Time is Running Out for Bitcoin to Counter Quantum Threat, Putting 6.9 Million BTC at Risk
Not all aspects of bitcoin are vulnerable to quantum computers. The process of bitcoin mining, which involves adding new blocks to the blockchain, utilizes a type of mathematics known as hashing that quantum computers are unable to break. As a result, the ledger and the rule that new bitcoins can only be created through mining would remain intact in the event of a quantum attack. However, ownership would be severely compromised. Bitcoin wallets rely on a different form of mathematics that converts a private key into a public address. This mathematics is easily reversible in one direction but not the other, which is the primary factor preventing unauthorized individuals from spending coins. A quantum algorithm known as Shor's algorithm significantly reduces the time required to reverse this process. Recently, Google published a paper demonstrating that this attack could be executed with fewer resources than previously estimated, and within a timeframe that competes with bitcoin's block times. This article, the final installment in a series, examines the potential consequences and the response of the bitcoin community. Approximately 6.9 million bitcoins, equivalent to one-third of all mined coins, are stored in wallets with publicly visible keys, making them susceptible to quantum attacks. This includes early bitcoins stored in addresses that published public keys by default, as well as any wallet that has been spent from, as spending reveals the key for the remaining balance. A quantum attacker would not need to compete with ongoing transactions but could instead target wallets with exposed keys at their own pace. Bitcoin's creator, Satoshi Nakamoto, holds around 1 million bitcoins that have remained untouched since the network's inception and are now at risk. The 2021 Taproot upgrade inadvertently expanded the problem by making transactions more efficient and private, but as a side effect, any bitcoin spent since its activation has published the key protecting the remaining balance at that address. Although the quantum threat has sparked intense debate, bitcoin developers have yet to propose a concrete solution. In contrast, Ethereum has had a formal quantum-resistant program in place since 2018, with four teams working full-time on the migration and multiple independent developer groups testing networks weekly. Ethereum has outlined specific upgrades and launched a website to track progress. Bitcoin, on the other hand, lacks a unified strategy. There are proposals, such as BIP-360, which suggests introducing new quantum-safe address types, and a competing proposal from BitMEX Research to implement a detection system that triggers defensive actions in the event of a quantum attack. However, neither proposal has gained broad support from core developers, and they address different aspects of the problem. The lack of a centralized authority and a governance process that facilitates regular upgrades makes it challenging for bitcoin to respond to the quantum threat. The migration of 6.9 million exposed coins requires decisions that the network has historically avoided, such as whether to freeze old address formats or allow exposed coins to move to new quantum-safe addresses. Every option would alter the character of bitcoin in ways the network has traditionally refused to change. The next steps will be crucial in determining whether bitcoin can coordinate a significant security upgrade before the threat becomes a reality.