Time Running Out for Bitcoin to Avert Quantum Threat, Putting 6.9 Million BTC at Risk
Not all aspects of bitcoin are vulnerable to quantum computers. The process of bitcoin mining, which involves a type of mathematics known as hashing, is resistant to quantum attacks. This means that the blockchain ledger and the rule that new bitcoins can only be created through mining would remain intact. However, ownership of bitcoins is a different story. Bitcoin wallets rely on a specific type of mathematics that converts a private key into a public address. This math works in one direction but not the other, which prevents unauthorized access to coins. A quantum algorithm known as Shor's algorithm can bypass this security measure. Recently, Google released a paper demonstrating that a quantum attack could be executed with fewer resources than previously thought, making it a pressing concern for bitcoin. This article explores the potential risks, what bitcoin has done so far to address the issue, and whether the network can coordinate a significant security upgrade before quantum computers become a threat. Approximately 6.9 million bitcoins, or one-third of all mined coins, are stored in wallets with publicly visible keys, making them susceptible to quantum attacks. This includes early bitcoins and any wallet that has been spent from, as spending reveals the key. The 2021 Taproot upgrade inadvertently expanded the problem by publishing keys for any bitcoin spent since its activation. While there are ongoing debates among bitcoin developers, no concrete plan has emerged yet. In contrast, Ethereum has had a formal quantum-resistant program in place since 2018, with multiple teams working on the migration and a dedicated website to track progress. Bitcoin has proposals, such as BIP-360, which suggests introducing new quantum-safe address types, and a competing proposal from BitMEX Research for a detection system to trigger defensive actions in case of a quantum attack. However, neither proposal has broad support from core developers. The lack of a centralized authority and a governance process makes it challenging for bitcoin to implement effective solutions. The network's development culture emphasizes stability and rare, hard changes, which has kept it stable for nearly two decades but also makes addressing the quantum threat more difficult. Migrating the exposed coins requires decisions that the network has historically avoided, such as freezing old address formats or allowing exposed coins to move to new quantum-safe addresses. Every option has implications for bitcoin's character and requires coordination that may not be feasible given the network's governance structure. The question remains whether bitcoin can coordinate a significant security upgrade before the threat becomes reality.