Time is Running Out for Bitcoin to Counter Quantum Threat, Putting 6.9 Million BTC at Risk

Not all aspects of bitcoin are vulnerable to quantum computers. The process of bitcoin mining, which involves adding new blocks to the blockchain, relies on a type of mathematics known as hashing that quantum computers are unable to break. As a result, the blockchain itself and the rule that new bitcoins can only be created through mining would remain intact in the event of a quantum attack. New blocks would continue to be produced, and the chain would remain operational. However, ownership would be severely compromised. Bitcoin wallets are secured by a different type of mathematics that converts a private key into a public address that can be seen by anyone. This math works effortlessly in one direction but not at all in the other, and it is the sole barrier preventing a stranger from spending your coins. The first part of this series on quantum computing delved into the physics behind it, explaining how a quantum computer is fundamentally different from a regular computer, starting with a very cold, very small metal loop where particles exhibit behaviors not seen elsewhere on Earth. The second part explored what happens when a quantum computer is directed at bitcoin. Bitcoin wallets rely on a one-way mathematical problem. Converting a private key into a public address takes milliseconds, but reversing the process, from public address back to private key, would take a regular computer longer than the age of the universe. A quantum algorithm known as Shor's algorithm reduces this gap. A recent paper by Google demonstrated that the attack could be executed with significantly fewer resources than previously estimated, within a timeframe that competes with bitcoin's block times. This final piece in the series focuses on the response. It examines what is actually at risk, the measures bitcoin has taken, and whether a network designed to resist coordinated change can implement the largest security upgrade in its history before the relevant hardware becomes available. The pool of exposed bitcoin is substantial, with approximately 6.9 million bitcoin, or about one-third of all mined bitcoin, stored in wallets whose public keys are permanently visible on the blockchain. This includes early bitcoin from the network's first years, which was stored in an address format that published the public key by default, as well as any wallet that has ever been spent from, because spending reveals the key for any remaining balance. A quantum attacker would not need to compete with an ongoing transaction; instead, they could work through wallets with exposed keys at their own pace, one by one. Bitcoin's pseudonymous creator, Satoshi Nakamoto, holds roughly 1 million bitcoin that have remained untouched since the network's early days and are now classified as exposed. The 2021 Taproot upgrade expanded the problem. Taproot is a modification to how bitcoin addresses function, intended to make transactions more efficient and private. A side effect was that any bitcoin spent after Taproot's activation has published the key protecting the remaining balance at that address. This was not an error but a reasonable trade-off at the time, given that quantum timelines appeared much longer than they do now. Several efforts are underway to address the quantum threat. Ethereum, which can be considered one of Bitcoin's largest competitors among institutional investors in the crypto market, has had a formal quantum-resistant program in place since 2018. The Ethereum Foundation operates four teams that work on the migration full-time, with more than ten independent developer groups releasing weekly test networks. The plan outlines specific upgrades across four upcoming network-wide changes, transitioning Ethereum's security to new mathematics that quantum computers cannot break. It has even launched a dedicated website, pq.ethereum.org, to publish its progress. Bitcoin, on the other hand, lacks a comparable strategy. This does not mean there are no efforts to solve the problem. One formal proposal, BIP-360, from a group of developers and researchers, suggests adding new quantum-safe address types that holders could voluntarily migrate to. A competing proposal from BitMEX Research would implement a detection system that triggers defensive action if a quantum attack is observed on the network. However, neither proposal has broad support from bitcoin's core developers, and they address different parts of the problem. Nic Carter, a prominent bitcoin advocate, has highlighted the issue in recent months. "Elliptic curve cryptography is on the verge of becoming obsolete," Carter wrote on X, referring to the mathematics that secures bitcoin wallets. He described Ethereum's approach as "best in class" and bitcoin's as "worst in class," citing developers who "deny, gaslight, gatekeep, and bury their heads in the sand" rather than engage with the problem. Adam Back, the CEO of Blockstream and a prominent early contributor to bitcoin, disagrees on the urgency but agrees on the direction. "Quantum computing still has a lot to prove. Current systems are essentially lab experiments," Back said at a conference earlier this month. However, he also stated that bitcoin should prepare now by building optional upgrades in advance, allowing the network to migrate when necessary, rather than scrambling during a crisis. The biggest challenge in implementing effective solutions against Bitcoin's quantum threat lies in coordination. Bitcoin's migration is more difficult than Ethereum's for reasons unrelated to the actual mathematics. Ethereum has a foundation that funds engineering work and a governance process that regularly passes major upgrades. Bitcoin has neither, and its development culture views any central authority as a failure mode. The network's social consensus holds that changes to the protocol should be rare and difficult. These principles have kept the network stable for nearly two decades but also make the quantum problem structurally harder for bitcoin to solve. Migrating the 6.9 million exposed coins requires decisions that the network has spent twenty years avoiding. Questions arise about whether old address formats should be frozen after a certain date to protect coins from future theft, whether exposed coins should be allowed to move to new quantum-safe addresses using their original keys, and what happens to coins whose owners cannot or will not migrate. Satoshi's coins are the most striking example. Freezing old formats protects the coins from theft but makes them permanently inaccessible, including to Satoshi. Leaving the old formats open means those coins remain a standing prize for whoever builds the first working quantum computer or has access to a quantum computer and wishes to attack. Setting a migration deadline forces Satoshi to either move the coins, revealing their ownership, or lose them. Every option changes bitcoin's character in ways the network has historically refused to change. The Google paper's framing is a summary of the industry's current stance. A successful attack on the mathematics bitcoin uses "should not be seen as a wake-up call to adopt post-quantum cryptography as much as a potential signal that PQC adoption has already failed." This implies that by the time the threat becomes visible, the window to respond may already have closed. Developers now face the question of whether a network built to resist coordinated change can coordinate the largest security upgrade in its history before the hardware catches up to the theory. Ethereum's eight-year head start suggests the correct answer is to start now. Bitcoin's governance culture suggests the likely answer is to wait until the threat is demonstrated, then move. Only one of those answers works if the timeline turns out to be shorter than the optimists' estimate.