Time Running Out for Bitcoin to Counter Quantum Threat, 6.9 Million BTC at Risk
Not all aspects of bitcoin are vulnerable to quantum computers. The process of adding new blocks to the blockchain, known as mining, relies on a type of mathematics called hashing, which quantum computers are unable to crack. As a result, the blockchain itself and the rule that new bitcoins can only be created through mining would remain intact in the event of a quantum attack. Blocks would continue to be produced, and the chain would remain operational. However, ownership would be severely compromised. Bitcoin wallets are secured by a different mathematical approach that converts a private key into a publicly visible address. This math is easily reversible in one direction but virtually impossible in the other, making it the sole barrier preventing unauthorized individuals from spending your coins. A significant portion of bitcoin, approximately 6.9 million, is stored in wallets with publicly visible keys, making them susceptible to quantum attacks. This includes early bitcoin from the network's inception, stored in an address format that published the public key by default, as well as any wallet that has been spent from, as spending reveals the key for the remaining balance. A quantum attacker would not need to compete with ongoing transactions; instead, they could systematically target wallets with exposed keys at their leisure. Bitcoin's pseudonymous creator, Satoshi Nakamoto, holds around 1 million bitcoin, untouched since the network's early days, which now falls into the vulnerable category. The 2021 Taproot upgrade inadvertently expanded the issue. Taproot is a modification to how bitcoin addresses function, intended to enhance transaction efficiency and privacy. A side effect was that any bitcoin spent after Taproot's activation has published the key protecting the remaining balance at that address. Although this was not an error, it was a reasonable trade-off at the time, given the perceived longer timelines for quantum threats. Currently, there are no concrete plans from Bitcoin developers to address the quantum threat. Ethereum, a major competitor, has had a formal quantum-resistant program in place since 2018, with multiple teams working on the migration and a dedicated website to track progress. Bitcoin, on the other hand, lacks a comparable strategy. There are proposals, such as BIP-360, which suggests introducing new quantum-safe address types for voluntary migration, and a competing proposal from BitMEX Research for a detection system to trigger defensive actions in case of a quantum attack. However, neither proposal has gained broad support from bitcoin's core developers, and they address different aspects of the problem. Prominent bitcoin advocate Nic Carter has voiced concerns, stating that the current cryptographic approach is on the verge of obsolescence and describing Ethereum's approach as 'best in class' and bitcoin's as 'worst in class.' Adam Back, Blockstream CEO and early bitcoin contributor, agrees on the need for preparation but disagrees on the urgency. The primary challenge in implementing effective solutions against the quantum threat is coordination. Bitcoin's migration is more complex than Ethereum's due to its lack of a central authority and governance process. The network's development culture views any central authority as a failure mode, and changes to the protocol are rare and difficult. This has kept the network stable but makes addressing the quantum problem structurally harder. Migrating the exposed coins requires decisions that the network has avoided for twenty years. Questions arise about freezing old address formats, allowing exposed coins to move to quantum-safe addresses, and the fate of coins whose owners cannot or will not migrate. The future is uncertain, with the Google paper framing the situation as a potential signal that post-quantum cryptography adoption may have already failed. Developers face the question of whether a network built to resist coordinated change can implement the biggest security upgrade in its history before the threat becomes imminent. Ethereum's head start suggests the need to act now, while bitcoin's governance culture may lead to waiting until the threat is more apparent, a strategy that may not be effective if the timeline is shorter than expected.