computers become a reality. The pool of vulnerable bitcoins is substantial, with approximately 6.9 million coins, or about one-third of all mined bitcoins, stored in wallets whose public keys are already visible on the blockchain. This includes early bitcoins from the network's first years, which were stored in an address format that published the public key by default, as well as any wallet that has ever been spent from, as spending reveals the key for any remaining balance. A quantum attacker would not need to compete with ongoing transactions but could instead work through the wallets with exposed keys at their own pace. This includes the approximately 1 million bitcoins held by bitcoin's pseudonymous creator, Satoshi Nakamoto, which have remained untouched since the network's early days and are now at risk. The 2021 Taproot upgrade inadvertently expanded the problem. Taproot is a change to how bitcoin addresses work, intended to make transactions more efficient and private. However, as a side effect, any bitcoin spent since Taproot's activation has published the key protecting the remaining balance at that address. While this was a reasonable trade-off at the time, given the perceived longer timeline for quantum computing, it has now become a more pressing issue. Several proposals are being discussed to address the quantum threat, but nothing concrete has emerged from bitcoin developers yet. In contrast, Ethereum, one of bitcoin's major competitors, has had a formal quantum-resistant program in place since 2018. The Ethereum Foundation has four teams working full-time on the migration, with multiple independent developer groups testing networks weekly. Ethereum has a clear plan to upgrade its security to quantum-resistant mathematics across four upcoming network-wide changes and has even launched a dedicated website to track progress. Bitcoin, on the other hand, lacks a comparable strategy. There are efforts underway to solve the problem, including a formal proposal known as BIP-360, which would introduce new quantum-safe address types that holders could migrate to voluntarily. Another proposal from BitMEX Research suggests implementing a detection system that would trigger defensive actions if a quantum attack is observed on the network. However, neither proposal has gained broad support from bitcoin's core developers, and they address different aspects of the problem. The challenge in implementing effective solutions against the quantum threat is significant, primarily due to bitcoin's governance structure. Bitcoin's development culture is designed to treat any central authority as a potential failure point, and its social consensus favors rare and difficult changes to the protocol. While this has kept the network stable for nearly two decades, it also makes addressing the quantum problem more difficult. Migrating the 6.9 million exposed coins requires making decisions that the network has historically avoided. Questions include whether old address formats should be frozen after a certain date to protect coins from future theft, whether exposed coins should be allowed to move to new quantum-safe addresses using their original keys, and what happens to coins whose owners cannot or will not migrate. The coins held by Satoshi Nakamoto are a stark example of the dilemma. Freezing old formats would protect the coins from theft but make them permanently inaccessible, including to Satoshi. Leaving the old formats open means those coins remain a target for whoever first develops a working quantum computer. Setting a migration deadline would force Satoshi to either move the coins, revealing their ownership, or lose them. Every option changes bitcoin's character in ways the network has historically resisted. The Google paper frames the industry's current stance, suggesting that a successful attack on bitcoin's mathematics should not be seen as a wake-up call to adopt post-quantum cryptography but rather as a potential signal that the adoption of such cryptography has already failed. This implies that by the time the threat becomes apparent, it may already be too late to respond. Developers are now faced with the question of whether a network built to resist coordinated change can coordinate the largest security upgrade in its history before quantum computers become a reality. Ethereum's eight-year head start in addressing quantum resistance suggests that starting now is the correct approach. However, bitcoin's governance culture indicates that the network may wait until the threat is demonstrated before taking action. Only one of these approaches will be effective if the timeline for quantum computing turns out to be shorter than optimists predict.