Time is Running Out for Bitcoin to Counter Quantum Computing Threats, Putting 6.9 Million BTC at Risk
Not all aspects of bitcoin are vulnerable to quantum computer attacks. The process of bitcoin mining, which involves adding new blocks to the blockchain, relies on a type of mathematics known as hashing, which quantum computers are unable to break. As a result, the blockchain ledger and the rule that new bitcoins can only be created through mining would remain intact in the event of a quantum attack. The production of blocks and the continuation of the chain would not be affected. However, ownership would be severely impacted. Bitcoin wallets are secured by a different type of mathematics that converts a private key into a public address. This math works in one direction but not the other, and it is the only thing preventing unauthorized individuals from spending your coins. The first part of this series delved into the physics of quantum computing, explaining how a quantum computer is fundamentally different from a regular computer, starting with a very cold, very small loop of metal where particles exhibit unique behaviors. The second part examined what happens when a quantum computer is directed at bitcoin, highlighting how bitcoin wallets rely on a one-way math problem. While turning a private key into a public address takes milliseconds, reversing the process would take a regular computer longer than the age of the universe. A quantum algorithm known as Shor's algorithm bridges this gap. A recent paper by Google demonstrated that the attack could be executed with far fewer resources than previously estimated, and within a time frame that competes with bitcoin's block times. This final piece in the series focuses on the response to this threat, including what is at risk, the measures bitcoin has taken, and whether a network designed to resist coordinated change can implement the largest security upgrade in its history before the arrival of quantum hardware. The vulnerable pool of bitcoins is substantial, consisting of roughly 6.9 million coins, approximately one-third of all mined bitcoins, which are stored in wallets with publicly visible keys on the blockchain. This includes early bitcoins from the network's first years, which were stored in an address format that published the public key by default, as well as any wallet that has been spent from, as spending reveals the key for any remaining balance. A quantum attacker would not need to compete with an ongoing transaction but could instead work through the wallets with exposed keys at their own pace. Notably, this includes the approximately 1 million bitcoins held by bitcoin's pseudonymous creator, Satoshi Nakamoto, which have remained untouched since the network's early days. The 2021 Taproot upgrade inadvertently expanded the problem by changing how bitcoin addresses function, with the intention of making transactions more efficient and private. However, this change had the side effect of publishing the key that protects any remaining bitcoin at an address after a transaction, following the activation of Taproot. While this was not an error, it was a reasonable trade-off at the time, given the perceived longer timeline for quantum threats. Currently, there are no concrete plans from bitcoin developers to address the quantum threat, despite the intense debate it has sparked in recent months. In contrast, Ethereum, a major competitor to bitcoin among institutional investors, has had a formal quantum-resistant program in place since 2018. The Ethereum Foundation supports four full-time teams working on the migration, along with more than ten independent developer groups that release weekly test networks. Ethereum's plan outlines specific upgrades across four upcoming network-wide changes, aiming to transition its security to new mathematics that quantum computers cannot break. It has even launched a dedicated website, pq.ethereum.org, to track its progress. Bitcoin lacks a comparable strategy. However, there are efforts underway to solve the problem. One formal proposal, BIP-360, put forth by a group of developers and researchers, suggests introducing new quantum-safe address types that holders could voluntarily migrate to. Another proposal from BitMEX Research recommends implementing a detection system that would trigger defensive actions if a quantum attack is observed on the network. Neither proposal has gained broad support from bitcoin's core developers, and they address different aspects of the problem. Nic Carter, a prominent bitcoin advocate, has highlighted the issue, stating that the elliptic curve cryptography securing bitcoin wallets is on the verge of becoming obsolete. He praised Ethereum's approach as 'best in class' and criticized bitcoin's as 'worst in class', citing developers who deny, downplay, or ignore the problem rather than engaging with it. Adam Back, the CEO of Blockstream and an early contributor to bitcoin, disagrees on the urgency but agrees on the direction, suggesting that bitcoin should prepare now by incorporating optional upgrades in advance, allowing the network to migrate when necessary, rather than reacting in a crisis. The primary challenge in implementing effective solutions against bitcoin's quantum threat lies in coordination. Bitcoin's migration is more complex than Ethereum's due to reasons unrelated to the mathematics involved. Ethereum has a foundation that supports engineering work and a governance process that regularly implements major upgrades. Bitcoin, on the other hand, lacks a central authority and treats any form of centralized governance as a failure mode, with a social consensus that changes to the protocol should be rare and difficult. While these principles have maintained the network's stability for nearly two decades, they also make addressing the quantum problem structurally more challenging for bitcoin. Migrating the 6.9 million exposed coins requires decisions that the network has avoided for twenty years. Questions arise about whether old address formats should be frozen after a certain date to protect coins from future theft, whether exposed coins should be allowed to move to new quantum-safe addresses using their original keys, and what happens to coins whose owners cannot or will not migrate. Satoshi's coins present a sharp example, as freezing old formats would protect the coins but make them permanently inaccessible, including to Satoshi, while leaving the old formats open means those coins remain a potential target for whoever first develops a working quantum computer or gains access to one. Setting a migration deadline would force Satoshi to either move the coins, revealing their ownership, or lose them. Every option would change bitcoin's character in ways the network has historically refused to change. The Google paper frames the industry's stance, suggesting that a successful attack on bitcoin's mathematics should not be seen as a call to adopt post-quantum cryptography but rather as a potential signal that the adoption of post-quantum cryptography has already failed. This implies that by the time the threat becomes apparent, the window to respond may have already closed. Developers are now faced with the question of whether a network designed to resist coordinated change can coordinate the largest security upgrade in its history before quantum hardware becomes a reality. Ethereum's eight-year head start suggests that starting now is the correct approach, while bitcoin's governance culture indicates that waiting until the threat is demonstrated may be the more likely path. Only one of these approaches will be effective if the timeline proves to be shorter than optimists estimate.