Time Runs Out for Bitcoin to Counter Quantum Computing Threat, Putting 6.9 Million BTC at Risk
Not all aspects of bitcoin are vulnerable to quantum computers. The process of bitcoin mining, which involves adding new blocks to the blockchain, utilizes a type of mathematics known as hashing that quantum computers are unable to breach effectively. As a result, the blockchain itself and the rule that new bitcoins can only be created through mining would survive an attack from a quantum computer. The production of blocks and the continuation of the chain would remain uninterrupted. However, what would be compromised is ownership. Bitcoin wallets are secured by a different form of mathematics that converts a private key into a public address visible to everyone. This mathematics operates effortlessly in one direction but is impractical in the reverse, and it is the sole barrier preventing an unknown individual from spending your coins. The first part of this series on quantum computing delved into the realm of physics, explaining that a quantum computer is fundamentally distinct from a conventional computer. It begins with an extremely cold, minuscule loop of metal where particles exhibit behaviors not observed elsewhere on Earth. The second installment examined the implications of directing this machine at bitcoin. Bitcoin wallets rely on a one-way mathematical problem. Converting a private key into a public address takes milliseconds, whereas reversing the process, from a public address back to the private key, would require a conventional computer more time than the age of the universe. A quantum algorithm known as Shor's algorithm reduces this gap. A recent paper by Google demonstrated that the attack could be executed with significantly fewer resources than previously estimated, within a time frame that competes with bitcoin's block times. This final piece in the series focuses on the response. It discusses what is actually at risk, the measures bitcoin has taken, and whether a network designed to resist coordinated change can implement the most significant security upgrade in its history before the relevant hardware is developed. The pool of exposed assets is substantial, with roughly 6.9 million bitcoin, equivalent to about one-third of all mined bitcoin, stored in wallets with publicly visible keys on the blockchain. Most of this bitcoin originates from the network's early years and is stored in an address format that, by default, publishes the public key. It also includes any wallet that has been spent from, as spending reveals the key for any remaining balance. A quantum attacker would not need to compete with an ongoing transaction; instead, they could process the wallets with exposed keys at their own pace. Bitcoin's pseudonymous creator, Satoshi Nakamoto, holds approximately 1 million bitcoin that have remained untouched since the network's inception and now fall into the exposed category. The 2021 Taproot upgrade expanded the problem. Taproot is a modification to how bitcoin addresses function, intended to make transactions more efficient and private. A side effect was that any bitcoin spent after Taproot's activation has published the key protecting the remaining balance at that address. Although this was not an error, it was a reasonable trade-off at the time, given that quantum timelines seemed much longer than they do now. Several proposals are in the works to address the quantum threat, but nothing concrete has emerged from bitcoin developers yet. Ethereum, which can be considered one of bitcoin's main competitors among institutional investors in the crypto market, has had a formal quantum-resistant program in place since 2018. The Ethereum Foundation operates four teams working full-time on the migration, with over ten independent developer groups releasing weekly test networks. The plan outlines specific upgrades across four upcoming network-wide changes, transitioning Ethereum's security to new mathematics that quantum computers cannot breach. In contrast, bitcoin lacks a comparable strategy. This does not mean there are no efforts to solve the issue. One formal proposal, BIP-360, from a group of developers and researchers, suggests introducing new quantum-safe address types that holders could voluntarily migrate to. A competing proposal from BitMEX Research involves installing a detection system that triggers defensive actions if a quantum attack is observed on the network. However, neither proposal has broad support from bitcoin's core developers, and they address different aspects of the problem. The biggest challenge in implementing effective solutions against bitcoin's quantum threat lies in coordination. Bitcoin's migration is harder than Ethereum's due to reasons unrelated to the mathematics itself. Ethereum has a foundation that funds engineering work and a governance process that regularly passes major upgrades. Bitcoin has neither, with a development culture that views any central authority as a failure mode and a social consensus that changes to the protocol should be rare and difficult. These principles have kept the network stable for nearly two decades but also make the quantum problem structurally harder for bitcoin to solve. Migrating the 6.9 million exposed coins requires decisions that the network has spent twenty years avoiding. The question of what happens next is critical, with the Google paper's framing serving as a summary of the industry's stance. A successful attack on bitcoin's mathematics should not be viewed as a wake-up call to adopt post-quantum cryptography but rather as a potential signal that the adoption of post-quantum cryptography has already failed. This implies that by the time the threat becomes apparent, the window to respond may have already closed. Developers now face the question of whether a network built to resist coordinated change can coordinate the largest security upgrade in its history before the hardware catches up to the theory. Ethereum's eight-year head start suggests that starting now is the correct approach, while bitcoin's governance culture suggests that waiting until the threat is demonstrated may be the more likely course of action. Only one of these approaches will be effective if the timeline turns out to be shorter than optimists estimate.