Bitcoin's Quantum Conundrum: Can the Network Mitigate the Looming Threat?
Not all aspects of bitcoin are vulnerable to quantum computing. The process of mining, which involves adding new blocks to the blockchain, utilizes a type of mathematics known as hashing that quantum computers are unable to breach effectively. The ledger and the rule that new bitcoins can only be created through mining would remain intact in the face of a quantum attack, ensuring the continued production of blocks and the operation of the chain. However, ownership would be severely compromised. Bitcoin wallets rely on a different form of mathematics that converts a private key into a public address. This mathematics is straightforward in one direction but virtually impossible in the other, and it is this that prevents unauthorized individuals from spending coins. The first part of this series delved into the physics of quantum computing, explaining how it operates on fundamentally different principles than regular computers, starting with a tiny, cold loop of metal where particles exhibit unique behaviors. The second installment explored the implications of pointing a quantum computer at bitcoin, highlighting how bitcoin wallets depend on a one-way mathematical problem that can be resolved in milliseconds in one direction but would take a conventional computer longer than the universe's age to solve in the other. A quantum algorithm known as Shor's algorithm significantly reduces this gap. A recent paper by Google demonstrated that such an attack could be launched with fewer resources than previously thought, racing against bitcoin's block times. This final piece examines the response, focusing on what is at risk, the measures bitcoin has taken, and whether a network designed to resist coordinated change can implement the largest security upgrade in its history before quantum hardware becomes a reality. The pool of assets at risk is substantial, with approximately 6.9 million bitcoins, or about one-third of all mined bitcoins, stored in wallets with publicly visible keys on the blockchain. This includes early bitcoins and any wallet that has been spent from, as spending reveals the key for the remaining balance. A quantum attacker would not need to compete with ongoing transactions; instead, they could methodically work through wallets with exposed keys at their leisure. This includes the roughly 1 million bitcoins held by bitcoin's pseudonymous creator, Satoshi Nakamoto, which have remained untouched since the network's inception and are now categorized as exposed. The 2021 Taproot upgrade inadvertently expanded the problem by making transactions more efficient and private but also publishing the key protecting any remaining bitcoin at an address after a spend. While this was a deliberate trade-off at the time, given the perceived longer timelines for quantum threats, the situation has changed. Currently, there are no concrete plans from bitcoin developers to address the quantum threat, unlike Ethereum, which has had a formal quantum-resistant program in place since 2018. Ethereum's approach includes four full-time teams and multiple independent developer groups working on the migration, with a detailed plan for upgrades and a dedicated website to track progress. In contrast, bitcoin has proposals such as BIP-360, which suggests introducing new quantum-safe address types for voluntary migration, and a competing proposal from BitMEX Research for a detection system to trigger defensive actions in case of a quantum attack. However, neither proposal has gained broad support from core developers, and they address different aspects of the problem. The challenge in implementing effective solutions lies in bitcoin's governance structure, which is designed to resist coordinated change. Ethereum's more centralized governance and funding for engineering work facilitate upgrades, whereas bitcoin's culture treats any central authority as a potential failure and emphasizes rare and difficult protocol changes. This has kept the network stable but makes addressing the quantum problem more complex. Migrating the exposed coins requires decisions that the network has historically avoided, such as whether to freeze old address formats, allow exposed coins to move to quantum-safe addresses, or determine the fate of coins whose owners cannot or will not migrate. The example of Satoshi's coins is particularly poignant, as freezing old formats would protect them but make them inaccessible, including to Satoshi, while leaving them open makes them a target for quantum attackers. Setting a migration deadline would force Satoshi to either move the coins, revealing ownership, or lose them, each option changing bitcoin's character in ways it has historically refused. The recent Google paper frames the situation as a potential signal that the window for adopting post-quantum cryptography may already be closing. This implies that by the time the threat becomes apparent, it may be too late to respond. Developers are faced with the question of whether a network built to resist change can coordinate a significant security upgrade before quantum computing becomes a reality. Ethereum's head start suggests the importance of starting now, while bitcoin's governance culture may lead to waiting until the threat is more visible, a strategy that may not be viable if the timeline is shorter than anticipated.