Time is Running Out for Bitcoin to Counter Quantum Threat, Putting 6.9 Million BTC at Risk
Not all aspects of bitcoin are vulnerable to quantum computers. The process of bitcoin mining, which involves adding new blocks to the blockchain, utilizes a type of mathematics known as hashing that quantum computers are unable to effectively breach. The blockchain itself and the rule that new bitcoins can only be created through mining would survive a quantum attack, with blocks continuing to be produced and the chain remaining intact. However, what would be compromised is ownership. Bitcoin wallets are secured by a different type of mathematics that converts a private key into a public address that can be seen by anyone. This mathematics functions effortlessly in one direction but not at all in the other, and it is the sole barrier preventing a stranger from spending your coins. The first part of this series on quantum computing delved into the physics behind it, explaining that a quantum computer is fundamentally different from a regular computer, operating at extremely low temperatures and small scales where particles exhibit unique behaviors. The second part examined what happens when a quantum computer is directed at bitcoin. Bitcoin wallets rely on a one-way mathematical problem. Converting a private key into a public address takes mere milliseconds, but reversing the process, from public address back to private key, would take a conventional computer longer than the age of the universe. A quantum algorithm known as Shor's algorithm reduces this gap. A recent paper by Google demonstrated that this attack could be executed with far fewer resources than previously estimated, within a timeframe that competes with bitcoin's block times. This final piece in the series focuses on the response. It discusses what is actually at risk, the measures bitcoin has taken so far, and whether a network designed to resist coordinated change can coordinate the most significant security upgrade in its history before quantum hardware becomes a reality. The pool of bitcoin at risk is substantial, with approximately 6.9 million bitcoin, or about one-third of all bitcoin ever mined, stored in wallets whose public keys are permanently visible on the blockchain. Most of this bitcoin is from the network's early years, stored in an address format that published the public key by default. It also includes any wallet that has ever been spent from, because spending reveals the key for whatever remains. A quantum attacker would not need to compete with a transaction in progress but could instead work through the wallets with exposed keys at their own pace. This includes the roughly 1 million bitcoin held by Satoshi Nakamoto, bitcoin's pseudonymous creator, which has remained untouched since the network's early days and now falls into the exposed category. The 2021 Taproot upgrade expanded the problem. Taproot is a change to how bitcoin addresses work, aimed at making transactions more efficient and private. A side effect of Taproot was that any bitcoin spent since its activation has published the key protecting whatever remains at that address. This was not a mistake but a reasonable tradeoff at the time, given the perceived timelines for quantum threats. Currently, there are efforts underway to address the quantum threat. Ethereum, a major competitor to bitcoin, has had a formal quantum-resistant program in place since 2018. The Ethereum Foundation supports four teams working full-time on the migration, with over ten independent developer groups shipping weekly test networks. Ethereum's plan involves specific upgrades across four upcoming network-wide changes, transitioning Ethereum's security to new mathematics that quantum computers cannot break. In contrast, bitcoin has no equivalent strategy yet. There are formal proposals, such as BIP-360, which would introduce new quantum-safe address types that holders could migrate to voluntarily. Another proposal from BitMEX Research suggests installing a detection system that triggers defensive action if a quantum attack is observed on the network. However, neither proposal has broad support from bitcoin's core developers, and they address different aspects of the problem. The challenge in implementing effective solutions against bitcoin's quantum threat is significant. Bitcoin's migration is more complex than Ethereum's due to reasons unrelated to the actual mathematics. Ethereum has a foundation that funds engineering work and a governance process that regularly passes major upgrades. Bitcoin lacks both, with a development culture that treats any central authority as a potential failure mode and a social consensus that changes to the protocol should be rare and difficult. These principles have kept the network stable for nearly two decades but make solving the quantum problem structurally harder for bitcoin. Migrating the 6.9 million exposed coins requires decisions that the network has spent twenty years avoiding. Questions include whether old address formats should be frozen after a certain date to protect coins from future theft, whether exposed coins should be allowed to move to new quantum-safe addresses using their original keys, and what happens to coins whose owners cannot or will not migrate. The situation with Satoshi's coins is a sharp example. Freezing old formats protects the coins from theft but makes them permanently inaccessible, including to Satoshi. Leaving the old formats open means those coins remain a potential prize for whoever builds the first working quantum computer or gains access to one with the intent to attack. Setting a migration deadline forces Satoshi to either move the coins, revealing their ownership, or lose them. Every option changes bitcoin's character in ways the network has historically refused to change. The Google paper's framing is a summary of the industry's current stance. A successful attack on the mathematics bitcoin uses should not be seen as a wake-up call to adopt post-quantum cryptography but rather as a potential signal that the adoption of post-quantum cryptography has already failed. This implies that by the time the threat becomes apparent, the window to respond may already have closed. Developers are now faced with the question of whether a network built to resist coordinated change can coordinate the largest security upgrade in its history before quantum hardware catches up. Ethereum's eight-year head start suggests starting now is the correct approach. Bitcoin's governance culture, however, suggests waiting until the threat is demonstrated, then acting. Only one of these approaches will be effective if the timeline turns out to be shorter than optimists estimate.