Time's Running Out for Bitcoin to Counter Quantum Threat

Not all aspects of bitcoin are vulnerable to quantum computers. The process of bitcoin mining, which involves adding new blocks to the blockchain, utilizes a type of mathematics known as hashing that quantum computers cannot effectively breach. The blockchain itself and the rule that new bitcoins can only be created through mining would withstand a quantum attack. However, ownership is a different matter. Bitcoin wallets rely on a distinct type of mathematics that converts a secret private key into a public address that anyone can see. This mathematics works seamlessly in one direction but not the other, which is the sole factor preventing strangers from spending your coins. A quantum algorithm known as Shor's collapses this gap, and a recent paper by Google demonstrated that the attack could be executed with far fewer resources than previously estimated. This article explores the potential risks and the response of the bitcoin community to this threat. Approximately 6.9 million bitcoins, equivalent to one-third of all mined bitcoins, are stored in wallets whose public keys are permanently visible on the blockchain. A quantum attacker would not need to compete with ongoing transactions but could instead work through the wallets with exposed keys at their own pace. Bitcoin's pseudonymous creator, Satoshi Nakamoto, holds roughly 1 million bitcoins that have remained untouched since the network's early days and are now at risk. The 2021 Taproot upgrade inadvertently expanded the problem by making any spent bitcoins publish the key protecting the remaining balance at that address. While there is ongoing debate among bitcoin developers, no concrete plan has emerged to address the quantum threat. In contrast, Ethereum has had a formal quantum-resistant program in place since 2018 and is actively working on migrating its security to new mathematics that quantum computers cannot break. Bitcoin developers have proposed various solutions, including the introduction of new quantum-safe address types and a detection system to trigger defensive action in the event of a quantum attack. However, these proposals lack broad support from the core development team, and the community is divided on the best course of action. The lack of a centralized authority and a governance process makes it challenging for bitcoin to coordinate a unified response to the quantum threat. The migration of the 6.9 million exposed coins requires decisions that the network has historically avoided, such as freezing old address formats or allowing exposed coins to move to new quantum-safe addresses. The fate of Satoshi's coins is a prime example of the dilemma, as freezing old formats would protect the coins but make them permanently inaccessible, including to Satoshi. Setting a migration deadline would force Satoshi to either move the coins, revealing their ownership, or lose them. The future of bitcoin hangs in the balance, and the community must decide whether to start working on a solution now or wait until the threat becomes more apparent.