Time is Running Out for Bitcoin to Counter Quantum Threat, Putting 6.9 Million BTC at Risk

Not all aspects of bitcoin are vulnerable to quantum computer attacks. The process of bitcoin mining, which involves adding new blocks to the blockchain, utilizes a type of mathematics known as hashing that quantum computers are unable to break. As a result, the bitcoin ledger and the rule that new bitcoins can only be created through mining would remain intact in the event of a quantum attack. However, ownership of bitcoins is a different story. Bitcoin wallets are secured by a distinct type of mathematics that converts a private key into a public address. This math is straightforward in one direction but virtually impossible in the other, and it is the sole barrier preventing unauthorized individuals from spending someone else's coins. A quantum algorithm known as Shor's algorithm can bypass this security measure, and a recent paper by Google demonstrated that such an attack could be carried out with significantly fewer resources than previously thought. This article, the final installment in a series on the subject, examines the potential consequences of a quantum attack on bitcoin and the measures being taken to mitigate this risk. Approximately 6.9 million bitcoins, equivalent to one-third of all bitcoins ever mined, are stored in wallets whose public keys are already visible on the blockchain. This includes early bitcoins from the network's inaugural years, which were stored in an address format that publicly disclosed the public key by default, as well as any wallet that has been used for a transaction, as spending reveals the key for the remaining balance. A quantum attacker would not need to compete with an ongoing transaction but could instead systematically target wallets with exposed keys at their leisure. Bitcoin's pseudonymous creator, Satoshi Nakamoto, holds around 1 million bitcoins that have remained untouched since the network's early days and are now categorized as exposed. The 2021 Taproot upgrade inadvertently expanded the problem by making bitcoin addresses more efficient and private. As a result, any bitcoin spent since the Taproot activation has publicly disclosed the key protecting the remaining balance at that address. Although this was not an error, it was a reasonable trade-off at the time, given that quantum timelines appeared longer than they do now. Currently, there are no concrete plans from bitcoin developers to address the quantum threat, whereas other blockchains, such as Ethereum, have been preparing for this eventuality since 2018. Ethereum has a formal quantum-resistant program, with four full-time teams working on the migration and multiple independent developer groups testing networks on a weekly basis. In contrast, bitcoin lacks a comparable strategy. There are proposals, such as BIP-360, which would introduce new quantum-safe address types, and a competing proposal from BitMEX Research that would implement a detection system to trigger defensive measures in the event of a quantum attack. However, neither proposal has garnered broad support from bitcoin's core developers, and they address different aspects of the problem. The lack of a coordinated response to the quantum threat poses a significant challenge for bitcoin, given its decentralized nature and reluctance to implement changes. The biggest obstacle in implementing effective solutions is not the mathematical aspect but rather the coordination problem. Bitcoin's development culture is centered around avoiding central authority and treating changes to the protocol as rare and difficult. This approach has maintained the network's stability for nearly two decades but also makes it structurally harder for bitcoin to address the quantum problem. Migrating the 6.9 million exposed coins requires decisions that the network has avoided for twenty years. The question of what happens next is crucial, as the window to respond may already have closed by the time the threat becomes apparent. Developers are faced with the question of whether a network built to resist coordinated change can coordinate the biggest security upgrade in its history before the hardware catches up to the theory.