Bitcoin's Quantum Conundrum: Can the Network Mitigate the Looming Threat?

Not all aspects of Bitcoin are vulnerable to quantum computer attacks. The process of mining, which utilizes a type of mathematics known as hashing, is resistant to quantum computing's capabilities. Additionally, the blockchain ledger itself and the rule governing the creation of new Bitcoins through mining would remain intact in the face of a quantum attack, ensuring the continuous production of blocks and the functioning of the chain. However, what is at risk is ownership. Bitcoin wallets rely on a different mathematical framework, which converts a private key into a public address that can be seen by anyone. This math functions effortlessly in one direction but is virtually impossible to reverse, and it is this property that prevents unauthorized individuals from spending someone else's coins. The first part of this series delved into the physics of quantum computing, highlighting that a quantum computer is fundamentally distinct from a regular computer, operating at extremely low temperatures and leveraging unique particle behaviors. The second installment explored the implications of pointing a quantum computer at Bitcoin, emphasizing that Bitcoin wallets depend on a one-way mathematical problem. While transforming a private key into a public address takes mere milliseconds, reversing this process would take a conventional computer longer than the universe's age. However, a quantum algorithm known as Shor's algorithm significantly reduces this time gap. A recent paper by Google demonstrated that such an attack could be executed with fewer resources than previously estimated, racing against Bitcoin's block times. This final piece focuses on the response to this threat, examining what is at risk, the measures Bitcoin has taken, and whether a network designed to resist coordinated change can implement the most significant security upgrade in its history before quantum hardware becomes a reality. The exposed pool of Bitcoin is substantial, with approximately 6.9 million coins, roughly one-third of all mined Bitcoins, stored in wallets whose public keys are permanently visible on the blockchain. This includes early Bitcoins from the network's inception, stored in an address format that published public keys by default, as well as any wallet that has been spent from, as spending reveals the key for the remaining balance. A quantum attacker would not need to compete with ongoing transactions but could methodically work through wallets with exposed keys at their leisure. This includes the approximately 1 million Bitcoins held by Bitcoin's pseudonymous creator, Satoshi Nakamoto, which have remained untouched since the network's early days and are now in the exposed category. The 2021 Taproot upgrade inadvertently expanded the problem by changing how Bitcoin addresses function, aiming to make transactions more efficient and private. However, a side effect was that any Bitcoin spent since Taproot's activation has published the key protecting the remaining balance at that address. Although this was a reasonable trade-off at the time, considering quantum timelines seemed longer, it now poses a significant risk. Currently, there are no concrete plans from Bitcoin developers to address the quantum threat, unlike Ethereum, which has had a formal quantum-resistant program in place since 2018. Ethereum's approach includes four full-time teams working on migration, with multiple independent developer groups testing networks weekly, and a dedicated website to track progress. In contrast, Bitcoin's efforts are more dispersed, with proposals like BIP-360 suggesting the introduction of new quantum-safe address types for voluntary migration and a competing proposal from BitMEX Research advocating for a detection system to trigger defensive actions upon observing a quantum attack. However, neither proposal has garnered broad support from core developers, and they address different aspects of the problem. Prominent Bitcoin advocate Nic Carter has highlighted the urgency, stating that the elliptic curve cryptography securing Bitcoin wallets is on the verge of obsolescence, praising Ethereum's approach as 'best in class' and criticizing Bitcoin's as 'worst in class'. Adam Back, CEO of Blockstream and an early Bitcoin contributor, while disagreeing on the immediacy of the threat, agrees that Bitcoin should prepare with optional upgrades to facilitate a smoother migration when needed. The primary challenge in implementing effective solutions against Bitcoin's quantum threat lies in its governance structure. Unlike Ethereum, which has a foundation to fund engineering work and a governance process for major upgrades, Bitcoin's development culture is inherently resistant to central authority, treating changes to the protocol as rare and difficult. This has kept the network stable but makes addressing the quantum problem structurally harder. Migrating the exposed coins requires decisions that the network has historically avoided, such as whether to freeze old address formats to protect coins from future theft, allow exposed coins to move to quantum-safe addresses, or determine the fate of coins whose owners cannot or will not migrate. The fate of Satoshi's coins is a critical example, as freezing old formats would protect them but make them inaccessible, including to Satoshi, while leaving them open would leave them vulnerable to quantum attack. Setting a migration deadline would force Satoshi to either move the coins, revealing ownership, or lose them, each option altering Bitcoin's character in ways it has historically resisted. The future hangs in the balance, with the Google paper's framing suggesting that a successful attack should not be the catalyst for adopting post-quantum cryptography but rather a signal that such adoption has already failed. This implies that by the time the threat becomes apparent, the window for response may have closed. Developers are faced with the question of whether a network designed to resist coordinated change can implement its largest security upgrade before quantum hardware surpasses theoretical capabilities. Ethereum's head start suggests the importance of immediate action, while Bitcoin's governance culture indicates a likelihood to wait until the threat is demonstrated, a strategy that may not be viable if timelines are shorter than estimated.