Bitcoin's Quantum Conundrum: A Race Against Time to Prevent Catastrophic Losses

Not all aspects of bitcoin are vulnerable to quantum computer attacks. The process of mining, which involves adding new blocks to the blockchain, relies on a type of mathematics called hashing that quantum computers are unable to breach effectively. As a result, the ledger and the rule that new bitcoins can only be created through mining would remain intact in the event of a quantum attack. However, what would be severely compromised is ownership. Bitcoin wallets are secured by a different kind of mathematics that converts a secret private key into a publicly visible address. This math functions effortlessly in one direction but is virtually impossible in the other, and it is the sole barrier preventing unauthorized individuals from spending someone else's coins. The first part of this series on quantum computing delved into the physics behind it, explaining how a quantum computer is fundamentally distinct from a regular computer, operating at extremely low temperatures and small scales where particles exhibit unique behaviors. The second part explored the implications of pointing a quantum computer at bitcoin, highlighting how bitcoin wallets depend on a one-way mathematical problem. Converting a private key into a public address takes mere milliseconds, but reversing this process would take a conventional computer longer than the age of the universe. A quantum algorithm known as Shor's algorithm dramatically reduces this gap. A recent paper by Google demonstrated that such an attack could be executed with far fewer resources than previously estimated, and within a timeframe that competes with bitcoin's block creation times. This final piece in the series focuses on the response to this threat, examining what is at risk, the measures bitcoin has taken, and whether a network designed to resist coordinated changes can implement the largest security upgrade in its history before quantum hardware becomes a reality. The pool of vulnerable bitcoin is substantial, totaling roughly 6.9 million coins, or about one-third of all mined bitcoin, which are stored in wallets with publicly visible keys. This includes early bitcoin from the network's first years, stored in an address format that published the public key by default, as well as any wallet that has ever been spent from, as spending reveals the key for any remaining balance. A quantum attacker would not need to compete with ongoing transactions but could systematically target wallets with exposed keys at their leisure. This includes the approximately 1 million bitcoin held by bitcoin's pseudonymous creator, Satoshi Nakamoto, which have remained untouched since the network's early days and now fall into the vulnerable category. The 2021 Taproot upgrade inadvertently expanded the problem by changing how bitcoin addresses function, with the goal of making transactions more efficient and private. However, a side effect of Taproot is that any bitcoin spent since its activation has had its protecting key published, potentially exposing the remaining coins at that address. This was a deliberate design choice at the time, given the perceived longer timelines for quantum computing threats. Currently, there are discussions and proposals but no concrete actions from Bitcoin developers to address the quantum threat. In contrast, Ethereum, a major competitor, has had a formal quantum-resistant program in place since 2018, with dedicated teams working on migration and a clear plan for security upgrades that quantum computers cannot breach. Ethereum has even launched a website to track its progress. For bitcoin, there are proposals, such as BIP-360, which suggests introducing new quantum-safe address types for voluntary migration, and a proposal from BitMEX Research for a detection system to trigger defenses upon observing a quantum attack. However, neither proposal has gained broad support from core developers, and they address different aspects of the problem. Prominent figures in the bitcoin community have voiced their concerns, with Nic Carter describing the current state of elliptic curve cryptography as being on the brink of obsolescence and criticizing bitcoin's approach as 'worst in class' compared to Ethereum's 'best in class' strategy. Adam Back, CEO of Blockstream and an early bitcoin contributor, agrees on the need for preparation but disagrees on the urgency, suggesting that bitcoin should prepare now with optional upgrades to migrate when necessary, rather than reacting in a crisis. The main challenge in implementing effective solutions against the quantum threat is not the mathematics itself but bitcoin's governance structure. Ethereum's foundation and governance process allow for more streamlined decision-making and funding for engineering work. In contrast, bitcoin's development culture is wary of central authority, and changes to the protocol are rare and difficult. This has kept the network stable for nearly two decades but makes addressing the quantum problem structurally harder. Migrating the exposed coins requires making decisions that the network has historically avoided, such as whether to freeze old address formats to protect coins from future theft or allow exposed coins to move to new quantum-safe addresses. Every option would change bitcoin's character in ways the network has refused to alter. The situation with Satoshi's coins is particularly poignant, as freezing old formats would protect the coins but make them inaccessible, including to Satoshi, or leaving them open to potential quantum attacks. Setting a migration deadline would force Satoshi to either move the coins, revealing ownership, or lose them. The recent Google paper frames the industry's stance, suggesting that a successful attack on bitcoin's current mathematics should not be seen as a wake-up call but potentially as a signal that the window for adopting post-quantum cryptography has already closed. This implies that by the time the threat becomes apparent, it may be too late to respond. Developers are faced with the question of whether a network built to resist change can coordinate the largest security upgrade in its history before quantum hardware becomes a reality. Ethereum's head start suggests the importance of starting now, while bitcoin's governance culture leans towards waiting until the threat is demonstrated. Only one of these approaches will be effective if the timeline proves shorter than expected.