Bitcoin's Quantum Conundrum: A Race Against Time to Prevent a 6.9 Million BTC Heist
Not all aspects of bitcoin are vulnerable to quantum computer attacks. The process of bitcoin mining, which utilizes a type of math called hashing, is resistant to quantum computer breaches. The blockchain ledger and the rule that new bitcoins can only be created through mining would remain intact in the event of a quantum attack, ensuring the continuous production of blocks and the operation of the chain. However, ownership is a different story. Bitcoin wallets rely on a distinct mathematical concept that converts a private key into a public address. This math is easily computable in one direction but virtually impossible in the other, and it is the sole barrier preventing unauthorized individuals from spending bitcoins. The first part of this series on quantum computing delved into the physics underlying the technology, explaining how a quantum computer is a fundamentally distinct type of machine that operates at extremely low temperatures and small scales, where particles exhibit unique behaviors. The second installment examined the implications of directing a quantum computer at bitcoin, highlighting how bitcoin wallets depend on a one-way mathematical problem. Converting a private key into a public address takes milliseconds, whereas reversing the process would take an ordinary computer longer than the age of the universe. A quantum algorithm known as Shor's algorithm significantly reduces this time gap. A recent paper by Google demonstrated that this attack could be executed with far fewer resources than previously estimated, and within a time frame that competes with bitcoin's block times. This final piece in the series focuses on the response to this threat, including what is at risk, the measures bitcoin has taken, and whether a network designed to resist coordinated change can implement the most substantial security upgrade in its history before the advent of quantum hardware. Approximately 6.9 million bitcoins, equivalent to one-third of all mined bitcoins, are stored in wallets with publicly visible keys on the blockchain. This includes early bitcoins from the network's inaugural years, which were stored in an address format that published the public key by default, as well as any wallet that has been spent from, as spending reveals the key for the remaining balance. A quantum attacker would not need to compete with an ongoing transaction but could instead systematically target wallets with exposed keys at their leisure. This includes the roughly 1 million bitcoins held by bitcoin's pseudonymous creator, Satoshi Nakamoto, which have remained untouched since the network's early days and are now vulnerable. The 2021 Taproot upgrade inadvertently expanded the problem by changing how bitcoin addresses function, with the intention of making transactions more efficient and private. As a result, any bitcoin spent since the activation of Taproot has published the key protecting the remaining balance at that address. Although this was not an error, it was a reasonable trade-off at the time, given the perceived longer timeline for quantum threats. Currently, there are no concrete plans from Bitcoin developers to address the quantum threat, despite the heated debate in recent months. In contrast, Ethereum, a major competitor, has had a formal quantum-resistant program in place since 2018. The Ethereum Foundation has four full-time teams working on the migration, along with multiple independent developer groups releasing weekly test networks. Ethereum's plan involves specific upgrades across four upcoming network-wide changes, transitioning its security to quantum-resistant math. Bitcoin, on the other hand, lacks a comparable strategy. There are, however, efforts underway to solve the problem, including a formal proposal called BIP-360, which suggests introducing new quantum-safe address types that holders could migrate to voluntarily. Another proposal from BitMEX Research involves installing a detection system that triggers defensive actions if a quantum attack is observed on the network. Neither proposal has garnered broad support from bitcoin's core developers, and they address different aspects of the problem. Prominent bitcoin advocate Nic Carter has emphasized the urgency of the situation, stating that the math securing bitcoin wallets is on the verge of becoming obsolete. He praised Ethereum's approach as 'best in class' and criticized bitcoin's as 'worst in class,' citing developers who deny or downplay the issue rather than engaging with it. Adam Back, CEO of Blockstream and an early bitcoin contributor, disagrees on the urgency but agrees that bitcoin should prepare by implementing optional upgrades in advance, allowing the network to migrate when necessary rather than reacting in a crisis. The biggest challenge in implementing effective solutions against the quantum threat lies in bitcoin's migration being more complex than Ethereum's due to its lack of a central authority and governance process. Bitcoin's development culture views any central authority as a failure mode, and its social consensus holds that changes to the protocol should be rare and difficult. While these principles have maintained the network's stability for nearly two decades, they also make addressing the quantum problem structurally more challenging for bitcoin. Migrating the 6.9 million exposed coins requires decisions that the network has historically avoided, such as whether to freeze old address formats after a certain date to protect coins from future theft, or whether exposed coins should be allowed to move to new quantum-safe addresses using their original keys. The fate of coins whose owners cannot or will not migrate also poses a significant question, with Satoshi's coins being the most notable example. Freezing old formats would protect the coins but make them permanently inaccessible, including to Satoshi, while leaving the old formats open would leave the coins vulnerable to quantum attacks. Setting a migration deadline would force Satoshi to either move the coins, revealing their ownership, or lose them, with every option changing bitcoin's character in ways the network has historically refused to change. The Google paper frames the situation as a potential signal that the adoption of post-quantum cryptography may have already failed by the time a successful attack occurs. This means that the window to respond may have closed by the time the threat becomes apparent. Developers are now faced with the question of whether a network built to resist coordinated change can coordinate the largest security upgrade in its history before quantum hardware becomes a reality. Ethereum's eight-year head start suggests that starting now is the correct approach, but bitcoin's governance culture indicates that the network may wait until the threat is demonstrated before taking action. Only one of these approaches will be effective if the timeline proves to be shorter than optimists estimate.