Time's Running Out for Bitcoin to Counter Quantum Computing Threat
Not all aspects of bitcoin are vulnerable to quantum computer attacks. The process of bitcoin mining, which involves adding new blocks to the blockchain, uses a type of mathematics known as hashing that quantum computers are unable to break. As a result, the ledger and the rule that new bitcoins can only be created through mining would survive a quantum attack. However, ownership of bitcoins would be at risk. Bitcoin wallets are secured by a different kind of mathematics that converts a private key into a public address. This math works in one direction but not the other, preventing strangers from spending someone else's coins. A quantum algorithm known as Shor's algorithm can break this math, and a recent paper by Google demonstrated that this attack could be carried out with fewer resources than previously thought. This article discusses the potential risks and the response of the bitcoin community to the quantum threat. Approximately 6.9 million bitcoins, or about one-third of all mined bitcoins, are at risk due to exposed public keys. This includes early bitcoins stored in addresses that published public keys by default, as well as wallets that have been spent from, revealing their public keys. A quantum attacker would not need to rush to exploit these wallets, as they could work through them at their own pace. Even Satoshi Nakamoto, the pseudonymous creator of bitcoin, holds around 1 million bitcoins that are now at risk. The 2021 Taproot upgrade inadvertently expanded the problem by publishing the keys protecting remaining bitcoins at an address after a transaction. While there are ongoing debates and proposals to address the quantum threat, bitcoin developers have yet to come up with a concrete plan. In contrast, Ethereum has had a formal quantum-resistant program in place since 2018 and is actively working on migrating its security to quantum-resistant mathematics. The lack of a centralized authority and governance process in bitcoin makes it harder to coordinate a response to the quantum threat. Migrating the exposed coins would require decisions that the network has avoided for years, such as freezing old address formats or allowing exposed coins to move to new quantum-safe addresses. The fate of Satoshi's coins is a prime example, as freezing old formats would protect the coins but make them inaccessible, including to Satoshi. Setting a migration deadline would force Satoshi to either move the coins, revealing their ownership, or lose them. The future of bitcoin's security hangs in the balance, and the question remains whether the network can coordinate a massive security upgrade before the quantum threat becomes a reality.