Bitcoin's Quantum Conundrum: A Race Against Time to Protect 6.9 Million Coins
Not all aspects of bitcoin are vulnerable to quantum attacks. The process of mining, which involves adding new blocks to the blockchain, utilizes a type of mathematics known as hashing, which quantum computers are unable to break. As a result, the blockchain itself and the rule that new bitcoins can only be created through mining would remain intact in the event of a quantum attack. The production of blocks would continue, and the chain would remain operational. However, ownership would be severely compromised. Bitcoin wallets rely on a different type of mathematics, which converts a private key into a public address that can be seen by anyone. This mathematics works effortlessly in one direction but is impossible to reverse, and it is the only barrier preventing an unknown individual from spending someone else's coins. The first part of this series on quantum computing delved into the realm of physics, explaining how a quantum computer is fundamentally distinct from a conventional computer. It begins with an extremely cold, tiny loop of metal where particles exhibit behaviors that are not observed anywhere else on Earth. The second part examined what occurs when a quantum computer is directed at bitcoin. Bitcoin wallets rely on a one-way mathematical problem. Converting a private key into a public address takes mere milliseconds. Conversely, reversing the process, from a public address back to a private key, would take a conventional computer longer than the age of the universe. A quantum algorithm known as Shor's algorithm reduces this gap. A recent paper by Google demonstrated that the attack could be executed with far fewer resources than previously estimated, within a time frame that competes with bitcoin's block times. This final piece in the series focuses on the response to the quantum threat. It discusses what is actually at risk, the measures bitcoin has taken to address the issue, and whether a network designed to resist coordinated change can implement the most significant security upgrade in its history before the advent of quantum hardware. A substantial portion of the bitcoin network is vulnerable to attack. Approximately 6.9 million bitcoins, which is roughly one-third of all mined coins, are stored in wallets whose public keys are permanently visible on the blockchain. The majority of these coins are from the network's early days and are stored in an address format that, by default, publishes the public key. Additionally, any wallet that has been spent from is also at risk, as spending reveals the key for any remaining balance. A quantum attacker would not need to compete with an ongoing transaction. Instead, they could systematically work through the wallets with exposed keys at their own pace. Bitcoin's pseudonymous creator, Satoshi Nakamoto, holds approximately 1 million bitcoins that have remained untouched since the network's early days and are now classified as exposed. The 2021 Taproot upgrade inadvertently exacerbated the problem. Taproot is a modification to how bitcoin addresses function, intended to make transactions more efficient and private. An unintended consequence was that any bitcoin spent since Taproot's activation has published the key protecting the remaining balance at that address. Although this was not an error, it was a reasonable trade-off at the time, given the perceived longer timeline for quantum threats. Several initiatives are underway to address the quantum threat. While the issue has sparked intense debate in recent months, and other blockchains are taking action, bitcoin developers have yet to propose a concrete plan. Ethereum, which can be considered one of bitcoin's largest competitors among institutional investors, has had a formal quantum-resistant program in place since 2018. The Ethereum Foundation has four teams working full-time on the migration, with over ten independent developer groups creating weekly test networks. The plan involves specific upgrades across four upcoming network-wide changes, transitioning Ethereum's security to new mathematics that quantum computers cannot break. Ethereum has even launched a dedicated website to track its progress. In contrast, bitcoin lacks a comparable strategy. This does not mean that efforts are not being made to address the issue. One formal proposal, BIP-360, put forth by a group of developers and researchers, suggests introducing new quantum-safe address types that holders could voluntarily migrate to. Another proposal from BitMEX Research recommends implementing a detection system that triggers defensive actions if a quantum attack is observed on the network. However, neither proposal has garnered broad support from bitcoin's core developers, and they address different aspects of the problem. Nic Carter, a prominent bitcoin advocate, has highlighted the issue in recent months. Carter stated that the mathematics securing bitcoin wallets is on the verge of becoming obsolete and described Ethereum's approach as 'best in class' and bitcoin's as 'worst in class.' He criticized developers for denying, downplaying, or ignoring the problem rather than engaging with it. Adam Back, the CEO of Blockstream and an early bitcoin contributor, disagrees on the urgency but agrees on the direction. Back stated that quantum computing still has much to prove and that current systems are essentially laboratory experiments. However, he also emphasized that bitcoin should prepare now by incorporating optional upgrades in advance, allowing the network to migrate when necessary, rather than reacting in a crisis. The primary challenge in implementing effective solutions against the quantum threat lies in coordination. Bitcoin's migration is more complex than Ethereum's due to reasons unrelated to the mathematics itself. Ethereum has a foundation that funds engineering work and a governance process that regularly implements significant upgrades. Bitcoin, on the other hand, lacks a central authority and treats any such authority as a potential failure mode. Its development culture emphasizes rare and difficult changes to the protocol, which has maintained the network's stability for nearly two decades but also makes addressing the quantum problem structurally more challenging. Migrating the 6.9 million exposed coins requires decisions that the network has avoided for twenty years. Questions arise about whether old address formats should be frozen after a certain date to protect coins from future theft, whether exposed coins should be allowed to move to new quantum-safe addresses using their original keys, and what happens to coins whose owners cannot or will not migrate. The coins held by Satoshi Nakamoto are a prime example. Freezing old formats protects the coins from theft but makes them permanently inaccessible, including to Satoshi. Leaving the old formats open means those coins remain a potential target for whoever builds the first functional quantum computer or gains access to one. Setting a migration deadline forces Satoshi to either move the coins, revealing their ownership, or lose them. Every option changes bitcoin's character in ways the network has historically refused to change. The future of bitcoin's quantum threat is uncertain. The Google paper's framing serves as a summary of the industry's current stance. A successful attack on bitcoin's mathematics 'should not be seen as a wake-up call to adopt post-quantum cryptography as much as a potential signal that PQC adoption has already failed.' This implies that by the time the threat becomes apparent, the window to respond may have already closed. Developers now face the question of whether a network designed to resist coordinated change can implement the most significant security upgrade in its history before quantum hardware becomes a reality. Ethereum's eight-year head start suggests that the correct answer is to start now. Bitcoin's governance culture, however, suggests that the likely answer is to wait until the threat is demonstrated, then act. Only one of these approaches will be effective if the timeline proves shorter than optimists predict.