Time's Running Out for Bitcoin to Counter Quantum Threat

Not all aspects of bitcoin are vulnerable to quantum computers. The process of bitcoin mining, which utilizes a type of math known as hashing, is resistant to quantum attacks. The blockchain ledger and the rule that new bitcoins can only be created through mining would remain intact in the event of a quantum attack, with blocks continuing to be produced and the chain remaining operational. However, ownership would be compromised. Bitcoin wallets rely on a different type of math that converts a private key into a public address. This math is easily executable in one direction but not the other, which is the primary factor preventing unauthorized individuals from spending coins. A quantum algorithm known as Shor's algorithm can bypass this limitation. A recent paper by Google demonstrated that such an attack could be executed with significantly fewer resources than previously estimated, and within a timeframe that competes with bitcoin's block times. This article explores the potential risks, the current state of bitcoin's response, and the challenges of coordinating a network-wide security upgrade. Approximately 6.9 million bitcoins, roughly one-third of all mined coins, are stored in wallets with publicly visible keys, making them susceptible to quantum attacks. This includes early bitcoins and any wallet that has been spent from, as spending reveals the key. The 2021 Taproot upgrade inadvertently expanded the problem by publishing the key protecting remaining coins at an address after a transaction. While the quantum threat has sparked intense debate, no concrete solution has emerged from bitcoin developers. In contrast, Ethereum has had a formal quantum-resistant program in place since 2018, with multiple teams working on the migration and a dedicated website tracking progress. Bitcoin has proposals such as BIP-360, which suggests adding new quantum-safe address types, and a competing proposal from BitMEX Research for a detection system. However, neither has gained broad support from core developers. The lack of a centralized authority and a governance process that favors rare and hard changes makes it challenging for bitcoin to implement effective solutions. The migration of exposed coins requires decisions that the network has historically avoided, such as freezing old address formats or allowing exposed coins to move to new quantum-safe addresses. Every option poses significant changes to bitcoin's character, including the potential for Satoshi's untouched coins to be either protected or lost. The industry's current stance, as reflected in a recent Google paper, suggests that the window to adopt post-quantum cryptography may already be closing. Developers face the question of whether a network designed to resist coordinated change can coordinate a major security upgrade before the threat becomes imminent. Ethereum's head start and bitcoin's governance culture suggest different paths forward, with only one likely to be effective if the timeline proves shorter than expected.