Time Runs Out for Bitcoin to Counter Quantum Threat, Putting 6.9 Million BTC at Risk

Not all aspects of bitcoin are vulnerable to quantum computer attacks. The process of bitcoin mining, which involves adding new blocks to the blockchain, utilizes a type of mathematics known as hashing that quantum computers are unable to effectively breach. As a result, the blockchain itself and the rule that new bitcoins can only be created through mining would survive a quantum attack, with blocks continuing to be produced and the chain remaining operational. However, ownership would be severely compromised. Bitcoin wallets are secured by a different form of mathematics that converts a private key into a public address visible to anyone. This math operates effortlessly in one direction but is extremely challenging in the reverse, making it the sole barrier preventing unauthorized individuals from spending someone else's coins. A significant portion of bitcoin, approximately 6.9 million, is at risk due to exposed public keys. This includes early bitcoin stored in address formats that published public keys by default, as well as wallets that have been spent from, as spending reveals the key for any remaining balance. A quantum attacker wouldn't need to compete with ongoing transactions; instead, they could methodically work through wallets with exposed keys at their leisure. Bitcoin's pseudonymous creator, Satoshi Nakamoto, holds about 1 million bitcoin that has remained untouched since the network's inception and is now categorized as exposed. The 2021 Taproot upgrade inadvertently expanded the issue by making bitcoin addresses more efficient and private, but as a side effect, any bitcoin spent since Taproot's activation has published the key protecting the remaining balance at that address. Currently, there are no concrete plans from Bitcoin developers to address the quantum threat, unlike Ethereum, which has a formal quantum-resistant program in place since 2018. Ethereum's approach includes four teams working full-time on the migration, with multiple independent developer groups releasing weekly test networks and a dedicated website to track progress. Bitcoin has proposals such as BIP-360, which suggests adding new quantum-safe address types, and a competing proposal from BitMEX Research for a detection system to trigger defensive actions in case of a quantum attack. However, neither proposal has gained broad support from core developers, and they address different aspects of the problem. The lack of a centralized authority and a governance process that can pass major upgrades makes bitcoin's migration more challenging than Ethereum's. The biggest hurdle is not the mathematics itself but the coordination and decision-making process within the bitcoin community, which has historically treated any central authority as a failure and believes changes to the protocol should be rare and difficult. Migrating the exposed coins requires making decisions that the network has avoided for twenty years, such as whether to freeze old address formats, allow exposed coins to move to new addresses, or decide the fate of coins whose owners cannot or will not migrate. The situation with Satoshi's coins is particularly sensitive, as freezing old formats would protect them but make them inaccessible, including to Satoshi, while leaving the formats open would leave the coins vulnerable to theft. Setting a migration deadline would force Satoshi to either move the coins, revealing ownership, or risk losing them. Every option would alter bitcoin's character in ways the network has historically refused to change. The recent Google paper frames the industry's stance, suggesting that a successful attack on bitcoin's mathematics should not be seen as a wake-up call but potentially as a signal that adopting post-quantum cryptography has already failed. This implies that by the time the threat becomes apparent, the window for response may have already closed. Developers are now faced with the question of whether a network designed to resist coordinated change can implement its largest security upgrade before quantum computers catch up. Ethereum's head start and proactive approach suggest that starting now is the correct strategy, while bitcoin's governance culture may lead to waiting until the threat is more evident, which could prove too late if the timeline is shorter than estimated.