Time Running Out for Bitcoin to Counter Quantum Threat
While not all aspects of bitcoin are vulnerable to quantum computing, ownership is at significant risk. The math that protects bitcoin wallets can be broken by quantum computers, which could lead to the theft of approximately 6.9 million bitcoins, including those owned by the cryptocurrency's pseudonymous creator, Satoshi Nakamoto. A quantum algorithm known as Shor's can collapse the gap between a public address and its corresponding private key, potentially allowing hackers to steal coins. The exposed pool of bitcoin is substantial, with roughly one-third of all mined coins at risk. This includes early bitcoin stored in addresses that published public keys by default, as well as any wallet that has been spent from, as spending reveals the key. The 2021 Taproot upgrade inadvertently expanded the problem by publishing the key protecting remaining coins at an address after a transaction. While other blockchains, such as Ethereum, have been preparing for the quantum threat since 2018, Bitcoin developers have yet to propose a concrete solution. Ethereum has a formal quantum-resistant program with multiple teams working on migration, whereas Bitcoin's development culture makes it harder to implement changes due to its lack of central authority and governance process. The coordination problem lies in the network's inability to make decisions on implementing effective solutions. Migrating the exposed coins requires decisions that the network has historically avoided, such as freezing old address formats or allowing exposed coins to move to new quantum-safe addresses. The Google paper's warning that a successful attack should not be seen as a wake-up call but rather as a potential signal that post-quantum cryptography adoption has already failed highlights the urgency of the situation. The question remains whether Bitcoin can overcome its governance challenges to implement the necessary security upgrade before the threat becomes a reality.