Time Running Out for Bitcoin to Mitigate Quantum Threat, 6.9 Million BTC at Risk

Not all aspects of bitcoin are vulnerable to quantum computers. The process of adding new blocks to the blockchain, known as mining, relies on a type of mathematics called hashing, which quantum computers are unable to break. The blockchain itself and the rule that new bitcoins can only be created through mining would remain intact in the event of a quantum attack, with blocks continuing to be produced and the chain remaining operational. However, ownership would be severely compromised. Bitcoin wallets are secured by a different type of mathematics that converts a private key into a public address. This math is easily performed in one direction but not the other, and it is the only thing preventing unauthorized individuals from spending your coins. The first part of this series on quantum computing delved into the physics behind it, explaining that a quantum computer is fundamentally different from a regular computer, operating at extremely low temperatures and small scales where particles exhibit unique behaviors. The second part examined the implications of pointing a quantum computer at bitcoin, highlighting that bitcoin wallets rely on a one-way mathematical problem. While converting a private key into a public address takes milliseconds, reversing the process would take a conventional computer longer than the age of the universe. A quantum algorithm known as Shor's algorithm bridges this gap, and a recent paper by Google demonstrated that such an attack could be carried out with far fewer resources than previously estimated, racing against bitcoin's block times. This final piece in the series focuses on the response to this threat, discussing what is at risk, the measures bitcoin has taken, and whether a network designed to resist coordinated change can implement the largest security upgrade in its history before quantum hardware becomes a reality. The pool of at-risk bitcoin is substantial, with approximately 6.9 million coins, or about one-third of all mined bitcoin, stored in wallets with publicly visible keys on the blockchain. Most of this bitcoin is from the network's early years, stored in an address format that published the public key by default, and includes any wallet that has been spent from, as spending reveals the key for the remaining balance. A quantum attacker would not need to compete with ongoing transactions but could instead work through wallets with exposed keys at their own pace. This includes the roughly 1 million bitcoin held by Satoshi Nakamoto, the pseudonymous creator of bitcoin, which has remained untouched since the network's early days and now falls into the exposed category. The 2021 Taproot upgrade inadvertently expanded the problem by changing how bitcoin addresses work, making transactions more efficient and private. However, a side effect was that any bitcoin spent since Taproot's activation has published the key protecting the remaining balance at that address. While this was not a mistake at the time, given the perceived longer timelines for quantum threats, it has become a significant issue. Efforts are underway to address the quantum threat, although nothing concrete has emerged from bitcoin developers yet. In contrast, Ethereum, a major competitor, has had a formal quantum-resistant program in place since 2018, with the Ethereum Foundation supporting four full-time teams and numerous independent developer groups working on the migration. Ethereum has even launched a dedicated website to track its progress. Bitcoin lacks a comparable strategy, although there are proposals, such as BIP-360, which suggests introducing new quantum-safe address types for voluntary migration, and a proposal from BitMEX Research for a detection system to trigger defensive actions in case of a quantum attack. Neither proposal has garnered broad support from bitcoin's core developers, and they address different aspects of the problem. Prominent bitcoin advocate Nic Carter has highlighted the urgency, stating that the cryptography securing bitcoin wallets is on the verge of becoming obsolete and praising Ethereum's approach as 'best in class' while criticizing bitcoin's as 'worst in class'. Adam Back, CEO of Blockstream and an early bitcoin contributor, agrees on the need for preparation but disagrees on the immediacy of the threat, suggesting that bitcoin should prepare now with optional upgrades to migrate when necessary, rather than waiting for a crisis. The biggest challenge in implementing effective solutions against the quantum threat is coordination. Bitcoin's migration is more complex than Ethereum's due to its lack of a central authority and governance process, treating any central authority as a failure mode and requiring changes to the protocol to be rare and difficult. This has kept the network stable for nearly two decades but makes addressing the quantum problem structurally harder. Migrating the 6.9 million exposed coins requires decisions that the network has historically avoided, such as whether to freeze old address formats to protect coins from future theft or allow exposed coins to move to new quantum-safe addresses using their original keys. The fate of coins whose owners cannot or will not migrate, including Satoshi's, poses significant challenges. Setting a migration deadline would force Satoshi to either move the coins, revealing ownership, or lose them, changing bitcoin's character in ways the network has refused to alter. The future of bitcoin in the face of quantum threats remains uncertain, with the Google paper framing the situation as a potential signal that the window for adopting post-quantum cryptography may already have closed by the time the threat becomes apparent. Developers face the question of whether a network built to resist change can coordinate the largest security upgrade in its history before quantum hardware catches up. Ethereum's head start suggests the importance of starting now, while bitcoin's governance culture may lead to waiting until the threat is demonstrated, a strategy that may not be viable if the timeline is shorter than estimated.