Bitcoin's Quantum Conundrum: A Race Against Time to Protect 6.9 Million Coins

Not all aspects of bitcoin are vulnerable to quantum computer attacks. The process of mining, which involves adding new blocks to the blockchain, utilizes a type of mathematics known as hashing that quantum computers cannot effectively breach. The ledger and the rule that new bitcoins can only be created through mining would endure a quantum attack, with blocks continuing to be produced and the chain remaining intact. However, ownership is a different matter. Bitcoin wallets rely on a distinct mathematical approach that converts a private key into a public address. This math functions effortlessly in one direction but is impractical in the other, and it is the sole barrier preventing unauthorized individuals from spending coins. A quantum algorithm known as Shor's collapses this gap, and a recent paper by Google demonstrated that the attack could be executed with fewer resources than previously estimated, within a timeframe that competes with bitcoin's block times. This article, the final in a series, explores the response to this threat, including what is at risk, the measures bitcoin has taken, and whether the network can coordinate the largest security upgrade in its history before the threat materializes. Approximately 6.9 million bitcoins, roughly one-third of all mined coins, are stored in wallets with publicly visible keys, making them susceptible to quantum attacks. This includes early bitcoins and any wallet that has been spent from, as spending reveals the key. The 2021 Taproot upgrade inadvertently expanded the problem by publishing the key protecting remaining coins at an address after a transaction. While the quantum threat has sparked intense debate, concrete plans from bitcoin developers are yet to emerge. In contrast, Ethereum has had a formal quantum-resistant program since 2018, with four teams working full-time on the migration and a dedicated website to track progress. Bitcoin has no equivalent strategy, although proposals like BIP-360 and a detection system from BitMEX Research have been put forth. However, these proposals lack broad support from core developers and address different aspects of the problem. The lack of a central authority and a governance process that favors rare and difficult changes makes implementing effective solutions challenging for bitcoin. Migrating the exposed coins requires decisions that the network has historically avoided, such as freezing old address formats or allowing exposed coins to move to new quantum-safe addresses. The future of bitcoin's security hangs in the balance, with the question of whether the network can coordinate a significant upgrade before the threat materializes.