Time Runs Out for Bitcoin to Counter Quantum Threat, Putting 6.9 Million BTC at Risk
Not all aspects of bitcoin are vulnerable to quantum computer attacks. The process of bitcoin mining, which involves adding new blocks to the blockchain, utilizes a type of mathematics known as hashing that quantum computers are unable to breach effectively. The blockchain itself and the rule that new bitcoins can only be created through mining would remain intact in the event of a quantum attack. The production of blocks and the continuity of the chain would not be affected. However, ownership would be severely compromised. Bitcoin wallets rely on a different mathematical mechanism that converts a private key into a public address visible to everyone. This math functions effortlessly in one direction but is impractical in the reverse, which is the sole barrier preventing unauthorized individuals from spending your coins. The first part of this series on quantum computing delved into the physics behind it, explaining that a quantum computer is fundamentally distinct from a regular computer, operating at extremely low temperatures and small scales where particles exhibit unique behaviors not observed elsewhere on Earth. The second part explored the implications of directing such a machine at bitcoin, highlighting that bitcoin wallets depend on a one-way mathematical problem. Converting a private key into a public address takes milliseconds, but reversing this process would take a conventional computer longer than the age of the universe. A quantum algorithm known as Shor's algorithm significantly reduces this timeframe. A recent paper by Google demonstrated that this attack could be executed with far fewer resources than previously estimated, racing against bitcoin's block times. This final piece in the series focuses on the response to this threat, examining what is at risk, the actions bitcoin has taken, and whether a network designed to resist coordinated change can implement the most significant security upgrade in its history before the advent of capable hardware. The pool of at-risk bitcoins is substantial, with approximately 6.9 million bitcoins, roughly one-third of all mined bitcoins, stored in wallets with publicly visible keys on the blockchain. Most of these are early bitcoins from the network's initial years, stored in an address format that published the public key by default. This also includes any wallet that has been spent from, as spending reveals the key for the remaining balance. A quantum attacker would not need to compete with ongoing transactions but could systematically target wallets with exposed keys at their leisure. Bitcoin's pseudonymous creator, Satoshi Nakamoto, holds about 1 million bitcoins, untouched since the network's early days, which are now in the exposed category. The 2021 Taproot upgrade inadvertently expanded the problem. Taproot is a modification to how bitcoin addresses function, aimed at making transactions more efficient and private. However, it had the side effect of publishing the key protecting any remaining balance at an address after a transaction, following its activation. This was a deliberate design choice at the time, given the perceived longer timelines for quantum threats. Currently, there are efforts underway to address the quantum threat, although nothing concrete has emerged from Bitcoin developers. In contrast, Ethereum, a major competitor, has had a formal quantum-resistant program in place since 2018. The Ethereum Foundation supports four full-time teams working on the migration, with over ten independent developer groups deploying weekly test networks. They have outlined specific upgrades across four upcoming network-wide changes to transition Ethereum's security to quantum-resistant mathematics. Ethereum has even launched a dedicated website, pq.ethereum.org, to track its progress. Bitcoin lacks a comparable strategy at this point. However, there are proposals and efforts to solve the problem. One such proposal, BIP-360, from a group of developers and researchers, suggests introducing new quantum-safe address types that holders could migrate to voluntarily. Another proposal from BitMEX Research involves installing a detection system that would trigger defensive measures if a quantum attack is observed on the network. Neither proposal has gained broad support from bitcoin's core developers, and they address different aspects of the issue. Prominent bitcoin advocate Nic Carter has highlighted the urgency, stating that the elliptic curve cryptography securing bitcoin wallets is on the verge of obsolescence. He praised Ethereum's approach as 'best in class' and criticized bitcoin's as 'worst in class', citing developers who deny or downplay the issue rather than engaging with it. Adam Back, CEO of Blockstream and an early bitcoin contributor, disagrees on the immediacy of the threat but agrees that bitcoin should prepare by incorporating optional upgrades in advance, allowing for a smoother migration when necessary. The main challenge in implementing effective solutions against the quantum threat is not the mathematics itself but the coordination and governance within the bitcoin network. Ethereum's migration is facilitated by its foundation, which funds engineering work, and its governance process, which regularly implements significant upgrades. Bitcoin, with its aversion to central authority and preference for rare and difficult protocol changes, faces a structurally harder problem. Migrating the 6.9 million exposed coins requires decisions that the network has historically avoided, such as whether to freeze old address formats to protect coins from future theft, allow exposed coins to move to quantum-safe addresses using their original keys, or determine the fate of coins whose owners cannot or will not migrate. The coins held by Satoshi Nakamoto are a critical example, as freezing old formats would protect the coins but make them inaccessible, including to Satoshi, while leaving the formats open would put the coins at risk of theft by a quantum attacker. Setting a migration deadline would force Satoshi to either move the coins, revealing ownership, or lose them, each option changing bitcoin's character in ways the network has traditionally resisted. The recent Google paper frames the industry's current stance, suggesting that a successful attack on bitcoin's mathematics should not be seen as a wake-up call for post-quantum cryptography adoption but as a potential signal that such adoption has already failed. This implies that by the time the threat becomes apparent, the window for response may have already closed. Developers are now faced with the question of whether a network designed to resist coordinated change can coordinate its largest security upgrade before the advent of capable hardware. Ethereum's head start suggests the importance of starting now, while bitcoin's governance culture indicates a likely wait until the threat is demonstrated, which may not be a viable approach if the timeline is shorter than estimated.