Time Runs Out for Bitcoin to Mitigate Quantum Computing Threat, Putting 6.9 Million BTC at Risk
Not all aspects of bitcoin are vulnerable to quantum computers. The process of bitcoin mining, which utilizes a type of mathematics known as hashing, is secure against quantum threats. The underlying ledger and the rule that new bitcoins can only be created through mining would remain intact in the event of a quantum attack, with blocks continuing to be produced and the chain remaining operational. However, what is at risk is ownership. Bitcoin wallets rely on a different mathematical approach that converts a private key into a public address. This math is straightforward in one direction but virtually impossible in the other, and it is this challenge that prevents unauthorized individuals from spending coins. The first part of this series on quantum computing delved into the physics behind it, explaining how a quantum computer is fundamentally different from a traditional computer, operating at extremely low temperatures and small scales where particles exhibit unique behaviors. The second part examined the implications of quantum computing for bitcoin, highlighting how bitcoin wallets depend on a one-way mathematical problem. Converting a private key into a public address takes mere milliseconds, but reversing this process would take a conventional computer longer than the universe's age. A quantum algorithm called Shor's algorithm significantly reduces this timeframe. A recent paper by Google demonstrated that such an attack could be executed with fewer resources than previously thought, posing a significant threat to bitcoin. This final piece in the series focuses on the response to this threat, discussing what is at risk, the measures bitcoin has taken, and whether the network can coordinate a major security upgrade before quantum hardware becomes a reality. Approximately 6.9 million bitcoins, roughly one-third of all mined coins, are stored in wallets with publicly visible keys, making them vulnerable to quantum attacks. This includes early bitcoins and any wallet that has been spent from, as spending reveals the key. A quantum attacker would not need to compete with ongoing transactions but could systematically target exposed wallets. Bitcoin's pseudonymous creator, Satoshi Nakamoto, holds about 1 million bitcoins that are now at risk. The 2021 Taproot upgrade inadvertently expanded the problem by making any spent bitcoin publish its protective key, although this was a reasonable trade-off at the time given the perceived longer timeline for quantum threats. Currently, there are no concrete plans from bitcoin developers to address the quantum threat, unlike Ethereum, which has a formal quantum-resistant program in place since 2018. Ethereum's approach includes four full-time teams and numerous independent developer groups working towards migrating to quantum-safe mathematics. In contrast, bitcoin has proposals like BIP-360, which suggests introducing new quantum-safe address types, and a competing proposal from BitMEX Research for a detection system to trigger defensive actions in case of a quantum attack. Neither proposal has broad support from core developers, and they address different aspects of the problem. Prominent bitcoin advocate Nic Carter has emphasized the urgency, stating that the current elliptic curve cryptography is on the verge of obsolescence and praising Ethereum's approach while criticizing bitcoin's lack of action. Adam Back, CEO of Blockstream and an early bitcoin contributor, agrees on the need for preparation but disagrees on the immediacy of the threat. The main challenge for bitcoin is not the mathematical solution but the coordination problem. Bitcoin's development culture and lack of central authority make implementing changes difficult. The network's stability over nearly two decades is a testament to its design, but this also makes addressing the quantum threat structurally harder. Migrating the exposed coins requires decisions that the network has historically avoided, such as freezing old address formats or allowing exposed coins to move to new quantum-safe addresses. Every option poses significant changes to bitcoin's character, including the fate of Satoshi's untouched coins. The recent Google paper frames the industry's stance, suggesting that a successful attack should not be the catalyst for adopting post-quantum cryptography but rather a signal that such adoption may have already failed. This implies that by the time the threat becomes apparent, the window for response may have closed. Developers are faced with the question of whether a network designed to resist coordinated change can implement its largest security upgrade before quantum hardware advances. Ethereum's head start and proactive approach suggest the importance of starting now, while bitcoin's governance culture may lead to waiting until the threat is more visible, a strategy that may not be effective if the timeline is shorter than expected.