Time Running Out for Bitcoin to Counter Quantum Threat, 6.9 Million BTC at Risk
Not all aspects of bitcoin are vulnerable to quantum computer attacks. The process of bitcoin mining, which involves adding new blocks to the blockchain, relies on a type of mathematics called hashing that quantum computers are unable to break. As a result, the ledger and the rule that new bitcoins can only be created through mining would remain intact in the event of a quantum attack. However, ownership of bitcoins would be at risk. Bitcoin wallets are secured by a different type of mathematics that converts a private key into a public address. This math works in one direction but not the other, preventing unauthorized access to coins. A quantum algorithm known as Shor's algorithm can bypass this security measure. Google recently published a paper demonstrating that this attack can be executed with fewer resources than previously thought, and within a time frame that competes with bitcoin's block times. This article, the final part of a series, explores the potential consequences and bitcoin's response to this threat. Approximately 6.9 million bitcoins, roughly one-third of all mined bitcoins, are stored in wallets with publicly visible keys, making them vulnerable to quantum attacks. This includes early bitcoins and any wallet that has been used for a transaction, as spending reveals the key. A quantum attacker wouldn't need to rush, as they could systematically target these wallets at their own pace. Bitcoin's creator, Satoshi Nakamoto, holds about 1 million bitcoins that are also at risk. The 2021 Taproot upgrade inadvertently expanded the problem by making bitcoin addresses more efficient and private, but also publishing the key protecting any remaining balance at an address. While there is ongoing debate among bitcoin developers, no concrete plan has emerged to address the quantum threat. In contrast, Ethereum has a formal quantum-resistant program in place since 2018, with multiple teams working on the migration to quantum-resistant cryptography. Bitcoin has proposals like BIP-360, which suggests adding new quantum-safe address types, and a competing proposal from BitMEX Research for a detection system to trigger defensive actions in case of a quantum attack. However, neither proposal has gained broad support from core developers. The lack of a coordinated response is largely due to bitcoin's governance structure, which is designed to resist centralized changes. This makes implementing effective solutions against the quantum threat more challenging. The biggest hurdle is deciding how to migrate the 6.9 million exposed coins without compromising bitcoin's core principles. Options include freezing old address formats, allowing exposed coins to move to new quantum-safe addresses, or setting a migration deadline. Each option has significant implications for bitcoin's character and stability. The outcome depends on whether the network can coordinate a major security upgrade before the threat becomes reality.