The Clock is Ticking: Can Bitcoin Prevent a Quantum Threat to 6.9 Million BTC?

Not all aspects of bitcoin are vulnerable to quantum computers. The process of bitcoin mining, which involves adding new blocks to the blockchain, utilizes a type of mathematics known as hashing that quantum computers are unable to break. As a result, the blockchain itself and the rule that new bitcoins can only be created through mining will remain intact in the event of a quantum attack. However, ownership is a different story. Bitcoin wallets rely on a distinct type of mathematics that converts a private key into a public address. This math is straightforward in one direction but extremely challenging in the other, which is the primary factor preventing unauthorized individuals from spending your coins. A quantum algorithm known as Shor's can bridge this gap. A recent paper by Google demonstrated that this attack can be executed with significantly fewer resources than previously estimated, and within a timeframe that competes with bitcoin's block times. This article, the final installment in a series, focuses on the response to this threat. It examines what is actually at risk, the measures bitcoin has taken so far, and whether a network designed to resist coordinated change can coordinate the largest security upgrade in its history before the threat materializes. The vulnerable pool of bitcoin is substantial, with approximately 6.9 million bitcoin, or roughly one-third of all mined bitcoin, stored in wallets with publicly visible keys on the blockchain. This includes early bitcoin from the network's initial years, which was stored in an address format that published the public key by default, as well as any wallet that has been spent from, as spending reveals the key for any remaining balance. A quantum attacker would not need to compete with an ongoing transaction; instead, they could work through wallets with exposed keys at their own pace. Bitcoin's pseudonymous creator, Satoshi Nakamoto, holds approximately 1 million bitcoin that have remained untouched since the network's early days and are now classified as exposed. The 2021 Taproot upgrade expanded the problem by introducing a change to how bitcoin addresses function, aiming to make transactions more efficient and private. As a result, any bitcoin spent since Taproot's activation has published the key protecting the remaining balance at that address. While the quantum threat has sparked intense debate in recent months, and other blockchains are preparing, bitcoin developers have yet to propose a concrete plan. Ethereum, one of bitcoin's largest competitors, has had a formal quantum-resistant program in place since 2018. The Ethereum Foundation operates four full-time teams working on the migration and has launched a dedicated website to track progress. Bitcoin, on the other hand, lacks a comparable strategy. There are efforts to address the issue, including a formal proposal known as BIP-360, which would introduce new quantum-safe address types that holders could migrate to voluntarily. Another proposal from BitMEX Research suggests implementing a detection system that triggers defensive action in the event of a quantum attack on the network. However, neither proposal has garnered broad support from bitcoin's core developers, and they address different aspects of the problem. The lack of a unified approach to addressing the quantum threat poses a significant challenge for bitcoin. The network's development culture, which treats any central authority as a failure mode and emphasizes rare and difficult protocol changes, makes it structurally harder for bitcoin to respond to the quantum threat. Migrating the exposed coins requires decisions that the network has avoided for twenty years. The fate of Satoshi's coins serves as a prime example, as freezing old formats would protect them from theft but render them permanently inaccessible, including to Satoshi. Every possible solution changes bitcoin's character in ways the network has historically refused to change. The future of bitcoin's quantum resistance remains uncertain, with the Google paper's framing serving as a summary of the industry's current stance. A successful attack on bitcoin's math should not be seen as a wake-up call to adopt post-quantum cryptography but rather as a potential signal that adoption has already failed. This implies that by the time the threat becomes apparent, the window to respond may have already closed. Developers are now faced with the question of whether a network built to resist coordinated change can coordinate the largest security upgrade in its history before the threat materializes.