Time Is Running Out for Bitcoin to Counter Quantum Computing Threats, With 6.9 Million BTC at Risk
While not all aspects of bitcoin are vulnerable to quantum computers, a significant portion is at risk. The process of bitcoin mining, which utilizes a type of mathematics known as hashing, is secure against quantum attacks. However, the ownership of bitcoins, which relies on a different mathematical concept that converts a private key into a public address, is susceptible to quantum threats. A quantum algorithm known as Shor's can potentially breach this security. Recent research by Google has shown that such an attack could be executed with fewer resources than previously thought, posing a significant threat to the security of the bitcoin network. Approximately 6.9 million bitcoins, equivalent to one-third of all mined bitcoins, are at risk due to their public keys being visible on the blockchain. This includes early bitcoins stored in address formats that published public keys by default, as well as wallets that have been spent from, thereby revealing their keys. The 2021 Taproot upgrade has further exacerbated the issue by publishing keys for any bitcoin spent since its activation. While the quantum threat has sparked intense debate, concrete solutions from bitcoin developers are still pending. In contrast, Ethereum has had a formal quantum-resistant program in place since 2018 and is actively working on migrating its security to quantum-resistant mathematics. Bitcoin's lack of a centralized authority and governance process makes implementing solutions more challenging. Proposals such as BIP-360 and a detection system by BitMEX Research have been put forth but lack broad support from core developers. The coordination problem stems from bitcoin's development culture, which treats central authority as a failure mode and emphasizes rare and difficult protocol changes. Migrating the exposed coins requires making decisions that the network has historically avoided, such as freezing old address formats or allowing exposed coins to move to new quantum-safe addresses. The sharpest example is Satoshi's coins, which pose a significant dilemma. Setting a migration deadline would force Satoshi to either move the coins, revealing ownership, or lose them. Every option would change bitcoin's character in ways the network has refused to change. The Google paper frames the situation as a potential signal that post-quantum cryptography adoption may have already failed by the time a successful attack occurs. Developers are left with the question of whether a network built to resist coordinated change can coordinate the biggest security upgrade in its history before the threat becomes imminent. Ethereum's head start suggests the importance of starting now, while bitcoin's governance culture may lead to waiting until the threat is demonstrated.