Time's Running Out for Bitcoin to Counter Quantum Threat, With 6.9 Million BTC at Risk
Not all aspects of bitcoin are vulnerable to quantum computing attacks. The process of bitcoin mining, which involves adding new blocks to the blockchain, relies on a type of mathematics known as hashing that is resistant to quantum computing. As a result, the blockchain itself and the rule that new bitcoins can only be created through mining would remain intact in the event of a quantum attack. The production of blocks would continue, and the chain would remain operational. However, ownership would be severely compromised. Bitcoin wallets are secured by a different type of mathematics that converts a private key into a public address. This mathematics is straightforward in one direction but virtually impossible in the other, and it is the sole barrier preventing unauthorized individuals from spending your coins. The first installment of this series on quantum computing delved into the underlying physics. A quantum computer is not merely a faster version of a conventional computer; it is a fundamentally distinct type of machine that operates at extremely low temperatures and small scales, where particles exhibit behaviors that are not observed elsewhere on Earth. The second installment examined the implications of directing such a machine at bitcoin. Bitcoin wallets rely on a mathematical problem that is virtually insoluble. Converting a private key into a public address takes mere milliseconds, whereas reversing the process would take a conventional computer longer than the age of the universe. However, a quantum algorithm known as Shor's algorithm can solve this problem efficiently. A recent paper by Google demonstrated that this attack could be executed with significantly fewer resources than previously estimated, and within a time frame that competes with bitcoin's block times. This final installment of the series focuses on the response to this threat. It examines what is actually at risk, the measures bitcoin has taken to address the issue, and whether a network designed to resist coordinated change can execute the most significant security upgrade in its history before the advent of quantum computing hardware. The pool of vulnerable bitcoin is substantial, with approximately 6.9 million coins, or about one-third of all mined bitcoin, stored in wallets whose public keys are permanently visible on the blockchain. The majority of these coins are from the network's early days and are stored in an address format that published the public key by default. This also includes any wallet that has been spent from, as spending reveals the key for any remaining balance. A quantum attacker would not need to compete with an ongoing transaction; instead, they could systematically compromise wallets with exposed keys at their own pace. Bitcoin's pseudonymous creator, Satoshi Nakamoto, holds approximately 1 million bitcoin that have remained untouched since the network's early days and are now classified as exposed. The 2021 Taproot upgrade exacerbated the problem by introducing a change to how bitcoin addresses function, aimed at enhancing transaction efficiency and privacy. As a result, any bitcoin spent since the activation of Taproot has published the key protecting the remaining balance at that address. This was a deliberate design choice at the time, given the perceived longer timelines for quantum computing. Currently, there are efforts underway to address the quantum threat, although nothing concrete has emerged from Bitcoin developers yet. In contrast, Ethereum, a major competitor to Bitcoin, has had a formal quantum-resistant program in place since 2018. The Ethereum Foundation supports four full-time teams working on the migration, with over ten independent developer groups deploying weekly test networks. They have outlined specific upgrades across four upcoming network-wide changes, transitioning Ethereum's security to quantum-resistant mathematics. Bitcoin, on the other hand, lacks a comparable strategy. There are, however, proposals aimed at solving the problem. One such proposal, BIP-360, suggests introducing new quantum-safe address types that holders could migrate to voluntarily. Another proposal from BitMEX Research recommends implementing a detection system that triggers defensive measures if a quantum attack is observed on the network. Neither proposal has garnered broad support from Bitcoin's core developers, and they address different aspects of the problem. The challenge in implementing effective solutions lies in Bitcoin's governance structure. Ethereum's migration is facilitated by its foundation and governance process, which enables the passage of significant upgrades. Bitcoin, with its lack of central authority and emphasis on rare and hard protocol changes, faces a structurally more difficult problem. The migration of 6.9 million exposed coins requires decisions that the network has historically avoided. The question of whether old address formats should be frozen to protect coins from future theft, or whether exposed coins should be allowed to move to new quantum-safe addresses using their original keys, remains unresolved. The coins held by Satoshi Nakamoto pose a sharp example of this dilemma. Freezing old formats would protect the coins but make them permanently inaccessible, including to Satoshi. Leaving the old formats open would mean those coins remain vulnerable to quantum attacks. Setting a migration deadline would force Satoshi to either move the coins, revealing their ownership, or lose them. Every option would alter Bitcoin's character in ways the network has historically resisted. The Google paper frames the industry's current stance, suggesting that a successful attack on Bitcoin's mathematics should not be seen as a wake-up call to adopt post-quantum cryptography but rather as a potential signal that such adoption has already failed. This implies that by the time the threat becomes apparent, the window for response may have already closed. Developers are now faced with the question of whether a network designed to resist coordinated change can execute the largest security upgrade in its history before quantum computing hardware becomes a reality. Ethereum's eight-year head start in addressing this issue suggests that starting now is the correct approach. However, Bitcoin's governance culture indicates that the likely response will be to wait until the threat is demonstrated, and then act.