Time Running Out for Bitcoin to Mitigate Quantum Threat, 6.9 Million BTC at Risk

Not all aspects of Bitcoin are vulnerable to quantum computer attacks. The process of mining, which involves adding new blocks to the blockchain, utilizes a type of mathematics known as hashing that quantum computers cannot effectively breach. Consequently, the blockchain itself and the rule that new Bitcoins can only be created through mining would remain intact in the event of a quantum attack. Blocks would continue to be produced, and the chain would persist. However, ownership would be severely compromised. Bitcoin wallets rely on a different form of mathematics that converts a private key into a public address visible to everyone. This mathematics operates effortlessly in one direction but is impractical in the other, and it is the sole barrier preventing unauthorized individuals from spending your coins. Part 1 of this series on quantum computing delved into the physics behind it, explaining that a quantum computer is fundamentally distinct from a regular computer, originating from a very cold, small metal loop where particles exhibit unique behaviors not observed elsewhere on Earth. Part 2 explored the implications of directing this machine at Bitcoin, highlighting that Bitcoin wallets depend on a one-way mathematical problem. Converting a private key into a public address takes mere milliseconds, whereas reversing this process, from public address back to private key, would take a conventional computer longer than the age of the universe. A quantum algorithm known as Shor's algorithm bridges this gap. A recent paper by Google demonstrated that this attack could be executed with significantly fewer resources than previously estimated, within a timeframe that competes with Bitcoin's block times. This final piece in the series focuses on the response, examining what is actually at risk, the measures Bitcoin has taken, and whether a network designed to resist coordinated change can coordinate the most substantial security upgrade in its history before the relevant hardware is developed. The pool of exposed Bitcoin is substantial, with approximately 6.9 million Bitcoin, roughly one-third of all mined Bitcoin, stored in wallets whose public keys are permanently visible on the blockchain. This includes early Bitcoin from the network's inaugural years, stored in an address format that published the public key by default, as well as any wallet that has been spent from, since spending reveals the key for any remaining balance. A quantum attacker would not need to compete with an ongoing transaction; instead, they could systematically work through wallets with exposed keys at their leisure. Bitcoin's pseudonymous creator, Satoshi Nakamoto, holds approximately 1 million Bitcoin, untouched since the network's early days, which now falls into the exposed category. The 2021 Taproot upgrade expanded the problem. Taproot is a modification to how Bitcoin addresses function, intended to make transactions more efficient and private. A side effect was that any Bitcoin spent since Taproot's activation has published the key protecting the remaining balance at that address. This was not an error but a reasonable trade-off at the time, given that quantum timelines appeared much longer than they do now. Several efforts are underway to address the quantum threat, although nothing concrete has emerged from Bitcoin developers yet. Ethereum, a significant competitor to Bitcoin among institutional investors, has had a formal quantum-resistant program in place since 2018. The Ethereum Foundation operates four full-time teams working on the migration, with over ten independent developer groups releasing weekly test networks. The plan outlines specific upgrades across four upcoming network-wide changes, transitioning Ethereum's security to new mathematics that quantum computers cannot break. In contrast, Bitcoin lacks an equivalent strategy. That does not mean there are no efforts to solve it. One formal proposal, BIP-360, from a group of developers and researchers, would introduce new quantum-safe address types that holders could voluntarily migrate to. A competing proposal from BitMEX Research would implement a detection system that triggers defensive action if a quantum attack is observed on the network. However, neither proposal has broad support from Bitcoin's core developers, and they address different aspects of the problem. Prominent Bitcoin advocate Nic Carter has highlighted the issue, stating that elliptic curve cryptography, which secures Bitcoin wallets, is on the brink of obsolescence. He described Ethereum's approach as 'best in class' and Bitcoin's as 'worst in class,' citing developers who deny, gaslight, or ignore the problem rather than engaging with it. Adam Back, the CEO of Blockstream and an early Bitcoin contributor, disagrees on the urgency but agrees on the direction, suggesting that Bitcoin should prepare now with optional upgrades built in advance, allowing the network to migrate when needed rather than reacting in a crisis. The biggest challenge in implementing effective solutions against Bitcoin's quantum threat lies in coordination. Bitcoin's migration is harder than Ethereum's due to reasons unrelated to the actual mathematics. Ethereum has a foundation that funds engineering work and a governance process that regularly passes major upgrades, whereas Bitcoin has neither. Its development culture views any central authority as a failure mode, and its social consensus holds that changes to the protocol should be rare and difficult. These principles have kept the network stable for nearly two decades but also make the quantum problem structurally harder for Bitcoin to solve. Migrating the 6.9 million exposed coins requires decisions that the network has spent twenty years avoiding. The Google paper frames the industry's stance, suggesting that a successful attack on Bitcoin's mathematics should not be seen as a wake-up call to adopt post-quantum cryptography but rather as a potential signal that such adoption has already failed. This implies that by the time the threat becomes apparent, the window to respond may have already closed. Developers now face the question of whether a network built to resist coordinated change can coordinate the biggest security upgrade in its history before the hardware catches up to the theory. Ethereum's eight-year head start suggests that starting now is the correct approach, while Bitcoin's governance culture suggests waiting until the threat is demonstrated before acting. Only one of these approaches will be effective if the timeline turns out to be shorter than estimated.