Time Runs Out for Bitcoin to Counter Quantum Threat, Putting 6.9 Million BTC at Risk
Not all aspects of bitcoin are vulnerable to quantum computers. The process of bitcoin mining, which utilizes a form of math known as hashing, is secure against quantum attacks. The bitcoin ledger and the rule that new bitcoins can only be created through mining would survive a quantum assault, with blocks continuing to be produced and the chain remaining operational. However, ownership would be severely impacted. Bitcoin wallets rely on a different type of math that converts a private key into a public address. This math is straightforward in one direction but impractical in the other, serving as the primary barrier against unauthorized spending of coins. A quantum algorithm known as Shor's algorithm significantly reduces the time required to reverse this process. Google's recent paper demonstrated that such an attack could be executed with fewer resources than previously estimated, highlighting the urgency of the situation. This article explores the potential consequences and the response of the bitcoin community. Approximately 6.9 million bitcoins, roughly one-third of all mined bitcoins, are stored in wallets with publicly visible keys, making them susceptible to quantum attacks. This includes early bitcoins and any wallet that has been used for transactions, as spending reveals the key. A quantum attacker could systematically target these wallets without needing to compete with ongoing transactions. The 2021 Taproot upgrade inadvertently increased the vulnerability by publishing keys for any bitcoin spent since its activation. While the quantum threat has sparked intense debate, concrete solutions have yet to emerge from bitcoin developers. In contrast, Ethereum has a formal quantum-resistant program in place since 2018, with multiple teams working on the migration and a dedicated website to track progress. Bitcoin lacks a comparable strategy, although there are proposals such as BIP-360, which suggests introducing new quantum-safe address types, and a competing proposal from BitMEX Research for a detection system to trigger defensive actions in case of a quantum attack. Neither proposal has gained broad support from core developers, and they address different aspects of the problem. The lack of a centralized authority and a governance process that favors rare and difficult changes to the protocol makes it challenging for bitcoin to implement effective solutions. Migrating the exposed coins requires decisions that the network has historically avoided, such as freezing old address formats or allowing exposed coins to move to new quantum-safe addresses. The fate of Satoshi's untouched coins, which are part of the exposed category, poses a significant dilemma. Setting a migration deadline would force Satoshi to either move the coins, revealing ownership, or risk losing them. The future of bitcoin's security hangs in the balance, with the question of whether the network can coordinate a massive security upgrade before quantum computers become a reality.