Time Is Running Out for Bitcoin to Mitigate Quantum Computing Threat

Not all aspects of bitcoin are vulnerable to quantum computers. The process of bitcoin mining, which involves adding new blocks to the blockchain, utilizes a type of mathematics known as hashing that quantum computers are unable to breach. The blockchain itself and the rule that new bitcoins can only be created through mining would withstand a quantum attack. However, ownership of bitcoins is at risk. Bitcoin wallets are secured by a different type of mathematics that converts a private key into a public address. This math works in one direction but is impractical to reverse, which prevents unauthorized individuals from spending coins. A quantum algorithm known as Shor's algorithm can reverse this process. Google's recent paper demonstrated that this attack can be executed with fewer resources than previously estimated, and within a timeframe that competes with bitcoin's block creation. This article explores the potential consequences and the response of the bitcoin community to this threat. Approximately 6.9 million bitcoins, equivalent to one-third of all mined bitcoins, are stored in wallets whose public keys are visible on the blockchain. A quantum attacker could target these wallets at their own pace. Bitcoin's pseudonymous creator, Satoshi Nakamoto, holds around 1 million bitcoins that are also vulnerable. The 2021 Taproot upgrade inadvertently increased the problem by publishing the key protecting remaining bitcoins at an address after a transaction. While there is no concrete plan from bitcoin developers to address this issue, other blockchains like Ethereum have been working on quantum-resistant solutions since 2018. Ethereum has a formal program with multiple teams and independent developer groups working on the migration. Bitcoin has proposals like BIP-360 and a detection system from BitMEX Research, but they lack broad support and only address part of the problem. The lack of a central authority and governance process in bitcoin makes it harder to implement solutions. The network's development culture prioritizes stability and treats central authority as a failure mode, making it challenging to coordinate a significant security upgrade. Migrating the exposed coins requires decisions that the network has avoided for twenty years, such as freezing old address formats or allowing exposed coins to move to new quantum-safe addresses. Every option changes bitcoin's character in ways the network has historically refused to change. The future of bitcoin's security depends on whether the network can coordinate a massive security upgrade before the threat becomes a reality.