Time is Running Out for Bitcoin to Mitigate Quantum Computing Threat
Not all aspects of bitcoin are vulnerable to quantum computers. The process of adding new blocks to the blockchain, known as mining, relies on a type of mathematics called hashing, which is resistant to quantum attacks. The blockchain itself and the rule that new bitcoins can only be created through mining would remain intact in the event of a quantum attack. However, ownership of bitcoins would be at risk. Bitcoin wallets are secured by a different type of mathematics that converts a private key into a public address. This math is easy to perform in one direction but virtually impossible in the other, which prevents unauthorized access to the coins. A quantum algorithm known as Shor's algorithm can break this math, potentially allowing hackers to access and steal coins. Google recently published a paper demonstrating that a quantum attack on bitcoin could be carried out with fewer resources than previously thought, highlighting the urgent need for a solution. Approximately 6.9 million bitcoins, or one-third of all mined coins, are stored in wallets with publicly visible keys, making them vulnerable to quantum attacks. This includes early bitcoins stored in outdated address formats and any wallet that has been used for a transaction, as the public key is revealed during the spending process. Even Satoshi Nakamoto's estimated 1 million untouched bitcoins are at risk. The 2021 Taproot upgrade inadvertently increased the vulnerability by publishing the public key of any bitcoin spent since its activation. While the quantum threat has sparked debate, no concrete plan has emerged from bitcoin developers. In contrast, Ethereum has had a formal quantum-resistant program in place since 2018, with multiple teams working on the migration to quantum-resistant cryptography. Some proposals have been put forth for bitcoin, including the introduction of new quantum-safe address types and a detection system to trigger defensive action in the event of a quantum attack. However, these proposals lack broad support from core developers and only address part of the problem. The lack of a centralized authority and formal governance process makes it challenging for bitcoin to coordinate a response to the quantum threat. The network's development culture prioritizes decentralization and stability over rapid changes, which may hinder its ability to implement effective solutions. The migration of 6.9 million exposed coins requires decisions that the network has avoided for years, such as freezing old address formats or allowing exposed coins to move to new quantum-safe addresses. Every option has significant implications for the network's character and stability. The Google paper's warning that a successful attack should not be seen as a wake-up call but rather as a potential signal that post-quantum cryptography adoption has already failed highlights the urgency of the situation. Developers must now determine whether the network can coordinate a massive security upgrade before the threat becomes a reality.