Time Is Running Out for Bitcoin to Mitigate Quantum Computing Threat
Not all aspects of bitcoin are vulnerable to quantum computers. The process of bitcoin mining, which utilizes a type of math known as hashing, is secure against quantum attacks. The blockchain ledger and the rule that new bitcoins can only be created through mining would remain intact in the event of a quantum attack, with blocks continuing to be produced and the chain remaining operational. However, ownership of bitcoins would be at risk. Bitcoin wallets rely on a different type of math that converts a private key into a public address. This math is easily reversible in one direction but not the other, which is the primary barrier preventing unauthorized individuals from spending someone else's coins. A quantum algorithm known as Shor's algorithm can bypass this barrier, and a recent paper by Google demonstrated that such an attack could be executed with fewer resources than previously estimated, within a timeframe that competes with bitcoin's block times. This article, the final installment in a series, explores the potential consequences and the response of the bitcoin community. Approximately 6.9 million bitcoins, equivalent to one-third of all mined coins, are stored in wallets with publicly visible keys, making them vulnerable to quantum attacks. This includes early bitcoins from the network's inception, which were stored in an address format that published the public key by default, as well as any wallet that has been spent from, as spending reveals the key for any remaining balance. A quantum attacker would not need to rush against an ongoing transaction but could instead work through the wallets with exposed keys at their own pace. Bitcoin's pseudonymous creator, Satoshi Nakamoto, holds around 1 million bitcoins that have remained untouched since the network's early days and are now at risk. The 2021 Taproot upgrade inadvertently expanded the problem by making any bitcoin spent since its activation publish the key protecting the remaining balance at that address. While the quantum threat has sparked intense debate, concrete solutions have yet to emerge from bitcoin developers. In contrast, Ethereum has had a formal quantum-resistant program in place since 2018, with four full-time teams working on the migration and over ten independent developer groups releasing weekly test networks. Ethereum's plan involves specific upgrades across four upcoming network-wide changes, transitioning its security to quantum-resistant math. Bitcoin, on the other hand, lacks a comparable strategy. There are, however, efforts underway to address the issue, including a formal proposal known as BIP-360, which would introduce new quantum-safe address types for voluntary migration, and a competing proposal from BitMEX Research to implement a detection system that triggers defensive measures in the event of a quantum attack. Neither proposal has garnered broad support from bitcoin's core developers, and they address different aspects of the problem. Prominent bitcoin advocate Nic Carter has emphasized the urgency of the situation, stating that the elliptic curve cryptography securing bitcoin wallets is on the verge of obsolescence. He praised Ethereum's approach as 'best in class' and criticized bitcoin's as 'worst in class,' citing developers who deny or downplay the issue rather than engaging with it. Adam Back, CEO of Blockstream and an early contributor to bitcoin, disagrees on the urgency but agrees that bitcoin should prepare by implementing optional upgrades in advance. The primary challenge in implementing effective solutions against the quantum threat lies in bitcoin's governance structure. Ethereum's foundation and governance process facilitate major upgrades, whereas bitcoin's development culture is wary of central authority, and its social consensus favors rare and difficult protocol changes. This has kept the network stable for nearly two decades but makes addressing the quantum problem more difficult. Migrating the 6.9 million exposed coins requires decisions that the network has historically avoided, such as freezing old address formats or allowing exposed coins to move to quantum-safe addresses using their original keys. Every option would alter bitcoin's character in ways the network has traditionally resisted. The future of bitcoin's quantum resilience hinges on whether the network can coordinate a significant security upgrade before quantum computers become a reality.