Time is Running Out for Bitcoin to Mitigate Quantum Computing Threat
Not all aspects of Bitcoin are vulnerable to quantum computer attacks. The process of mining, which involves adding new blocks to the blockchain, utilizes a type of mathematics known as hashing that quantum computers are unable to break. As a result, the ledger and the rule that new Bitcoins can only be created through mining will remain intact. However, ownership is a different matter. Bitcoin wallets rely on a distinct type of mathematics that converts a private key into a public address. This math functions efficiently in one direction but is impractical in the other, which is the primary barrier preventing unauthorized individuals from spending someone else's coins. A quantum algorithm known as Shor's algorithm can bridge this gap, and a recent paper by Google demonstrated that such an attack could be executed with fewer resources than previously estimated, within a time frame that competes with Bitcoin's block times. This article explores the potential risks, the current state of Bitcoin's response, and whether the network can coordinate a significant security upgrade before quantum computers become a reality. Approximately 6.9 million Bitcoins, representing about one-third of all mined coins, are stored in wallets with publicly visible keys, making them susceptible to quantum attacks. This includes early Bitcoins and any wallet that has been spent from, as spending reveals the key for the remaining balance. Bitcoin's pseudonymous creator, Satoshi Nakamoto, holds around 1 million Bitcoins that are also at risk. The 2021 Taproot upgrade inadvertently expanded the problem by making any spent Bitcoin publish the key protecting the remaining balance at that address. While the quantum threat has sparked intense debate, no concrete plan has emerged from Bitcoin developers. In contrast, Ethereum has had a formal quantum-resistant program in place since 2018, with four teams working on the migration and a dedicated website to track progress. Bitcoin has proposals, such as BIP-360, which suggests adding new quantum-safe address types, and a competing proposal from BitMEX Research for a detection system to trigger defensive action in case of a quantum attack. However, neither has gained broad support from core developers, and they address different aspects of the problem. The lack of a centralized authority and a governance process that can implement major upgrades makes Bitcoin's migration more challenging than Ethereum's. The biggest hurdle is coordinating decisions that the network has historically avoided, such as whether to freeze old address formats or allow exposed coins to move to new quantum-safe addresses. Setting a migration deadline would force owners, including Satoshi, to either move their coins or risk losing them. The future of Bitcoin hangs in the balance, as developers face the question of whether the network can coordinate a significant security upgrade before quantum computers become a reality.