Time is Running Out for Bitcoin to Mitigate Quantum Computing Threat

Not all aspects of bitcoin are vulnerable to quantum computers. The process of bitcoin mining, which utilizes a type of mathematics known as hashing, is resistant to quantum computing attacks. The blockchain ledger and the rule that new bitcoins can only be created through mining would remain intact in the event of a quantum attack. However, ownership of bitcoins is a different story. Bitcoin wallets rely on a specific type of mathematics that converts a private key into a public address. This math is easily reversible in one direction but not the other, and it is the only thing preventing unauthorized parties from spending someone else's coins. A quantum algorithm known as Shor's algorithm can bypass this security measure, and a recent paper by Google demonstrated that this attack could be carried out with fewer resources than previously thought. This article explores the potential risks and the response of the bitcoin community to this threat. Approximately 6.9 million bitcoins, or about one-third of all mined coins, are stored in wallets with publicly visible keys, making them vulnerable to quantum attacks. This includes early bitcoins from the network's first years, which were stored in an address format that published the public key by default, as well as any wallet that has ever been spent from, as spending reveals the key for any remaining balance. A quantum attacker would not need to compete with ongoing transactions but could instead work through the wallets with exposed keys at their own pace. Bitcoin's pseudonymous creator, Satoshi Nakamoto, holds approximately 1 million bitcoins that are now at risk. The 2021 Taproot upgrade inadvertently expanded the problem by making any bitcoin spent since its activation publish the key protecting the remaining balance at that address. While the quantum threat has sparked intense debate in recent months, and other blockchains are taking action, the bitcoin community has yet to propose a concrete solution. Ethereum, a major competitor to bitcoin, has had a formal quantum-resistant program in place since 2018 and has made significant progress in migrating its security to quantum-resistant mathematics. In contrast, bitcoin's development culture treats any centralized authority as a potential failure point, and its social consensus holds that changes to the protocol should be rare and difficult. This makes it challenging for the network to coordinate a response to the quantum threat. Several proposals have been put forward, including the addition of new quantum-safe address types and the implementation of a detection system to trigger defensive action in the event of a quantum attack. However, these proposals have yet to gain broad support from bitcoin's core developers. The coordination problem is the biggest challenge in implementing effective solutions against the quantum threat. Bitcoin's migration is harder than Ethereum's due to its lack of a central authority and governance process. The network's development culture has kept it stable for nearly two decades but also makes it structurally harder to solve the quantum problem. Migrating the 6.9 million exposed coins requires decisions that the network has spent years avoiding. The question of what happens next is a pressing one, and the answer will depend on whether the bitcoin community can coordinate a response to the quantum threat before it's too late.