Time Is Running Out for Bitcoin to Counter the Quantum Threat

Not all aspects of bitcoin are vulnerable to quantum computers. The process of bitcoin mining, which involves adding new blocks to the blockchain, utilizes a type of mathematics known as hashing that quantum computers are unable to breach effectively. The blockchain itself and the rule that new bitcoins can only be created through mining would survive a quantum attack, allowing blocks to continue being produced and the chain to remain operational. However, ownership is a different matter. Bitcoin wallets rely on a distinct type of mathematics that converts a secret private key into a publicly visible address. This math functions effortlessly in one direction but is impractical in the other, serving as the sole barrier preventing strangers from spending your coins. A quantum algorithm known as Shor's collapses this gap, and a recent paper by Google demonstrated that the attack could be executed with far fewer resources than previously estimated, within a timeframe that competes with bitcoin's block times. This article, the final installment in the series, focuses on the response to this threat. It examines what is actually at risk, the measures bitcoin has taken so far, and whether a network designed to resist coordinated change can coordinate the most significant security upgrade in its history before the threat materializes. The exposed pool of bitcoin is substantial, with roughly 6.9 million bitcoin, or about one-third of all mined bitcoin, stored in wallets whose public keys are permanently visible on the chain. This includes early bitcoin from the network's first years, stored in an address format that published the public key by default, as well as any wallet that has ever been spent from, because spending reveals the key for the remaining balance. A quantum attacker would not need to compete with an ongoing transaction; instead, they could work through the wallets with exposed keys at their own pace. Bitcoin's pseudonymous creator, Satoshi Nakamoto, holds approximately 1 million bitcoin that have remained untouched since the network's early days and now fall into the exposed category. The 2021 Taproot upgrade inadvertently expanded the problem by making transactions more efficient and private, but as a side effect, any bitcoin spent since Taproot's activation has published the key protecting the remaining balance at that address. While the quantum threat has sparked intense debate in recent months, and other blockchains are preparing, no concrete plan has emerged from Bitcoin developers yet. Ethereum, one of Bitcoin's largest competitors, has had a formal quantum-resistant program in place since 2018, with four full-time teams working on the migration and a dedicated website to track progress. Bitcoin, on the other hand, lacks a comparable strategy. There are proposals, such as BIP-360, which suggests adding new quantum-safe address types, and a competing proposal from BitMEX Research for a detection system to trigger defensive actions in case of a quantum attack. However, neither proposal has gained broad support from core developers, and they address different aspects of the problem. The challenge lies in bitcoin's governance culture, which treats any central authority as a failure mode and holds that changes to the protocol should be rare and difficult. This has kept the network stable for nearly two decades but makes addressing the quantum problem structurally harder. Migrating the exposed coins requires decisions the network has avoided for twenty years, such as whether to freeze old address formats to protect coins from future theft or allow exposed coins to move to new quantum-safe addresses using their original keys. Every option alters bitcoin's character in ways the network has historically refused to change. The question now is whether a network built to resist coordinated change can coordinate the most significant security upgrade in its history before the threat becomes a reality.