Bitcoin's Quantum Conundrum: Can the Network Mitigate the Looming Threat?

Not all aspects of bitcoin are vulnerable to quantum computer attacks. The process of bitcoin mining, which utilizes a type of mathematics known as hashing, is resistant to quantum computer exploitation. Consequently, the bitcoin ledger and the principle that new bitcoins can only be created through mining would remain intact in the face of a quantum attack, with blocks continuing to be produced and the chain remaining operational. However, what is at risk is ownership. Bitcoin wallets rely on a different form of mathematics that converts a private key into a public address. This mathematical function is straightforward in one direction but virtually impossible in the other, which is the primary obstacle preventing unauthorized individuals from spending someone else's coins. The first part of this series delved into the physics of quantum computing, explaining that a quantum computer is fundamentally distinct from a regular computer, operating at extremely low temperatures and tiny scales where particles exhibit unique behaviors. The second part examined the implications of directing a quantum computer at bitcoin, highlighting that bitcoin wallets depend on a one-way mathematical problem. While transforming a private key into a public address takes mere milliseconds, reversing this process would take a conventional computer longer than the universe's age. A quantum algorithm known as Shor's algorithm significantly reduces this time gap. A recent paper by Google demonstrated that such an attack could be executed with fewer resources than previously estimated, racing against bitcoin's block times. This final installment focuses on the response to this threat, including what is actually at risk, the measures bitcoin has taken, and whether a network designed to resist coordinated change can implement the most significant security upgrade in its history before quantum hardware becomes a reality. The pool of exposed bitcoin is substantial, with approximately 6.9 million bitcoins, or about one-third of all mined bitcoins, stored in wallets whose public keys are permanently visible on the blockchain. This includes early bitcoins from the network's first years, stored in an address format that published the public key by default, as well as any wallet that has ever been spent from, since spending reveals the key for the remaining balance. A quantum attacker would not need to compete with an ongoing transaction but could instead work through the wallets with exposed keys at their own pace. Notably, this includes the approximately 1 million bitcoins held by bitcoin's pseudonymous creator, Satoshi Nakamoto, which have remained untouched since the network's early days and are now in the exposed category. The 2021 Taproot upgrade inadvertently expanded the problem by changing how bitcoin addresses function, aiming to make transactions more efficient and private. As a side effect, any bitcoin spent since Taproot's activation has published the key protecting the remaining balance at that address. Although this was not a mistake, it was a reasonable tradeoff at the time, given the perceived longer timelines for quantum threats. Currently, there are ongoing efforts to address the quantum threat, with heated debates among developers and preparations underway on other blockchains. Ethereum, a major competitor to bitcoin, has had a formal quantum-resistant program in place since 2018, with the Ethereum Foundation running four full-time teams and multiple independent developer groups working on the migration. In contrast, bitcoin has no equivalent strategy, although there are proposals, such as BIP-360, which suggests introducing new quantum-safe address types for voluntary migration, and a competing proposal from BitMEX Research for a detection system that triggers defensive actions upon observing a quantum attack on the network. Neither proposal has broad support from bitcoin's core developers, and they address different aspects of the problem. Prominent bitcoin advocate Nic Carter has emphasized the urgency of the situation, stating that the elliptic curve cryptography securing bitcoin wallets is on the verge of obsolescence and praising Ethereum's approach as 'best in class' while criticizing bitcoin's as 'worst in class.' Adam Back, CEO of Blockstream and an early bitcoin contributor, agrees on the need for preparation but disagrees on the immediacy of the threat, suggesting that bitcoin should prepare now with optional upgrades to migrate when necessary, rather than reacting in a crisis. The biggest challenge in implementing effective solutions against the quantum threat lies in bitcoin's governance structure. Unlike Ethereum, which has a foundation funding engineering work and a governance process for major upgrades, bitcoin's development culture is wary of central authority, and its social consensus favors rare and difficult changes to the protocol. While this has maintained network stability for nearly two decades, it makes addressing the quantum problem structurally harder for bitcoin. Migrating the exposed 6.9 million coins requires decisions that the network has historically avoided, such as whether to freeze old address formats to protect coins from future theft or allow exposed coins to move to new quantum-safe addresses using their original keys. The fate of coins whose owners cannot or will not migrate, including Satoshi's, poses a significant dilemma, with every option changing bitcoin's character in ways the network has refused to change. The Google paper frames the industry's stance, suggesting that a successful attack on bitcoin's mathematics should not be seen as a wake-up call to adopt post-quantum cryptography but rather as a potential signal that such adoption has already failed. This implies that by the time the threat becomes apparent, the window for response may have closed. Developers face the question of whether a network built to resist coordinated change can coordinate the largest security upgrade in its history before quantum hardware catches up. Ethereum's eight-year head start suggests starting now is the correct approach, while bitcoin's governance culture indicates a likely wait until the threat is demonstrated before acting. Only one of these strategies will be effective if the timeline proves shorter than optimists estimate.