Time is running out for bitcoin to mitigate quantum computing risks, with 6.9 million BTC at stake
Not all aspects of bitcoin are vulnerable to quantum computing attacks. The process of bitcoin mining, which utilizes a type of mathematics known as hashing, is resistant to quantum computing threats. The bitcoin ledger and the rule governing the creation of new bitcoins through mining would remain intact in the event of a quantum attack, ensuring the continued production of blocks and the operation of the chain. However, ownership would be severely compromised. Bitcoin wallets rely on a different mathematical approach, converting a private key into a public address that can be seen by anyone. This math functions efficiently in one direction but not the other, which is the primary barrier preventing unauthorized individuals from spending coins. A quantum algorithm known as Shor's algorithm can bridge this gap. A recent paper by Google demonstrated that such an attack could be executed with significantly fewer resources than previously estimated, within a timeframe that competes with bitcoin's block times. This article, the final installment in a series, examines the response to this threat, including what is at risk, the measures bitcoin has taken, and whether a network designed to resist coordinated change can implement the most significant security upgrade in its history before the threat materializes. Approximately 6.9 million bitcoin, equivalent to one-third of all mined bitcoin, is stored in wallets with publicly visible keys, making them susceptible to quantum attacks. This includes early bitcoin from the network's inaugural years, stored in an address format that publicly disclosed the key by default, as well as any wallet that has been spent from, as spending reveals the key for the remaining balance. A quantum attacker would not need to contend with an ongoing transaction; instead, they could methodically target wallets with exposed keys at their own pace. Bitcoin's pseudonymous creator, Satoshi Nakamoto, holds around 1 million bitcoin, which has remained untouched since the network's early days and now falls into the exposed category. The 2021 Taproot upgrade inadvertently expanded the problem. Taproot is a modification to how bitcoin addresses function, intended to enhance transaction efficiency and privacy. A side effect of this upgrade was that any bitcoin spent after Taproot's activation has publicly disclosed the key protecting the remaining balance at that address. While the quantum threat has sparked intense debate in recent months, with other blockchains preparing for the challenge, bitcoin developers have yet to propose a concrete solution. Ethereum, a major competitor to bitcoin, has had a formal quantum-resistant program in place since 2018. The Ethereum Foundation operates four full-time teams working on the migration, with over ten independent developer groups releasing weekly test networks. Ethereum has outlined specific upgrades across four upcoming network-wide changes, transitioning its security to quantum-resistant mathematics. In contrast, bitcoin lacks a comparable strategy. There are, however, efforts underway to address the issue. One formal proposal, BIP-360, put forth by a group of developers and researchers, suggests introducing new quantum-safe address types that holders could voluntarily migrate to. Another proposal from BitMEX Research recommends implementing a detection system that triggers defensive measures if a quantum attack is observed on the network. Neither proposal has garnered broad support from bitcoin's core developers, and they address different aspects of the problem. Prominent bitcoin advocate Nic Carter has emphasized the urgency of the situation, stating that the elliptic curve cryptography securing bitcoin wallets is on the verge of obsolescence. He praised Ethereum's approach as 'best in class' and criticized bitcoin's as 'worst in class,' citing developers who deny, downplay, or avoid engaging with the problem. Adam Back, CEO of Blockstream and an early bitcoin contributor, disagrees on the urgency but agrees that bitcoin should prepare by implementing optional upgrades in advance, allowing the network to migrate when necessary rather than reacting to a crisis. The primary challenge in implementing effective solutions against bitcoin's quantum threat lies in the network's governance structure. Bitcoin's migration is more complex than Ethereum's due to its lack of a central authority and formal governance process. Ethereum has a foundation that funds engineering work and a governance process that regularly passes significant upgrades. In contrast, bitcoin's development culture views any central authority as a potential failure mode, and its social consensus dictates that changes to the protocol should be rare and difficult. These principles have maintained the network's stability for nearly two decades but also make addressing the quantum problem structurally more challenging for bitcoin. Migrating the 6.9 million exposed coins requires decisions that the network has avoided for twenty years. The question of whether old address formats should be frozen after a certain date to protect coins from future theft, or whether exposed coins should be allowed to move to new quantum-safe addresses using their original keys, remains unanswered. The fate of coins whose owners cannot or will not migrate also poses a significant challenge. Satoshi's coins serve as a prime example, as freezing old formats would protect the coins from theft but render them permanently inaccessible, including to Satoshi. Allowing old formats to remain open means those coins would be vulnerable to quantum attacks. Setting a migration deadline would force Satoshi to either move the coins, revealing their ownership, or lose them. Every option would alter bitcoin's character in ways the network has historically refused to change. The Google paper's framing serves as a summary of the industry's current stance. A successful attack on bitcoin's mathematics 'should not be seen as a wake-up call to adopt post-quantum cryptography as much as a potential signal that PQC adoption has already failed.' This implies that by the time the threat becomes apparent, the window to respond may have already closed. Developers now face the question of whether a network designed to resist coordinated change can coordinate the most significant security upgrade in its history before quantum computing technology catches up. Ethereum's eight-year head start suggests that the correct approach is to start preparing now. Bitcoin's governance culture, however, suggests that the likely response will be to wait until the threat is demonstrated, and then react. Only one of these approaches will be effective if the timeline proves to be shorter than optimists estimate.