Time Running Out for Bitcoin to Counter Quantum Computing Threat
Not all aspects of Bitcoin are vulnerable to quantum computer attacks. The process of mining new blocks and adding them to the blockchain, which relies on a type of mathematics known as hashing, is secure against quantum computers. This means that the blockchain itself and the rule that new Bitcoins can only be created through mining would remain intact even if a quantum attack were to occur. However, the ownership of Bitcoins would be at risk. Bitcoin wallets are secured using a different kind of mathematics that converts a private key into a public address. This math works in one direction but not the other, preventing unauthorized access to a user's coins. A quantum algorithm, known as Shor's algorithm, can potentially break this math. Recently, a paper by Google demonstrated that such an attack could be carried out with fewer resources than previously thought, and within a timeframe that competes with Bitcoin's block times. This article explores the potential risks, what Bitcoin has done so far to address them, and whether the network can coordinate a major security upgrade before quantum computers become a threat. Approximately 6.9 million Bitcoins, or about one-third of all mined Bitcoins, are stored in wallets whose public keys are visible on the blockchain, making them vulnerable to quantum attacks. This includes early Bitcoins and any wallet that has been used for a transaction, as spending Bitcoins reveals the public key associated with the remaining balance. A quantum attacker would not need to compete with ongoing transactions but could instead target exposed wallets one by one. This puts at risk the approximately 1 million Bitcoins held by Bitcoin's creator, Satoshi Nakamoto, which have remained untouched since the network's early days. The 2021 Taproot upgrade inadvertently expanded the problem by making any Bitcoin spent since its activation publish the key protecting the remaining balance at that address. While there is ongoing debate and some proposals, such as BIP-360 and a detection system proposed by BitMEX Research, Bitcoin developers have yet to announce a concrete plan to address the quantum threat. In contrast, Ethereum has had a formal quantum-resistant program in place since 2018 and is actively working on migrating its security to quantum-safe mathematics. The challenge for Bitcoin lies in its governance structure, which is designed to resist centralized changes, making it difficult to implement the necessary upgrades. The migration of exposed coins requires decisions that the network has historically avoided, such as whether to freeze old address formats or allow exposed coins to move to quantum-safe addresses. Setting a migration deadline could force holders like Satoshi to either move their coins, potentially revealing their identity, or risk losing them. The future of Bitcoin's security against quantum threats hangs in the balance, with the question being whether the network can coordinate a significant security upgrade before the threat becomes imminent.