Time is running out for bitcoin to counter the quantum threat, with 6.9 million BTC at risk, including Satoshi's

Not all aspects of bitcoin are vulnerable to quantum computers. The process of bitcoin mining, which involves adding new blocks to the blockchain, utilizes a type of mathematics known as hashing that quantum computers are unable to crack. As a result, the ledger and the rule that new bitcoins can only be created through mining would remain intact in the event of a quantum attack. The production of blocks would continue, and the chain would remain operational. However, ownership would be severely compromised. Bitcoin wallets rely on a different type of mathematics that converts a private key into a public address. This math is straightforward in one direction but virtually impossible in the other, making it the sole barrier that prevents unauthorized individuals from spending your coins. The first part of this series on quantum computing delved into the physics behind it, explaining how a quantum computer is fundamentally distinct from a regular computer, operating at extremely low temperatures and small scales where particles exhibit unique behaviors. The second part explored the implications of pointing a quantum machine at bitcoin, highlighting how bitcoin wallets rely on a one-way mathematical problem. Converting a private key into a public address takes mere milliseconds, but reversing the process would take a conventional computer longer than the universe's age. A quantum algorithm known as Shor's algorithm significantly reduces this gap. A recent paper by Google demonstrated that this attack could be executed with far fewer resources than previously estimated, and within a time frame that competes with bitcoin's block times. This final piece in the series focuses on the response to this threat, examining what is at risk, the measures bitcoin has taken, and whether a network designed to resist coordinated changes can implement the largest security upgrade in its history before quantum hardware becomes a reality. The exposed pool of bitcoin is substantial, with approximately 6.9 million bitcoin, or about one-third of all mined bitcoin, stored in wallets whose public keys are permanently visible on the blockchain. This includes early bitcoin from the network's first years, which was stored in an address format that published the public key by default, as well as any wallet that has ever been spent from, as spending reveals the key for any remaining balance. A quantum attacker would not need to compete with an ongoing transaction; instead, they could systematically work through wallets with exposed keys at their own pace. Bitcoin's pseudonymous creator, Satoshi Nakamoto, holds roughly 1 million bitcoin that has remained untouched since the network's early days and now falls into the exposed category. The 2021 Taproot upgrade inadvertently expanded the problem. Taproot is a modification to how bitcoin addresses function, intended to make transactions more efficient and private. However, it had the side effect of publishing the key that protects any remaining bitcoin at an address after a transaction, for any bitcoin spent since Taproot was activated. This was not an oversight but a reasonable trade-off at the time, given the perceived longer timelines for quantum threats. Currently, there are efforts underway to address the quantum threat, although nothing concrete has emerged from Bitcoin developers yet. Ethereum, a major competitor to Bitcoin, has had a formal quantum-resistant program in place since 2018. The Ethereum Foundation supports four full-time teams working on the migration, with over ten independent developer groups releasing weekly test networks. They have outlined specific upgrades across four upcoming network-wide changes, aiming to transition Ethereum's security to quantum-resistant mathematics. In contrast, Bitcoin lacks a comparable strategy. There are, however, proposals and efforts to solve the problem. One such formal proposal, BIP-360, from a group of developers and researchers, suggests introducing new quantum-safe address types that holders could voluntarily migrate to. Another proposal from BitMEX Research would implement a detection system that triggers defensive actions if a quantum attack is observed on the network. Neither proposal has gained broad support from Bitcoin's core developers, and they address different aspects of the problem. Nic Carter, a prominent bitcoin advocate, has highlighted the issue, stating that the elliptic curve cryptography securing bitcoin wallets is on the verge of becoming obsolete. He praised Ethereum's approach as 'best in class' and criticized Bitcoin's as 'worst in class', citing developers who deny, downplay, or ignore the problem rather than engaging with it. Adam Back, the CEO of Blockstream and an early bitcoin contributor, disagrees on the urgency but agrees that bitcoin should prepare now by building in optional upgrades that allow the network to migrate when necessary, rather than reacting in a crisis. The main challenge in implementing effective solutions against Bitcoin's quantum threat lies in coordination. Bitcoin's migration is more difficult than Ethereum's due to reasons unrelated to the mathematics involved. Ethereum has a foundation that funds engineering work and a governance process that regularly passes significant upgrades. In contrast, Bitcoin lacks a central authority and treats any form of centralized governance as a failure mode, with a social consensus that changes to the protocol should be rare and difficult. These principles have maintained the network's stability for nearly two decades but make addressing the quantum problem structurally harder for bitcoin. Migrating the 6.9 million exposed coins requires decisions that the network has spent twenty years avoiding. Questions arise about whether old address formats should be frozen after a certain date to protect coins from future theft, whether exposed coins should be allowed to move to new quantum-safe addresses using their original keys, and what happens to coins whose owners cannot or will not migrate. The case of Satoshi's coins is particularly poignant, as freezing old formats would protect the coins but make them permanently inaccessible, including to Satoshi, while leaving the old formats open means those coins are at risk of being stolen by the first entity to build a working quantum computer. Setting a migration deadline would force Satoshi to either move the coins, revealing their ownership, or lose them. Every option changes bitcoin's character in ways the network has historically refused to change. The Google paper frames the industry's stance, suggesting that a successful attack on bitcoin's mathematics should not be seen as a wake-up call to adopt post-quantum cryptography but rather as a potential signal that the adoption of post-quantum cryptography has already failed. This implies that by the time the threat becomes apparent, the window to respond may have already closed. Developers are now faced with the question of whether a network built to resist coordinated change can coordinate the largest security upgrade in its history before quantum hardware catches up with theoretical capabilities. Ethereum's eight-year head start in addressing quantum resistance suggests that starting now is the correct approach. However, Bitcoin's governance culture indicates that the network might wait until the threat is demonstrated before taking action. Only one of these approaches will be effective if the timeline proves to be shorter than optimists estimate.