Time Running Out for Bitcoin to Counter Quantum Threat, 6.9 Million BTC at Risk
Not all aspects of bitcoin are vulnerable to quantum computers. The process of bitcoin mining, which involves adding new blocks to the blockchain, utilizes a type of mathematics known as hashing that quantum computers are unable to break. As a result, the blockchain itself and the mechanism for creating new bitcoin through mining would survive an attack by a quantum computer. New blocks would continue to be produced, and the blockchain would remain operational. However, ownership of bitcoin would be severely compromised. Bitcoin wallets rely on a different type of mathematics that converts a private key into a public address. This mathematics is easy to perform in one direction but extremely difficult in the other, which is the primary obstacle preventing unauthorized individuals from spending someone else's coins. The first part of this series on quantum computing delved into the physics behind it, explaining how a quantum computer is fundamentally different from a regular computer, operating at extremely low temperatures and small scales where particles exhibit unique behaviors. The second part examined the implications of quantum computing for bitcoin, specifically how bitcoin wallets depend on a one-way mathematical problem. Converting a private key into a public address is a straightforward process, but reversing it would take an ordinary computer longer than the current age of the universe. A quantum algorithm known as Shor's algorithm significantly reduces this time gap. A recent paper by Google demonstrated that such an attack could be executed with fewer resources than previously thought, highlighting the urgency of the situation. This final piece in the series focuses on the response to the quantum threat, including what is at risk, the measures bitcoin has taken, and whether the network can coordinate a significant security upgrade before quantum computers become powerful enough to pose a threat. Approximately 6.9 million bitcoin, roughly one-third of all mined bitcoin, are stored in wallets with publicly visible keys, making them vulnerable to quantum attacks. This includes early bitcoin from the network's first years, which was stored in an address format that published the public key by default, as well as any wallet that has been spent from, as spending reveals the key for the remaining balance. A quantum attacker would not need to compete with ongoing transactions but could instead work through the wallets with exposed keys at their own pace. This includes the approximately 1 million bitcoin held by Satoshi Nakamoto, the pseudonymous creator of bitcoin, which has remained untouched since the network's early days. The 2021 Taproot upgrade inadvertently expanded the problem by making any bitcoin spent since its activation publish the key protecting the remaining balance at that address. Although this was not an error, it was a reasonable trade-off at the time, given the perceived longer timeline for quantum threats. Currently, there are no concrete plans from Bitcoin developers to address the quantum threat, unlike Ethereum, which has had a formal quantum-resistant program in place since 2018. Ethereum's approach includes four full-time teams working on the migration, with over ten independent developer groups testing networks weekly. Bitcoin, on the other hand, lacks a unified strategy. There are proposals, such as BIP-360, which suggests introducing new quantum-safe address types, and a proposal from BitMEX Research for a detection system to trigger defensive actions in case of a quantum attack. However, neither proposal has broad support from core developers, and they address different aspects of the problem. Prominent bitcoin advocate Nic Carter has criticized bitcoin's approach, calling it 'worst in class' compared to Ethereum's 'best in class' strategy. Adam Back, CEO of Blockstream and an early contributor to bitcoin, agrees on the need for preparation but disagrees on the urgency, suggesting that bitcoin should prepare now with optional upgrades to migrate when necessary. The biggest challenge for bitcoin is not the mathematical aspect but the coordination problem due to its lack of a central authority and governance process. Ethereum's foundation and regular upgrade process make its migration easier. Bitcoin's development culture, which treats any central authority as a failure mode and emphasizes rare and hard changes to the protocol, has kept the network stable but makes addressing the quantum threat more difficult. Migrating the exposed coins requires decisions that the network has historically avoided, such as whether to freeze old address formats to protect coins or allow exposed coins to move to new quantum-safe addresses. Every option changes bitcoin's character in ways the network has refused to change. The outcome depends on whether the network can coordinate a significant security upgrade before the threat becomes real.