Time is Running Out for Bitcoin to Counter Quantum Threat, Putting 6.9 Million BTC at Risk

Not all aspects of bitcoin are vulnerable to quantum computer attacks. The process of bitcoin mining, which involves adding new blocks to the blockchain, utilizes a type of mathematics known as hashing that quantum computers are unable to breach effectively. As a result, the blockchain itself and the rule that new bitcoins can only be created through mining would remain intact in the face of a quantum attack, allowing blocks to continue being produced and the chain to keep running. However, ownership of bitcoins is a different story. Bitcoin wallets rely on a specific type of mathematics that converts a secret private key into a publicly visible address, with the math being easily solvable in one direction but not the other. This one-way math problem is what prevents unauthorized individuals from spending someone else's coins. A quantum algorithm known as Shor's algorithm can bypass this security measure, and a recent paper by Google demonstrated that such an attack could be carried out with fewer resources than previously thought, within a timeframe that competes with bitcoin's block times. This article explores the potential risks, the current state of bitcoin's defense against quantum threats, and whether the network can coordinate a significant security upgrade before quantum computing technology advances further. The pool of bitcoin at risk is substantial, with approximately 6.9 million bitcoins - roughly one-third of all mined bitcoins - stored in wallets whose public keys are already visible on the blockchain. This includes early bitcoins from the network's first years, stored in an address format that published the public key by default, as well as any wallet that has ever been spent from, as spending reveals the key for the remaining balance. A quantum attacker would not need to race against an ongoing transaction but could instead work through the wallets with exposed keys at their own pace. This includes the approximately 1 million bitcoins held by bitcoin's pseudonymous creator, Satoshi Nakamoto, which have remained untouched since the network's early days and are now at risk. The 2021 Taproot upgrade inadvertently expanded the problem by making any bitcoin spent since its activation publish the key protecting the remaining balance at that address. While the quantum threat has sparked intense debate, no concrete plan has emerged from bitcoin developers yet. In contrast, Ethereum has had a formal quantum-resistant program in place since 2018, with four full-time teams working on the migration and a dedicated website to track progress. Ethereum's plan involves specific upgrades to move its security to quantum-resistant mathematics. Bitcoin, on the other hand, lacks a comparable strategy. There are proposals, such as BIP-360, which suggests introducing new quantum-safe address types that holders could migrate to voluntarily, and a proposal from BitMEX Research for a detection system that triggers defensive action if a quantum attack is observed. However, neither proposal has gained broad support from bitcoin's core developers, and they address different parts of the problem. Prominent bitcoin advocate Nic Carter has emphasized the urgency of the situation, describing bitcoin's approach as 'worst in class' compared to Ethereum's 'best in class' and calling for action to address the obsolescence of elliptic curve cryptography. Adam Back, CEO of Blockstream and an early bitcoin contributor, agrees on the need for preparation but disagrees on the immediacy of the threat, suggesting that bitcoin should prepare now with optional upgrades to migrate when necessary. The biggest challenge in implementing effective solutions against bitcoin's quantum threat is not the math itself but the coordination problem. Bitcoin's development culture and lack of central authority make significant upgrades difficult. Ethereum's governance process and foundation-funded engineering work make it easier for Ethereum to plan and execute such migrations. For bitcoin, migrating the 6.9 million exposed coins requires making decisions that the network has historically avoided, such as whether to freeze old address formats to protect coins from future theft or allow exposed coins to move to new quantum-safe addresses. The fate of Satoshi's coins is a sharp example of the dilemma, as freezing old formats would protect the coins but make them inaccessible, including to Satoshi, while leaving the formats open would leave the coins vulnerable to quantum attack. Setting a migration deadline would force Satoshi to either move the coins, revealing ownership, or lose them, changing bitcoin's character in ways the network has refused to change. The future of bitcoin's security against quantum threats hangs in the balance, with the question of whether the network can coordinate a major security upgrade before the advent of powerful quantum computers. The example of Ethereum, which has an eight-year head start, suggests that starting now is the correct approach, but bitcoin's governance culture may lead to waiting until the threat is more visible, at which point it may be too late.