Bitcoin's Quantum Conundrum: A Countdown to Secure 6.9 Million Coins

Not all aspects of bitcoin are vulnerable to quantum computers. The process of bitcoin mining, which involves the creation of new blocks on the blockchain, utilizes a type of mathematics known as hashing, which is impervious to quantum computer attacks. Consequently, the ledger and the rule governing the creation of new bitcoins through mining would remain intact in the face of a quantum attack, with blocks continuing to be produced and the chain remaining operational. However, ownership would be severely compromised. Bitcoin wallets rely on a different mathematical framework that converts a private key into a public address. This math is easily solvable in one direction but virtually impossible in the other, serving as the primary barrier preventing unauthorized individuals from spending coins. The first part of this series delved into the realm of physics, explaining that a quantum computer is fundamentally distinct from a conventional computer, operating at extremely low temperatures and manipulating particles in unique ways. The second installment examined the implications of directing a quantum computer at bitcoin, highlighting the dependence of bitcoin wallets on one-way mathematical problems. Converting a private key into a public address is a rapid process, whereas reversing this process would take an ordinary computer an eternity. A quantum algorithm known as Shor's algorithm bridges this gap. A recent paper by Google demonstrated that this attack could be executed with significantly fewer resources than previously estimated, racing against bitcoin's block times. This final installment focuses on the response, exploring what is at risk, the measures bitcoin has taken, and whether a network designed to resist coordinated change can implement the most substantial security upgrade in its history before the advent of quantum hardware. The pool of vulnerable bitcoin is substantial, with approximately 6.9 million coins, roughly one-third of all mined bitcoin, stored in wallets whose public keys are permanently visible on the blockchain. This includes early bitcoin from the network's inaugural years, stored in an address format that published the public key by default, as well as any wallet that has been spent from, as spending reveals the key for any remaining balance. A quantum attacker would not need to compete with ongoing transactions but could instead systematically target wallets with exposed keys at their leisure. Bitcoin's pseudonymous creator, Satoshi Nakamoto, holds approximately 1 million bitcoin, which has remained untouched since the network's early days and now falls into the vulnerable category. The 2021 Taproot upgrade inadvertently expanded the problem by changing how bitcoin addresses function, aiming to enhance transaction efficiency and privacy. As a result, any bitcoin spent since Taproot's activation has published the key protecting the remaining balance at that address. Although this was a deliberate design choice at the time, considering the perceived longer quantum timelines, it has become a concern given the current quantum threat landscape. Efforts are underway to address the quantum threat, although nothing concrete has emerged from Bitcoin developers yet. Ethereum, a major competitor, has had a formal quantum-resistant program in place since 2018, with the Ethereum Foundation supporting four full-time teams and numerous independent developer groups working on the migration. In contrast, Bitcoin lacks a comparable strategy. There are proposals, such as BIP-360, which suggests introducing new quantum-safe address types for voluntary migration, and a competing proposal from BitMEX Research for a detection system to trigger defensive actions in the event of a quantum attack. However, neither proposal has garnered broad support from Bitcoin's core developers, and they address different aspects of the problem. The absence of a unified approach and the lack of urgency among some developers have been criticized by prominent advocates like Nic Carter, who described Ethereum's approach as 'best in class' and Bitcoin's as 'worst in class.' Adam Back, CEO of Blockstream and an early contributor to Bitcoin, disagrees on the urgency but agrees that Bitcoin should prepare with optional upgrades to facilitate a smooth migration when needed. The primary challenge in implementing effective solutions against Bitcoin's quantum threat lies in its governance structure. Ethereum's foundation and governance process enable the coordination of significant upgrades, whereas Bitcoin's development culture is inherently resistant to central authority and change. This has kept the network stable for nearly two decades but complicates the solution to the quantum problem. Migrating the exposed coins requires decisions that the network has historically avoided, such as whether to freeze old address formats to protect coins from future theft or allow exposed coins to move to new quantum-safe addresses using their original keys. The fate of coins whose owners cannot or will not migrate, including Satoshi's 1 million untouched coins, poses a sharp example of the dilemmas faced. Setting a migration deadline would force Satoshi to either move the coins, revealing ownership, or lose them, altering Bitcoin's character in ways the network has traditionally refused to change. The recent Google paper frames the industry's stance, suggesting that a successful attack on Bitcoin's mathematics should not be seen as a call to adopt post-quantum cryptography but rather as a potential signal that such adoption has already failed. This implies that by the time the threat becomes apparent, the window for response may have closed. Developers are left wondering whether a network built to resist coordinated change can orchestrate the most significant security upgrade in its history before quantum hardware catches up. Ethereum's eight-year head start suggests the importance of starting now, while Bitcoin's governance culture indicates a likelihood of waiting until the threat is demonstrated, which may prove too late if the timeline is shorter than estimated.