Time Running Out for Bitcoin to Mitigate Quantum Threat, Putting 6.9 Million BTC at Risk
While not all aspects of bitcoin are vulnerable to quantum computers, the ownership of coins is at significant risk. Bitcoin mining, which involves the creation of new blocks on the blockchain, relies on a type of mathematics called hashing that quantum computers cannot effectively breach. This means the ledger and the rule that new bitcoins can only be created through mining will remain intact even in the face of a quantum attack, with blocks continuing to be produced and the chain remaining operational. However, the ownership of coins, which is protected by a different kind of mathematics that converts a private key into a public address, is under threat. This math, known as elliptic curve cryptography, is one-way, meaning it is easy to generate a public address from a private key but virtually impossible to reverse-engineer the private key from the public address. The security of this system is based on the difficulty of solving this mathematical problem, which currently takes an unfeasible amount of time for conventional computers. However, quantum computers can potentially solve this problem much faster using quantum algorithms like Shor's algorithm. Recently, Google released a paper indicating that such an attack could be feasible with fewer resources than previously thought, putting pressure on bitcoin to upgrade its security before quantum computers become powerful enough to launch an attack. Approximately 6.9 million bitcoins, about one-third of all mined coins, are at risk because their public keys have been exposed on the blockchain. This includes early bitcoins and any wallets that have been spent from, as spending reveals the public key. A quantum attacker wouldn't need to race against ongoing transactions but could systematically target wallets with exposed keys. Notably, Satoshi Nakamoto's approximately 1 million untouched bitcoins, which have been dormant since the network's early days, are also at risk. The 2021 Taproot upgrade inadvertently expanded the problem by making transactions more efficient and private but also publishing the key protecting remaining balances at addresses that have been spent from. To address this, there are proposals and efforts underway, such as BIP-360, which suggests introducing new quantum-safe address types, and a proposal from BitMEX Research for a detection system to trigger defensive actions in case of a quantum attack. However, these proposals lack broad support and solve different parts of the problem. Ethereum, a major competitor, has been preparing for the quantum threat since 2018 with a formal program, dedicated teams, and a clear plan for migration to quantum-resistant cryptography. The challenge for bitcoin lies in its governance structure, which is designed to resist coordinated change, making the implementation of such a significant security upgrade difficult. The question remains whether bitcoin can coordinate the necessary changes to protect itself against the quantum threat before it's too late.