Time Running Out for Bitcoin to Mitigate Quantum Threat

Not all aspects of bitcoin are vulnerable to quantum computers. The process of adding new blocks to the blockchain, known as mining, relies on a type of mathematics called hashing, which is resistant to quantum attacks. The blockchain itself and the rule that new bitcoins can only be created through mining would remain intact in the event of a quantum attack. However, ownership of bitcoins would be at risk. Bitcoin wallets are secured by a different type of mathematics that converts a private key into a public address. This math is easy to perform in one direction but virtually impossible in the other, which prevents unauthorized individuals from spending someone else's coins. A quantum algorithm known as Shor's algorithm can potentially break this math, and a recent paper by Google suggests that such an attack could be carried out with fewer resources than previously thought. This article explores the potential risks and the response of the bitcoin community to the quantum threat. Approximately 6.9 million bitcoins, or about one-third of all mined coins, are stored in wallets whose public keys are already visible on the blockchain. These coins are vulnerable to a quantum attack, which could allow an attacker to drain the wallets at their own pace. The 2021 Taproot upgrade has also expanded the problem by making any bitcoin spent since its activation publish the key protecting the remaining balance at that address. While there are ongoing debates and proposals to address the quantum threat, nothing concrete has emerged from bitcoin developers yet. In contrast, Ethereum has had a formal quantum-resistant program since 2018 and has made significant progress in migrating its security to new math that quantum computers cannot break. Bitcoin's lack of a coordinated response is due in part to its governance culture, which treats any central authority as a potential failure mode and emphasizes rare and difficult changes to the protocol. The migration of the 6.9 million exposed coins requires decisions that the network has historically avoided, such as freezing old address formats or allowing exposed coins to move to new quantum-safe addresses. Every option has significant implications for the character of the bitcoin network. The question now is whether the network can coordinate a massive security upgrade before the threat becomes a reality.