Time is Running Out for Bitcoin to Counter the Quantum Threat, Putting 6.9 Million BTC at Risk
Not all aspects of bitcoin are vulnerable to quantum computers. The process of bitcoin mining, which involves adding new blocks to the blockchain, utilizes a type of mathematics known as hashing that quantum computers are unable to breach in a meaningful way. The blockchain itself and the rule that new bitcoins can only be created through mining would survive a quantum attack, with blocks continuing to be produced and the chain remaining operational. However, ownership would be severely compromised. Bitcoin wallets are secured by a different type of mathematics that converts a private key into a public address that can be seen by anyone. This mathematics is straightforward in one direction but not the other, and it is the only barrier preventing an unauthorized individual from spending someone else's coins. The first part of this series on quantum computing delved into the physics behind it, explaining how a quantum computer is fundamentally different from a regular computer, operating at extremely low temperatures and small scales where particles exhibit unique behaviors. The second part explored the implications of pointing a quantum computer at bitcoin, highlighting how bitcoin wallets rely on a one-way mathematical problem. Converting a private key into a public address takes milliseconds, but reversing the process would take a conventional computer longer than the universe's age. A quantum algorithm known as Shor's algorithm significantly reduces this time gap. A recent paper by Google demonstrated that such an attack could be executed with fewer resources than previously thought, and within a time frame that competes with bitcoin's block times. This final piece in the series focuses on the response to this threat, discussing what is at risk, the measures bitcoin has taken, and whether a network designed to resist coordinated changes can implement the largest security upgrade in its history before quantum hardware becomes a reality. The pool of bitcoin at risk is substantial, with roughly 6.9 million coins, or about one-third of all mined bitcoin, stored in wallets whose public keys are permanently visible on the blockchain. This includes early bitcoin from the network's first years, stored in an address format that published the public key by default, as well as any wallet that has been spent from, as spending reveals the key for the remaining balance. A quantum attacker would not need to compete with an ongoing transaction but could instead work through wallets with exposed keys at their leisure. This includes the approximately 1 million bitcoin held by Satoshi Nakamoto, bitcoin's pseudonymous creator, which have remained untouched since the network's early days and are now in the exposed category. The 2021 Taproot upgrade inadvertently expanded the problem by changing how bitcoin addresses work, aiming to make transactions more efficient and private. However, a side effect was that any bitcoin spent since Taproot's activation has published the key protecting the remaining balance at that address. While this was a deliberate trade-off at the time, given the perceived longer timelines for quantum threats, the situation has changed. In response to the quantum threat, heated debates have emerged, but concrete actions from bitcoin developers are still pending. In contrast, Ethereum, a major competitor, has had a formal quantum-resistant program in place since 2018. The Ethereum Foundation supports four full-time teams working on the migration, with over ten independent developer groups releasing weekly test networks. Ethereum's plan involves specific upgrades across four upcoming network-wide changes, transitioning its security to quantum-resistant mathematics. It has even launched a dedicated website to track its progress. Bitcoin lacks a comparable strategy. Despite this, efforts are underway to address the issue. One proposal, BIP-360, suggests introducing new quantum-safe address types that holders could migrate to voluntarily. Another proposal from BitMEX Research involves installing a detection system that triggers defensive actions if a quantum attack is observed. However, neither proposal has broad support from bitcoin's core developers, and they address different aspects of the problem. Prominent bitcoin advocate Nic Carter has highlighted the urgency, stating that the cryptography securing bitcoin wallets is on the verge of becoming obsolete. He praised Ethereum's approach as 'best in class' and criticized bitcoin's as 'worst in class', citing a lack of engagement with the problem among developers. Adam Back, CEO of Blockstream and an early bitcoin contributor, disagrees on the immediacy of the threat but agrees that preparation is necessary. He suggests that bitcoin should prepare now with optional upgrades, allowing the network to migrate when needed rather than reacting in a crisis. The biggest challenge in addressing the quantum threat is coordination. Bitcoin's migration is more complex than Ethereum's due to its lack of a central authority and governance process. Ethereum's foundation and governance process enable it to pass major upgrades regularly. In contrast, bitcoin's development culture views any central authority as a failure and prefers rare and difficult changes to the protocol. While this has kept the network stable, it makes solving the quantum problem structurally harder. Migrating the 6.9 million exposed coins requires decisions that the network has historically avoided. Questions include whether old address formats should be frozen to protect coins, whether exposed coins should be allowed to move to new quantum-safe addresses, and what happens to coins whose owners cannot or will not migrate. The fate of Satoshi's coins is a sharp example, as freezing old formats protects them but makes them inaccessible, including to Satoshi, while leaving them open makes them a target for quantum attackers. Setting a migration deadline forces Satoshi to either move the coins, revealing ownership, or lose them. Every option changes bitcoin's character in ways it has historically refused to change. The Google paper frames the industry's stance, suggesting that a successful attack should not be seen as a call to adopt post-quantum cryptography but as a potential signal that such adoption has already failed. This implies that by the time the threat becomes apparent, the window for response may have closed. Developers face the question of whether a network designed to resist change can coordinate its largest security upgrade before quantum hardware becomes a reality. Ethereum's head start suggests starting now is the correct approach, while bitcoin's governance culture suggests waiting until the threat is demonstrated. Only one of these approaches will work if the timeline is shorter than estimated.