Time Running Out for Bitcoin to Counter Quantum Threat, Putting 6.9 Million BTC at Risk
Not all aspects of bitcoin are vulnerable to quantum computer attacks. The process of bitcoin mining, which involves a type of math known as hashing, is secure against quantum computers. This means the blockchain ledger and the rule that new bitcoins can only be created through mining would remain intact in the face of a quantum attack, with blocks continuing to be produced and the chain remaining operational. However, what is at risk is ownership. Bitcoin wallets rely on a different type of math that converts a secret private key into a publicly visible address. This math is easy to perform in one direction but virtually impossible in the other, and it is this mathematical barrier that prevents unauthorized individuals from spending someone else's coins. A previous article in this series delved into the physics behind quantum computing, explaining how it operates on a fundamentally different principle than classical computers, leveraging the unique behaviors of particles at very low temperatures and small scales. Another piece explored the implications of pointing a quantum computer at bitcoin, discussing how a quantum algorithm known as Shor's can significantly reduce the time it takes to reverse the one-way math problem that secures bitcoin wallets. Recently, Google released a paper indicating that such an attack could be executed with fewer resources than previously thought, highlighting the urgency of the situation. This final piece in the series focuses on the response to the quantum threat, examining what is at risk, the measures bitcoin has taken so far, and whether the network can coordinate a major security upgrade before quantum computers become a reality. The pool of bitcoin at risk is substantial, with approximately 6.9 million bitcoins, roughly one-third of all mined bitcoins, stored in wallets with publicly visible keys. This includes early bitcoins from the network's inception, which were stored in an address format that published the public key by default, as well as any wallet that has been used for a transaction, as spending from a wallet reveals the key for any remaining balance. A quantum attacker would not need to race against ongoing transactions but could systematically work through wallets with exposed keys at their leisure. Notably, this includes the approximately 1 million bitcoins held by bitcoin's pseudonymous creator, Satoshi Nakamoto, which have remained untouched since the network's early days and are now at risk. The 2021 Taproot upgrade inadvertently expanded the problem by changing how bitcoin addresses work, aiming to make transactions more efficient and private. However, a side effect of Taproot is that any bitcoin spent since its activation has had its protecting key published, making the remaining balance at that address vulnerable. This was a deliberate design choice at the time, given the perceived longer timeline for quantum threats, but it now poses an immediate risk. Efforts are underway to address the quantum threat, although nothing concrete has yet emerged from bitcoin developers. In contrast, Ethereum, a major competitor, has had a formal quantum-resistant program in place since 2018, with the Ethereum Foundation supporting four full-time teams and numerous independent developer groups working on the migration. Ethereum has outlined specific upgrades and has even launched a dedicated website to track its progress. Bitcoin, on the other hand, lacks a unified strategy. There are proposals, such as BIP-360, which suggests introducing new quantum-safe address types for voluntary migration, and a proposal from BitMEX Research for a detection system to trigger defensive actions in case of a quantum attack. However, these proposals have not gained broad support from bitcoin's core developers and address different aspects of the problem. Prominent figures in the bitcoin community, like Nic Carter, have emphasized the urgency of the situation, criticizing bitcoin's approach as inadequate compared to Ethereum's. Others, like Adam Back, agree on the need for preparation but disagree on the immediacy of the threat, suggesting that bitcoin should prepare optional upgrades in advance. The challenge in implementing effective solutions against the quantum threat for bitcoin is not the math itself but the network's governance structure. Bitcoin's development culture is based on avoiding central authority and treating changes to the protocol as rare and difficult, which has kept the network stable but makes coordinating a response to the quantum threat structurally harder. The migration of the 6.9 million exposed coins requires decisions that the network has historically avoided, such as whether to freeze old address formats to protect coins or allow exposed coins to move to new quantum-safe addresses. The situation with Satoshi's untouched coins is particularly poignant, as any solution affects not just the security of those coins but also the principle of bitcoin's decentralized nature. The recent Google paper frames the industry's stance, suggesting that a successful attack on bitcoin's current math should not be seen as a wake-up call but potentially as a signal that the window for adopting post-quantum cryptography has already closed. This implies that by the time the quantum threat becomes apparent, it may already be too late to respond. Developers are thus faced with the question of whether a network designed to resist coordinated change can implement its largest security upgrade before quantum computers become capable of exploiting the current vulnerabilities. Ethereum's head start suggests the importance of beginning now, but bitcoin's governance culture may lead to waiting until the threat is more tangible, a strategy that may not be viable if the timeline is shorter than anticipated.