Bitcoin's Quantum Conundrum: Racing Against Time to Protect 6.9 Million Coins

Not all aspects of bitcoin are vulnerable to quantum computer attacks. The process of bitcoin mining, which involves adding new blocks to the blockchain, utilizes a type of mathematics known as hashing, which quantum computers are unable to compromise. The blockchain itself and the rule that new bitcoins can only be created through mining would survive a quantum attack, with blocks continuing to be produced and the chain remaining intact. However, ownership is a different matter. Bitcoin wallets are secured by a distinct type of mathematics that converts a private key into a public address. This math functions effortlessly in one direction but is extremely challenging in the other, and it is this difficulty that prevents unauthorized individuals from spending coins. A quantum algorithm known as Shor's algorithm can bypass this difficulty. Google's recent paper demonstrated that such an attack could be launched with far fewer resources than previously estimated, and within a timeframe that competes with bitcoin's block times. This article explores the response to the quantum threat, including what is at risk, the measures bitcoin has taken, and whether the network can coordinate a significant security upgrade before quantum computers become powerful enough to launch an attack. Approximately 6.9 million bitcoins, roughly one-third of all mined coins, are stored in wallets with publicly visible keys, making them susceptible to quantum attacks. This includes early bitcoins from the network's inception, which were stored in an address format that published public keys by default, as well as any wallet that has been used for transactions, as spending reveals the key for any remaining balance. A quantum attacker would not need to compete with ongoing transactions; instead, they could target wallets with exposed keys at their own pace. Bitcoin's pseudonymous creator, Satoshi Nakamoto, holds approximately 1 million bitcoins that have remained untouched since the network's early days and are now at risk. The 2021 Taproot upgrade inadvertently expanded the problem by making bitcoin addresses more efficient and private, but also publishing the keys protecting any remaining coins at an address. While the quantum threat has sparked intense debate, no concrete plan has emerged from bitcoin developers. In contrast, Ethereum has had a formal quantum-resistant program in place since 2018, with four teams working on the migration and a dedicated website to track progress. Bitcoin has proposals, such as BIP-360, which suggests adding new quantum-safe address types, and a competing proposal from BitMEX Research for a detection system to trigger defensive action in case of a quantum attack. However, neither proposal has broad support from core developers, and they address different aspects of the problem. The lack of a coordinated response is largely due to bitcoin's governance culture, which treats central authority as a failure mode and prefers rare and difficult changes to the protocol. This approach has kept the network stable but makes addressing the quantum problem more challenging. Migrating the 6.9 million exposed coins requires decisions that the network has historically avoided, such as freezing old address formats or allowing exposed coins to move to new quantum-safe addresses. The fate of coins whose owners cannot or will not migrate, including Satoshi's, poses a significant dilemma. Setting a migration deadline would force Satoshi to either move the coins, revealing ownership, or lose them, which would alter bitcoin's character in ways the network has refused to change. The future of bitcoin's security in the face of the quantum threat remains uncertain, with developers facing the question of whether the network can coordinate a significant security upgrade before it's too late.