Bitcoin's Quantum Conundrum: A Race Against Time to Safeguard 6.9 Million Coins
Not all aspects of bitcoin are vulnerable to quantum computer attacks. The mining process, which utilizes a type of math known as hashing, is resistant to quantum computers. As a result, the blockchain ledger and the rule that new bitcoins can only be created through mining would remain intact in the event of a quantum attack. However, ownership is a different story. Bitcoin wallets rely on a distinct type of math that converts a private key into a public address. This math is easily solvable in one direction but extremely difficult to reverse, which is the primary obstacle preventing unauthorized individuals from spending someone else's coins. A quantum algorithm known as Shor's algorithm can bridge this gap. A recent paper by Google demonstrated that this attack can be executed with significantly fewer resources than previously estimated, and within a timeframe that competes with bitcoin's block times. This article, the final installment in a series, explores the potential consequences, the measures bitcoin has taken so far, and whether a network designed to resist coordinated change can implement the most substantial security upgrade in its history before quantum computers catch up. The pool of vulnerable bitcoin is substantial, with approximately 6.9 million coins, or one-third of all mined bitcoin, stored in wallets whose public keys are already visible on the blockchain. This includes early bitcoin from the network's inaugural years, which was stored in an address format that publicly disclosed the public key by default. It also encompasses any wallet that has been spent from, as spending reveals the key for the remaining balance. A quantum attacker would not need to compete with an ongoing transaction; instead, they could systematically work through wallets with exposed keys at their leisure. Bitcoin's pseudonymous creator, Satoshi Nakamoto, holds roughly 1 million bitcoin that has remained untouched since the network's early days and now falls into the vulnerable category. The 2021 Taproot upgrade inadvertently expanded the problem. Taproot is a modification to how bitcoin addresses function, intended to make transactions more efficient and private. A side effect of this upgrade is that any bitcoin spent since its activation has publicly disclosed the key protecting the remaining balance at that address. Although this was not an error, it was a reasonable tradeoff at the time, given the perceived longer timeline for quantum threats. Currently, there are efforts underway to address the quantum threat. Ethereum, a major competitor to bitcoin, has had a formal quantum-resistant program in place since 2018. The Ethereum Foundation has four teams working full-time on the migration, with over ten independent developer groups releasing weekly test networks. Their plan involves specific upgrades across four upcoming network-wide changes, transitioning Ethereum's security to new math that quantum computers cannot break. In contrast, bitcoin lacks a comparable strategy. There are, however, proposals from developers and researchers, such as BIP-360, which would introduce new quantum-safe address types that holders could voluntarily migrate to. Another proposal from BitMEX Research suggests implementing a detection system that would trigger defensive actions if a quantum attack is observed on the network. Neither proposal has garnered broad support from bitcoin's core developers, and they address different aspects of the problem. Nic Carter, a prominent bitcoin advocate, has emphasized the urgency of the situation, stating that the math securing bitcoin wallets is on the verge of becoming obsolete. He praised Ethereum's approach as 'best in class' and criticized bitcoin's as 'worst in class,' citing developers who deny, downplay, or ignore the issue rather than engaging with it. Adam Back, the CEO of Blockstream and an early contributor to bitcoin, disagrees on the urgency but agrees that bitcoin should prepare by incorporating optional upgrades in advance, allowing the network to migrate when necessary rather than reacting in a crisis. The primary challenge in implementing effective solutions against bitcoin's quantum threat lies in its migration, which is more complex than Ethereum's due to reasons unrelated to the math itself. Ethereum has a foundation that funds engineering work and a governance process that regularly implements significant upgrades. Bitcoin, on the other hand, lacks a central authority and a governance process, with its development culture treating any centralized control as a failure mode. The social consensus within bitcoin holds that changes to the protocol should be rare and difficult. While these principles have maintained the network's stability for nearly two decades, they also make addressing the quantum problem structurally more challenging for bitcoin. Migrating the 6.9 million exposed coins requires decisions that the network has avoided for twenty years. Questions arise about whether old address formats should be frozen after a certain date to protect coins from future theft, whether exposed coins should be allowed to move to new quantum-safe addresses using their original keys, and what happens to coins whose owners cannot or will not migrate. Satoshi's coins serve as a prime example. Freezing old formats protects the coins from theft but renders them permanently inaccessible, including to Satoshi. Leaving the old formats open means those coins remain a potential target for whoever develops a functional quantum computer or gains access to one. Setting a migration deadline forces Satoshi to either move the coins, revealing their ownership, or lose them. Every option alters bitcoin's character in ways the network has historically refused to change. The Google paper's framing serves as a summary of the industry's current stance. A successful attack on bitcoin's math 'should not be seen as a wake-up call to adopt post-quantum cryptography as much as a potential signal that PQC adoption has already failed.' This implies that by the time the threat becomes apparent, the window to respond may have already closed. Developers now face the question of whether a network designed to resist coordinated change can coordinate the most significant security upgrade in its history before quantum computers catch up. Ethereum's eight-year head start suggests that starting now is the correct approach. Bitcoin's governance culture, however, suggests that the likely response will be to wait until the threat is demonstrated before taking action. Only one of these approaches will be effective if the timeline proves shorter than optimists estimate.