Bitcoin Faces Quantum Computing Threat, Posing Risk to 6.9 Million Coins
Not all aspects of bitcoin are vulnerable to quantum computer attacks. The process of bitcoin mining, which involves adding new blocks to the blockchain, utilizes a type of mathematics called hashing that quantum computers are unable to breach effectively. The blockchain itself and the rule that new bitcoins can only be created through mining would survive a quantum attack. However, ownership is at risk. Bitcoin wallets rely on a different kind of mathematics that converts a private key into a public address. This math functions easily in one direction but is extremely difficult in the other, which is the primary barrier preventing unauthorized individuals from spending coins. A quantum algorithm known as Shor's can overcome this barrier. Recently, a paper by Google demonstrated that such an attack could be executed with fewer resources than previously thought, and within a time frame that competes with bitcoin's block times. This article discusses the potential consequences and the response from the bitcoin community. Approximately 6.9 million bitcoins, roughly one-third of all mined coins, are stored in wallets with publicly visible keys, making them vulnerable to quantum attacks. This includes early bitcoins and any wallet that has been used for transactions, as spending reveals the key. A quantum attacker wouldn't need to rush against ongoing transactions but could systematically target wallets with exposed keys. Bitcoin's pseudonymous creator, Satoshi Nakamoto, holds about 1 million bitcoins that are also at risk. The 2021 Taproot upgrade inadvertently increased the problem by making bitcoin addresses more efficient and private but also publishing the key protecting remaining balances at an address after a transaction. While there's been significant debate, concrete plans from bitcoin developers are yet to emerge. Ethereum, a major competitor, has had a formal quantum-resistant program since 2018 and is actively working on migrating its security to quantum-safe mathematics. Bitcoin has proposals like BIP-360, which suggests adding new quantum-safe address types, and a detection system from BitMEX Research, but neither has gained broad support from core developers. The challenge lies in bitcoin's governance culture, which resists centralized change, making the coordination of such a significant security upgrade difficult. The biggest hurdle is deciding how to protect exposed coins, whether to freeze old address formats, and what to do with coins whose owners cannot or will not migrate. Setting a migration deadline poses a particular dilemma for Satoshi's coins. The future of bitcoin's security against quantum threats remains uncertain, with the possibility that by the time the threat becomes apparent, it may already be too late to respond effectively.