Time's Running Out for Bitcoin to Counter Quantum Threat, Putting 6.9 Million BTC at Risk
Not all aspects of bitcoin are vulnerable to quantum computers. The process of bitcoin mining, which involves adding new blocks to the blockchain, relies on a type of mathematics known as hashing, which quantum computers are unable to break. As a result, the blockchain itself and the rule that new bitcoins can only be created through mining would remain intact in the event of a quantum attack. New blocks would continue to be produced, and the blockchain would keep functioning. However, ownership would be severely compromised. Bitcoin wallets are secured by a different type of mathematics that converts a private key into a public address that can be seen by anyone. This mathematics works effortlessly in one direction but is extremely difficult to reverse, which is the primary obstacle preventing unauthorized individuals from spending your coins. The first part of this series on quantum computing delved into the underlying physics. A quantum computer is fundamentally distinct from a conventional computer, operating at extremely low temperatures and small scales where particles exhibit unique behaviors not observed elsewhere on Earth. The second part explored the implications of directing a quantum computer at bitcoin. Bitcoin wallets rely on a one-way mathematical problem. Converting a private key into a public address takes mere milliseconds, whereas reversing the process, from public address to private key, would take a conventional computer longer than the age of the universe. Shor's quantum algorithm significantly reduces this gap. A recent paper by Google demonstrated that this attack could be executed with far fewer resources than previously estimated, and within a timeframe that competes with bitcoin's block times. This final piece in the series focuses on the response. It examines what is actually at risk, the measures bitcoin has taken, and whether a network designed to resist coordinated change can implement the most significant security upgrade in its history before quantum hardware becomes a reality. The pool of vulnerable bitcoin is substantial, with roughly 6.9 million coins, approximately one-third of all mined bitcoin, stored in wallets with publicly visible keys on the blockchain. Most of these coins are from the network's early days, stored in an address format that published the public key by default. It also includes any wallet that has been spent from, as spending reveals the key for any remaining balance. A quantum attacker would not need to compete with ongoing transactions. Instead, they could systematically target wallets with exposed keys at their own pace. Bitcoin's pseudonymous creator, Satoshi Nakamoto, holds approximately 1 million bitcoin, which has remained untouched since the network's early days and now falls into the exposed category. The 2021 Taproot upgrade inadvertently expanded the problem. Taproot is a modification to how bitcoin addresses function, aimed at making transactions more efficient and private. A side effect of Taproot was that any bitcoin spent after its activation published the key protecting the remaining balance at that address. Although this was not an error, it was a reasonable trade-off at the time, given the perceived longer timelines for quantum threats. Currently, there are efforts underway to address the quantum threat. While the issue has sparked intense debate in recent months, and other blockchains are preparing, bitcoin developers have yet to propose a concrete solution. Ethereum, a major competitor to bitcoin among institutional investors, has had a formal quantum-resistant program in place since 2018. The Ethereum Foundation supports four full-time teams working on the migration, with over ten independent developer groups launching weekly test networks. Their plan involves specific upgrades across four upcoming network-wide changes, transitioning Ethereum's security to quantum-resistant mathematics. Bitcoin, on the other hand, lacks a comparable strategy. This does not mean there are no efforts to solve the problem. One formal proposal, BIP-360, from a group of developers and researchers, suggests introducing new quantum-safe address types that holders could voluntarily migrate to. Another proposal from BitMEX Research involves installing a detection system that triggers defensive actions if a quantum attack is observed on the network. Neither proposal has garnered broad support from bitcoin's core developers, and they address different aspects of the problem. Nic Carter, a prominent bitcoin advocate, has highlighted the issue in recent months. Carter stated that the elliptic curve cryptography securing bitcoin wallets is on the verge of becoming obsolete, describing Ethereum's approach as 'best in class' and bitcoin's as 'worst in class.' He criticized developers for denying, downplaying, or ignoring the problem rather than engaging with it. Adam Back, the CEO of Blockstream and an early bitcoin contributor, disagrees on the urgency but agrees on the need for preparation. Back believes that while quantum computing still has much to prove and current systems are essentially lab experiments, bitcoin should prepare now by incorporating optional upgrades in advance, allowing the network to migrate when necessary, rather than reacting in a crisis. The biggest challenge in implementing effective solutions against bitcoin's quantum threat lies in coordination. Bitcoin's migration is more complex than Ethereum's due to reasons unrelated to the mathematics involved. Ethereum has a foundation that funds engineering work and a governance process that regularly passes major upgrades. In contrast, bitcoin lacks a central authority and a formal governance process, with its development culture treating any central authority as a failure mode and favoring rare and difficult changes to the protocol. These principles have maintained the network's stability for nearly two decades but also make addressing the quantum problem structurally more difficult for bitcoin. Migrating the 6.9 million exposed coins requires decisions that the network has spent twenty years avoiding. Questions arise about whether old address formats should be frozen after a certain date to protect coins from future theft, whether exposed coins should be allowed to move to new quantum-safe addresses using their original keys, and what happens to coins whose owners cannot or will not migrate. Satoshi's coins serve as the most striking example. Freezing old formats protects the coins from theft but makes them permanently inaccessible, including to Satoshi. Leaving the old formats open means those coins remain a potential target for whoever builds the first working quantum computer or gains access to one. Setting a migration deadline forces Satoshi to either move the coins, revealing their ownership, or lose them. Every option changes bitcoin's character in ways the network has historically refused to change. The Google paper frames the industry's current stance. A successful attack on bitcoin's mathematics 'should not be seen as a wake-up call to adopt post-quantum cryptography as much as a potential signal that PQC adoption has already failed.' This implies that by the time the threat becomes apparent, the window to respond may have already closed. Developers now face the question of whether a network built to resist coordinated change can coordinate the biggest security upgrade in its history before quantum hardware catches up. Ethereum's eight-year head start suggests starting now is the correct approach. Bitcoin's governance culture, however, suggests waiting until the threat is demonstrated, then acting. Only one of these approaches will be effective if the timeline turns out to be shorter than optimists estimate.