Time is Running Out for Bitcoin to Counter Quantum Threat, Putting 6.9 Million BTC at Risk

Not all aspects of bitcoin are vulnerable to quantum computer attacks. The process of bitcoin mining, which involves adding new blocks to the blockchain, utilizes a type of mathematics called hashing that is resistant to quantum computing. As a result, the blockchain itself and the rule that new bitcoins can only be created through mining would remain intact in the event of a quantum attack. The production of blocks and the operation of the chain would continue uninterrupted. However, ownership of bitcoins would be at risk. Bitcoin wallets rely on a different type of mathematics that converts a private key into a public address. This mathematical process is straightforward in one direction but virtually impossible in the other, and it is the sole barrier preventing unauthorized individuals from spending someone else's coins. A previous article in this series delved into the physics of quantum computing, explaining how it differs fundamentally from classical computing. It begins with a very cold, tiny loop of metal where particles exhibit behavior not seen elsewhere on Earth. The second part of the series examined the implications of quantum computing for bitcoin, highlighting the vulnerability of bitcoin wallets to quantum algorithms like Shor's. A recent paper by Google demonstrated that such an attack could be launched with fewer resources than previously thought, and within a timeframe that competes with bitcoin's block creation rate. This final installment focuses on the response to this threat, including what is at risk, the measures bitcoin has taken so far, and whether a network designed to resist coordinated changes can implement the largest security upgrade in its history before quantum hardware becomes a reality. The pool of bitcoin at risk is substantial, with approximately 6.9 million coins - about one-third of all mined bitcoins - stored in wallets whose public keys are permanently visible on the blockchain. This includes early bitcoins from the network's first years, which were stored in an address format that published the public key by default, as well as any wallet that has been used for transactions, as spending reveals the key for any remaining balance. A quantum attacker would not need to rush against an ongoing transaction but could systematically target wallets with exposed keys at their leisure. This includes the roughly 1 million untouched bitcoins held by bitcoin's pseudonymous creator, Satoshi Nakamoto, which are now in the exposed category. The 2021 Taproot upgrade inadvertently expanded the problem by changing how bitcoin addresses work, aiming to make transactions more efficient and private. However, it had the side effect of publishing the key protecting any remaining bitcoin at an address after a transaction, which was a reasonable tradeoff at the time given the perceived longer timelines for quantum threats. Currently, there are no concrete plans from Bitcoin developers to address the quantum threat, unlike Ethereum, which has had a formal quantum-resistant program in place since 2018. Ethereum's approach includes four full-time teams working on the migration, with specific upgrades planned across four network-wide changes to secure Ethereum against quantum computers. In contrast, Bitcoin has proposals like BIP-360, which suggests adding new quantum-safe address types for voluntary migration, and a proposal from BitMEX Research for a detection system to trigger defensive actions in case of a quantum attack. Neither proposal has gained broad support from core developers, and they address different parts of the problem. The challenge for Bitcoin lies in its governance culture, which treats any central authority as a failure and holds that changes to the protocol should be rare and difficult. This has kept the network stable for nearly two decades but makes addressing the quantum problem structurally harder. Migrating the exposed coins requires decisions that the network has historically avoided, such as whether to freeze old address formats to protect coins from future theft or allow exposed coins to move to new quantum-safe addresses. Every option would change Bitcoin's character in ways it has refused to change. The future of Bitcoin's security against quantum threats depends on whether the network can coordinate a significant upgrade before the emergence of capable quantum hardware.