Bitcoin's Quantum Conundrum: Can the Network Mitigate the Looming Threat?
While not all aspects of Bitcoin are vulnerable to quantum attacks, the ownership of coins is at significant risk. Bitcoin wallets rely on a specific type of mathematics that can be compromised by quantum computers, potentially allowing attackers to drain approximately 6.9 million BTC, including those held by the cryptocurrency's pseudonymous creator, Satoshi Nakamoto. The process of bitcoin mining, which utilizes a type of math known as hashing, is not susceptible to quantum computer attacks. This means that the blockchain ledger and the rule that new bitcoins can only be created through mining would remain intact in the event of a quantum attack. However, the ownership of coins, which is protected by a different kind of math, would be at risk. A quantum algorithm known as Shor's algorithm can effectively break this math, and a recent paper by Google has shown that such an attack could be carried out with fewer resources than previously thought. The exposed pool of bitcoin is substantial, with roughly 6.9 million coins at risk due to their public keys being visible on the blockchain. This includes early bitcoin from the network's first years, stored in an address format that published the public key by default, as well as any wallet that has ever been spent from. The 2021 Taproot upgrade has also expanded the problem, as any bitcoin spent since its activation has published the key protecting the remaining balance at that address. While there are ongoing efforts to address the quantum threat, including proposals for new quantum-safe address types and detection systems, a concrete strategy has yet to emerge from Bitcoin developers. In contrast, Ethereum has had a formal quantum-resistant program in place since 2018 and is actively working on migrating its security to new math that quantum computers cannot break. The biggest challenge in implementing effective solutions for Bitcoin lies in its governance structure, which treats any central authority as a potential failure mode and emphasizes rare and difficult changes to the protocol. This makes it structurally harder for Bitcoin to solve the quantum problem compared to Ethereum. Migrating the exposed coins requires decisions that the network has historically avoided, such as freezing old address formats or allowing exposed coins to move to new quantum-safe addresses. The fate of coins whose owners cannot or will not migrate, including Satoshi's, poses a significant dilemma. Ultimately, the question remains whether a network built to resist coordinated change can coordinate the biggest security upgrade in its history before quantum computers become a reality.