Time Runs Out for Bitcoin to Counter Quantum Threat, Putting 6.9 Million BTC at Risk

Not all aspects of bitcoin are vulnerable to quantum computers. The process of bitcoin mining, which involves adding new blocks to the blockchain, utilizes a type of mathematics called hashing that quantum computers are unable to break. This means that the blockchain itself and the rule that new bitcoins can only be created through mining will remain intact even if a quantum attack occurs. Blocks will continue to be produced, and the blockchain will keep functioning. However, what is at risk is ownership. Bitcoin wallets are secured by a different type of mathematics that converts a private key into a public address. This math works in one direction but not the other, preventing unauthorized individuals from spending coins. A quantum algorithm known as Shor's algorithm can bypass this security measure. Recently, a paper by Google demonstrated that such an attack could be carried out with fewer resources than previously thought, and within a time frame that competes with bitcoin's block times. This article explores the potential consequences and the response of the bitcoin community. Approximately 6.9 million bitcoins, roughly one-third of all mined coins, are stored in wallets whose public keys are visible on the blockchain. This includes early bitcoins and any wallet that has been used for transactions, as spending reveals the key. A quantum attacker could target these wallets at their own pace. Bitcoin's creator, Satoshi Nakamoto, holds about 1 million bitcoins that are also at risk. The 2021 Taproot upgrade inadvertently increased the vulnerability by making bitcoin addresses more efficient and private, but also exposing the keys of any spent coins. Currently, there are debates among bitcoin developers about how to address this issue. Ethereum, another major blockchain, has been working on a quantum-resistant program since 2018 and has a clear plan to migrate to new security measures. Bitcoin, however, lacks a unified strategy. There are proposals, such as BIP-360, which suggests introducing new quantum-safe address types, and a proposal by BitMEX Research for a detection system to trigger defensive actions in case of a quantum attack. Neither proposal has gained broad support from core developers. Prominent figures in the bitcoin community, like Nic Carter, have expressed concern over the lack of action, describing bitcoin's approach as 'worst in class' compared to Ethereum's. Others, like Adam Back, agree on the need for preparation but disagree on the urgency. The main challenge for bitcoin is its decentralized nature and lack of a central authority, making coordinated changes difficult. The network's culture prioritizes stability and rare, hard changes, which complicates the implementation of effective solutions against the quantum threat. Migrating the exposed coins requires making decisions that the network has historically avoided, such as freezing old address formats or allowing exposed coins to move to new quantum-safe addresses. Each option changes the character of bitcoin in significant ways. The future of bitcoin's security against quantum threats remains uncertain, with the possibility that by the time the threat becomes apparent, it may already be too late to respond.