Bitcoin's Quantum Conundrum: A Threat to 6.9 Million Coins

Not all aspects of Bitcoin are vulnerable to quantum attacks. The process of mining, which involves adding new blocks to the blockchain, utilizes a type of mathematics called hashing that quantum computers are unable to breach. The ledger and the rule that new Bitcoins can only be created through mining would remain intact in the event of a quantum attack. However, ownership is a different story. Bitcoin wallets rely on a distinct mathematical approach that converts a private key into a public address. This math functions effortlessly in one direction but is impractical in the other, and it is the sole barrier preventing unauthorized individuals from spending coins. A quantum algorithm known as Shor's algorithm can bridge this gap, and a recent paper by Google demonstrated that the attack could be executed with significantly fewer resources than previously estimated. This article, the final installment in a series, focuses on the response to this threat. It examines what is at risk, the measures Bitcoin has taken, and whether a network designed to resist coordinated change can implement the most substantial security upgrade in its history before the advent of quantum hardware. Approximately 6.9 million Bitcoins, roughly one-third of all mined coins, are stored in wallets with publicly visible keys, rendering them susceptible to quantum attacks. This includes early Bitcoins from the network's inception, which were stored in an address format that published the public key by default, as well as any wallet that has been spent from, as spending reveals the key for the remaining balance. A quantum attacker would not need to compete with an ongoing transaction; instead, they could methodically work through the wallets with exposed keys at their own pace. Bitcoin's pseudonymous creator, Satoshi Nakamoto, holds approximately 1 million Bitcoins, which have remained untouched since the network's early days and are now at risk. The 2021 Taproot upgrade inadvertently expanded the problem by making transactions more efficient and private, but also publishing the key protecting the remaining balance at an address. While the quantum threat has sparked intense debate, Bitcoin developers have yet to propose a concrete plan. In contrast, Ethereum has had a formal quantum-resistant program in place since 2018, with four teams working full-time on the migration and a dedicated website to track progress. Bitcoin has no equivalent strategy, although there are efforts to address the issue, such as a formal proposal to add new quantum-safe address types and a competing proposal to install a detection system. However, neither proposal has garnered broad support from Bitcoin's core developers, and they only solve half of the problem. The biggest challenge in implementing effective solutions is coordination, as Bitcoin's migration is more complex than Ethereum's due to its lack of a central authority and governance process. The network's development culture views any central authority as a failure mode, and its social consensus dictates that changes to the protocol should be rare and difficult. This has kept the network stable for nearly two decades but also makes the quantum problem structurally harder to solve. Migrating the 6.9 million exposed coins requires decisions that the network has spent years avoiding, such as freezing old address formats or allowing exposed coins to move to new quantum-safe addresses. Every option changes Bitcoin's character in ways the network has historically refused to change. The Google paper's framing suggests that a successful attack on Bitcoin's math should not be seen as a wake-up call to adopt post-quantum cryptography but rather as a potential signal that adoption has already failed. This implies that by the time the threat becomes visible, the window to respond may already have closed. Developers now face the question of whether a network built to resist coordinated change can coordinate the biggest security upgrade in its history before the hardware catches up to the theory. Ethereum's eight-year head start suggests that the correct answer is to start now, while Bitcoin's governance culture suggests that the likely answer is to wait until the threat is demonstrated, then move. Only one of these answers will work if the timeline turns out to be shorter than estimated.