Time Running Out for Bitcoin to Counter Quantum Computing Threat

Not all aspects of bitcoin are vulnerable to quantum computers. The process of bitcoin mining, which utilizes a type of math known as hashing, is resistant to quantum attacks. As a result, the blockchain ledger and the rule governing bitcoin creation through mining would remain intact in the face of a quantum threat. However, ownership of bitcoins is a different story. Bitcoin wallets rely on a type of math that converts a private key into a public address. This math is easy to perform in one direction but virtually impossible in the other, which is the primary obstacle preventing unauthorized individuals from spending someone else's coins. A quantum algorithm known as Shor's algorithm can bridge this gap, and a recent paper by Google demonstrated that this attack could be executed with fewer resources than previously estimated, within a timeframe that competes with bitcoin's block times. This article, the final installment in a series, focuses on the response to this threat. It examines what is at risk, the measures bitcoin has taken to address the issue, and whether a network designed to resist coordinated change can implement the most significant security upgrade in its history before quantum hardware becomes a reality. The pool of vulnerable bitcoins is substantial, with roughly 6.9 million coins, approximately one-third of all mined bitcoins, stored in wallets whose public keys are permanently visible on the blockchain. This includes early bitcoins from the network's first years, which were stored in an address format that published the public key by default, as well as any wallet that has been spent from, as spending reveals the key for the remaining balance. A quantum attacker would not need to compete with an ongoing transaction; instead, they could systematically target wallets with exposed keys at their leisure. Bitcoin's pseudonymous creator, Satoshi Nakamoto, holds approximately 1 million bitcoins that have remained untouched since the network's early days and are now categorized as exposed. The 2021 Taproot upgrade inadvertently expanded the problem by making transactions more efficient and private. However, a side effect of this upgrade was that any bitcoin spent since its activation has published the key protecting the remaining balance at that address. Although this was not an error, it was a reasonable trade-off at the time, given the perceived quantum timelines. Currently, there are no concrete plans from Bitcoin developers to address the quantum threat. In contrast, Ethereum, one of Bitcoin's main competitors, has had a formal quantum-resistant program in place since 2018. The Ethereum Foundation has dedicated teams working full-time on the migration, with multiple independent developer groups releasing weekly test networks. They have outlined a plan for specific upgrades across four upcoming network-wide changes, aiming to transition Ethereum's security to quantum-resistant math. Bitcoin, on the other hand, lacks a comparable strategy. There are, however, efforts underway to solve the problem. One proposal, BIP-360, suggests introducing new quantum-safe address types that holders could voluntarily migrate to. Another proposal from BitMEX Research recommends implementing a detection system that triggers defensive action if a quantum attack is observed on the network. Neither proposal has garnered broad support from Bitcoin's core developers, and they address different aspects of the problem. Nic Carter, a prominent Bitcoin advocate, has emphasized the urgency of the situation, stating that the elliptic curve cryptography used to secure Bitcoin wallets is on the verge of becoming obsolete. He praised Ethereum's approach as 'best in class' and criticized Bitcoin's as 'worst in class,' citing developers who deny, downplay, or ignore the problem rather than engaging with it. Adam Back, the CEO of Blockstream and an early Bitcoin contributor, disagrees on the urgency but concurs on the need for preparation. He suggests that Bitcoin should develop optional upgrades in advance, allowing the network to migrate when necessary, rather than reacting in a crisis. The primary challenge in implementing effective solutions against Bitcoin's quantum threat lies in its migration, which is more complex than Ethereum's due to reasons unrelated to the math itself. Ethereum has a foundation that funds engineering work and a governance process that regularly passes significant upgrades. In contrast, Bitcoin lacks a central authority and a governance process, with its development culture treating any central authority as a potential failure mode. This has kept the network stable for nearly two decades but also makes addressing the quantum problem structurally more difficult for Bitcoin. Migrating the 6.9 million exposed coins requires decisions that the network has avoided for twenty years. The question remains whether old address formats should be frozen after a certain date to protect coins from future theft or if exposed coins should be allowed to move to new quantum-safe addresses using their original keys. The fate of coins whose owners cannot or will not migrate also needs to be determined. Satoshi's coins serve as a prime example, as freezing old formats would protect them from theft but render them permanently inaccessible, including to Satoshi. Leaving the old formats open means those coins remain a potential target for whoever develops a functioning quantum computer or gains access to one. Setting a migration deadline would force Satoshi to either move the coins, thereby revealing their ownership, or risk losing them. Every option would alter Bitcoin's character in ways the network has historically resisted. The Google paper's framing serves as a summary of the industry's current stance, suggesting that a successful attack on Bitcoin's math should not be seen as a wake-up call to adopt post-quantum cryptography but rather as a potential indication that the window for adoption has already closed. This implies that by the time the threat becomes apparent, the opportunity to respond may have already passed. Developers are now faced with the question of whether a network designed to resist coordinated change can coordinate the most significant security upgrade in its history before quantum hardware catches up. Ethereum's eight-year head start suggests that the correct approach is to start preparing now. However, Bitcoin's governance culture indicates that the likely response will be to wait until the threat is demonstrated before taking action. Only one of these approaches will be effective if the timeline proves to be shorter than optimists predict.