Time Running Out for Bitcoin to Mitigate Quantum Threat, 6.9 Million BTC at Risk
Not all aspects of Bitcoin are vulnerable to quantum computers. The process of adding new blocks to the blockchain, known as mining, uses a type of mathematics called hashing that is resistant to quantum attacks. The blockchain itself and the rule that new Bitcoins can only be created through mining would remain intact in the event of a quantum attack. However, ownership of Bitcoins is a different matter. Bitcoin wallets are secured by a type of mathematics that converts a private key into a public address. This math works in one direction but not the other, preventing unauthorized access to funds. A quantum algorithm known as Shor's algorithm can potentially break this math, posing a significant threat to Bitcoin ownership. Approximately 6.9 million Bitcoins, or about one-third of all Bitcoins ever mined, are at risk due to exposed public keys. This includes early Bitcoins stored in addresses that published public keys by default, as well as any wallet that has been spent from, as spending reveals the key. Bitcoin's pseudonymous creator, Satoshi Nakamoto, holds around 1 million Bitcoins that are also at risk. The 2021 Taproot upgrade inadvertently expanded the problem by publishing keys for any Bitcoin spent since its activation. While there are ongoing efforts to address the quantum threat, no concrete plan has emerged from Bitcoin developers yet. In contrast, Ethereum has had a formal quantum-resistant program in place since 2018 and is working towards migrating its security to quantum-resistant math. Bitcoin's decentralized governance structure makes it challenging to implement a coordinated response to the quantum threat. The lack of a central authority and a governance process that favors rare and difficult changes to the protocol makes it harder for Bitcoin to adapt to the quantum threat. Migrating the 6.9 million exposed coins requires decisions that the network has historically avoided, such as freezing old address formats or allowing exposed coins to move to new quantum-safe addresses. The window to respond to the quantum threat may be shorter than expected, and the industry is watching to see how Bitcoin will address this significant challenge.