Time Running Out for Bitcoin to Counter Quantum Threat, With 6.9 Million BTC at Risk, Including Satoshi's Holdings
Not all aspects of Bitcoin are vulnerable to quantum computers. The process of mining, which involves adding new blocks to the blockchain, utilizes a type of mathematics known as hashing that quantum computers are unable to compromise. The blockchain itself and the rule that new Bitcoins can only be created through mining would survive a quantum attack, with blocks continuing to be produced and the chain remaining intact. However, ownership is a different story. Bitcoin wallets rely on a distinct type of mathematics that converts a private key into a public address, which anyone can see. This mathematics functions effortlessly in one direction but not the other, and it is the sole factor preventing an unknown individual from spending your coins. Part 1 of this series delved into the physics of quantum computing, explaining that a quantum computer is fundamentally different from a regular computer, starting with a very cold, very small loop of metal where particles exhibit unique behaviors not seen elsewhere on Earth. Part 2 examined the implications of directing this machine at Bitcoin, revealing that Bitcoin wallets depend on a one-way mathematical problem. Converting a private key into a public address takes milliseconds, whereas reversing the process, from public address back to private key, would take a regular computer longer than the age of the universe. A quantum algorithm known as Shor's algorithm reduces this gap. A recent paper by Google demonstrated that the attack could be executed with far fewer resources than previously estimated, within a window that competes with Bitcoin's block times. This final piece in the series focuses on the response, discussing what is actually at risk, what Bitcoin has done about it, and whether a network designed to resist coordinated change can coordinate the most significant security upgrade in its history before the hardware becomes a threat. The pool of exposed Bitcoin is substantial, with approximately 6.9 million Bitcoin, about one-third of all mined Bitcoin, stored in wallets whose public keys are permanently visible on the blockchain. Most of this is early Bitcoin from the network's initial years, stored in an address format that published the public key by default. It also includes any wallet that has ever been spent from, as spending reveals the key for whatever remains. A quantum attacker would not need to compete with a transaction in progress but could instead work through the wallets with already exposed keys at their own pace, one by one. Bitcoin's pseudonymous creator, Satoshi Nakamoto, holds roughly 1 million Bitcoin, untouched since the network's early days, and this stack now falls into the exposed category. The 2021 Taproot upgrade expanded the problem. Taproot is a modification to how Bitcoin addresses function, intended to make transactions more efficient and private. A side effect was that any Bitcoin spent since Taproot's activation has published the key protecting whatever remains at that address. This was not a mistake but a reasonable trade-off at the time, when quantum timelines appeared much longer than they do now. Currently, there are efforts underway to address the quantum threat. While the quantum threat has sparked intense debate in recent months and other blockchains are preparing, nothing concrete has emerged from Bitcoin developers yet. Ethereum, which can be considered one of Bitcoin's largest competitors among institutional investors looking at the crypto market, has had a formal quantum-resistant program since 2018. The Ethereum Foundation runs four teams working on the migration full-time, with more than ten independent developer groups shipping weekly test networks. The plan maps specific upgrades across four upcoming network-wide changes, moving Ethereum's security to new mathematics that quantum computers cannot break. It has even launched a dedicated website, pq.ethereum.org, to publish its progress. Bitcoin has no equivalent strategy so far. That doesn't mean there aren't any efforts out there to solve it. One such formal proposal is BIP-360 from a group of developers and researchers. It would add new quantum-safe address types that holders could voluntarily migrate to. A competing proposal from BitMEX Research would install a detection system that triggers defensive action if a quantum attack is observed on the network. However, neither has broad support from Bitcoin's core developers, and the two proposals solve different halves of the problem. Nic Carter, one of Bitcoin's prominent advocates, has called it out in the past months. "Elliptic curve cryptography is on the brink of obsolescence," Carter wrote on X, referring to the mathematics that secures Bitcoin wallets. He described Ethereum's approach as "best in class" and Bitcoin's as "worst in class," citing developers who "deny, gaslight, gatekeep, bury heads in sand" rather than engage with the problem. Adam Back, the Blockstream CEO and a prominent early Bitcoin contributor, disagrees on the urgency but agrees on the direction. "Quantum computing still has a lot to prove. Current systems are essentially lab experiments," Back said at a conference earlier this month. But he also said Bitcoin should prepare now, with optional upgrades built in advance so the network can migrate when needed, rather than scrambling in a crisis. The biggest challenge in implementing effective solutions against Bitcoin's quantum threat lies in the coordination problem. Bitcoin's migration is harder than Ethereum's for reasons unrelated to the actual mathematics. Ethereum has a foundation that funds engineering work and a governance process that regularly passes major upgrades. Bitcoin has neither. Its development culture treats any central authority as a failure mode, and its social consensus holds that changes to the protocol should be rare and hard. Those principles have kept the network stable for nearly two decades, but they also make the quantum problem structurally harder for Bitcoin to solve. Migrating the 6.9 million exposed coins requires decisions the network has spent twenty years avoiding. Should old address formats be frozen after a certain date to protect coins from future theft? Should exposed coins be allowed to move to new quantum-safe addresses using their original keys? What happens to coins whose owners cannot or will not migrate? Satoshi's coins are the sharpest example. Freezing old formats protects the coins from theft but makes them permanently inaccessible, including to Satoshi. Leaving the old formats open means those coins sit as a standing prize for whoever builds the first working quantum computer or has access to a quantum computer and wants to attack. Setting a migration deadline forces Satoshi to either move the coins, revealing their ownership, or lose them. Every option changes Bitcoin's character in ways the network has historically refused to change it. The Google paper's own framing is a summary of where the industry stands. A successful attack on the mathematics Bitcoin uses "should not be seen as a wake-up call to adopt post-quantum cryptography as much as a potential signal that PQC adoption has already failed." This means that by the time the threat becomes visible, the window to respond may already have closed. Developers now face a question of whether a network built to resist coordinated change can coordinate the biggest security upgrade in its history before the hardware catches up to the theory. Ethereum's eight-year head start suggests the correct answer is to start now. Bitcoin's governance culture suggests the likely answer is to wait until the threat is demonstrated, then move. Only one of those answers works if the timeline turns out to be shorter than the optimists' estimate.