Bitcoin's Quantum Conundrum: A Race Against Time to Safeguard 6.9 Million Coins
While not all aspects of bitcoin are vulnerable to quantum attacks, the ownership of coins is at risk due to the type of mathematics used to secure wallets. A quantum computer can potentially break this math, allowing an attacker to access and drain wallets. Approximately 6.9 million bitcoin, including those held by the cryptocurrency's pseudonymous creator Satoshi Nakamoto, are exposed due to their public keys being visible on the blockchain. The recent Taproot upgrade has further expanded the problem, as any bitcoin spent since its activation has published the key protecting the remaining coins at that address. Although the quantum threat has sparked intense debate, bitcoin developers have yet to propose a concrete solution. In contrast, Ethereum has had a formal quantum-resistant program in place since 2018 and is actively working on migrating its security to quantum-resistant math. Various proposals have been put forth for bitcoin, including the introduction of new quantum-safe address types and a detection system to trigger defensive action in case of a quantum attack. However, these proposals lack broad support from core developers and only address part of the problem. The lack of a centralized authority and a governance process that favors rare and hard changes to the protocol makes it challenging for bitcoin to coordinate an effective response to the quantum threat. The network's development culture, which treats central authority as a failure mode, has kept the network stable for nearly two decades but now poses a significant obstacle in addressing the quantum problem. The migration of the exposed coins requires decisions that the network has historically avoided, such as freezing old address formats or allowing exposed coins to move to new quantum-safe addresses. The fate of Satoshi's coins serves as a prime example of the challenges posed by the quantum threat, as any solution would necessitate changes to bitcoin's character that the network has refused to make. Ultimately, the question remains whether the bitcoin network can coordinate the necessary security upgrades before the threat becomes a reality, or if it will wait until the threat is demonstrated, by which time it may be too late.