Time is Running Out for Bitcoin to Counter Quantum Computing Threats, Putting 6.9 Million BTC at Risk

Not all aspects of bitcoin are vulnerable to quantum computer attacks. The process of bitcoin mining, which involves adding new blocks to the blockchain, utilizes a type of mathematics known as hashing that quantum computers are unable to effectively breach. Consequently, the blockchain itself and the rule that new bitcoins can only be created through mining would remain intact in the event of a quantum attack, with blocks continuing to be produced and the chain remaining operational. However, what would be compromised is ownership. Bitcoin wallets rely on a different form of mathematics that converts a private key into a public address that can be seen by anyone. This mathematics functions effortlessly in one direction but is impractical in the other, and it is the sole obstacle preventing an unauthorized individual from spending your coins. A previous examination of quantum computing delved into the realm of physics, explaining that a quantum computer is fundamentally distinct from a conventional computer, operating at extremely low temperatures and small scales where particles exhibit unique behaviors not observed elsewhere on Earth. Another analysis explored the implications of directing a quantum computer at bitcoin, highlighting that bitcoin wallets depend on a one-way mathematical problem. While transforming a private key into a public address takes mere milliseconds, reversing this process to obtain the private key from the public address would require an ordinary computer an amount of time exceeding the age of the universe. A quantum algorithm known as Shor's algorithm significantly reduces this time gap. A recent paper by Google demonstrated that such an attack could be executed with substantially fewer resources than previously estimated, and within a timeframe that competes with bitcoin's block times. This article, the final in a series, focuses on the response to this threat. It discusses what is actually at risk, the measures bitcoin has taken so far, and whether a network designed to resist coordinated changes can successfully implement the most significant security upgrade in its history before the advent of capable quantum hardware. The pool of vulnerable bitcoin is substantial, with approximately 6.9 million bitcoin - roughly one-third of all mined bitcoin - stored in wallets whose public keys are permanently visible on the blockchain. This includes early bitcoin from the network's inaugural years, stored in an address format that published the public key by default, as well as any wallet that has been spent from, as spending reveals the key for the remaining balance. A quantum attacker would not need to compete with an ongoing transaction but could instead systematically breach wallets with exposed keys at their leisure. This includes the approximately 1 million bitcoin held by bitcoin's pseudonymous creator, Satoshi Nakamoto, which have remained untouched since the network's early days and are now categorized as exposed. The 2021 Taproot upgrade inadvertently expanded the problem. Taproot is an alteration to how bitcoin addresses function, intended to enhance transaction efficiency and privacy. However, it had the side effect of publishing the key that protects any remaining bitcoin at an address after a transaction, following the activation of Taproot. Although this was a deliberate design choice at the time, given the perceived longer timelines for quantum threats, it now poses a significant risk. Several solutions are being explored. While the quantum threat has sparked intense debate and other blockchains are preparing, no concrete plan has emerged from Bitcoin developers yet. Ethereum, a major competitor to Bitcoin, has had a formal quantum-resistant program in place since 2018. The Ethereum Foundation supports four full-time teams working on the migration, with over ten independent developer groups deploying weekly test networks. They have outlined specific upgrades across four upcoming network-wide changes, aiming to transition Ethereum's security to quantum-resistant mathematics. In contrast, Bitcoin lacks a comparable strategy. This does not mean there are no efforts underway to address the issue. One formal proposal, BIP-360, put forth by a group of developers and researchers, suggests introducing new quantum-safe address types that holders could voluntarily migrate to. Another proposal from BitMEX Research recommends implementing a detection system that would trigger defensive actions if a quantum attack is detected on the network. However, neither proposal has garnered broad support from Bitcoin's core developers, and they address different aspects of the problem. Prominent bitcoin advocate Nic Carter has voiced concerns, stating that the elliptic curve cryptography securing bitcoin wallets is on the verge of obsolescence. He praised Ethereum's approach as 'best in class' and criticized Bitcoin's as 'worst in class', citing developers who deny, downplay, or ignore the problem rather than engaging with it. Adam Back, CEO of Blockstream and an early bitcoin contributor, disagrees on the urgency but agrees on the need for preparation. He suggests that bitcoin should prepare now by incorporating optional upgrades in advance, allowing the network to migrate when necessary rather than reacting in crisis mode. The biggest challenge in implementing effective solutions against Bitcoin's quantum threat lies in coordination. Bitcoin's migration is more complex than Ethereum's due to reasons unrelated to the mathematics involved. Ethereum has a foundation that funds engineering work and a governance process that regularly implements major upgrades. In contrast, Bitcoin lacks a central authority and treats any form of centralized control as a failure mode, with a social consensus that protocol changes should be rare and difficult. While these principles have maintained network stability for nearly two decades, they also make addressing the quantum problem structurally more challenging for bitcoin. Migrating the 6.9 million exposed coins requires decisions that the network has spent years avoiding. Questions arise about whether old address formats should be frozen after a certain date to protect coins from future theft, whether exposed coins should be allowed to move to new quantum-safe addresses using their original keys, and what happens to coins whose owners cannot or will not migrate. The coins held by Satoshi Nakamoto pose a sharp example. Freezing old formats would protect the coins from theft but render them permanently inaccessible, including to Satoshi. Leaving the old formats open means those coins remain a potential target for whoever first develops a working quantum computer or gains access to one. Setting a migration deadline would force Satoshi to either move the coins, thereby revealing their ownership, or lose them. Every option would alter bitcoin's character in ways the network has historically resisted. The future is uncertain, with the Google paper's framing serving as a summary of the industry's current stance. A successful attack on bitcoin's mathematics should not be seen as a wake-up call to adopt post-quantum cryptography but rather as a potential signal that the adoption of such cryptography has already failed. This implies that by the time the threat becomes apparent, the window for response may have already closed. Developers are now faced with the question of whether a network built to resist coordinated change can coordinate the largest security upgrade in its history before quantum hardware becomes capable. Ethereum's eight-year head start suggests that starting now is the correct approach. Bitcoin's governance culture, however, suggests that the likely response will be to wait until the threat is demonstrated, at which point it may be too late.