Time Runs Out for Bitcoin to Counter Quantum Threat, Putting 6.9 Million BTC at Risk

Not all aspects of bitcoin are vulnerable to quantum computers. The process of mining, which involves adding new blocks to the blockchain, utilizes a type of mathematics known as hashing that quantum computers are unable to break. As a result, the blockchain itself and the rule that new bitcoins can only be created through mining would survive a quantum attack. However, ownership of bitcoins is a different story. Bitcoin wallets rely on a distinct type of mathematics that converts a private key into a public address. This math functions seamlessly in one direction but is impractical in the other, and it is the sole barrier preventing unauthorized individuals from spending someone else's coins. A quantum algorithm known as Shor's algorithm can bypass this barrier. A recent paper by Google demonstrated that this attack could be executed with significantly fewer resources than previously estimated, and within a timeframe that competes with bitcoin's block times. This article explores the potential consequences and the response of the bitcoin community. Approximately 6.9 million bitcoins, equivalent to one-third of all mined bitcoins, are stored in wallets whose public keys are permanently visible on the blockchain. This includes early bitcoins from the network's first years, which were stored in an address format that published the public key by default, as well as any wallet that has been spent from, as spending reveals the key for the remaining balance. A quantum attacker would not need to compete with an ongoing transaction; instead, they could systematically target wallets with exposed keys at their leisure. Bitcoin's pseudonymous creator, Satoshi Nakamoto, holds approximately 1 million bitcoins that have remained untouched since the network's early days and are now categorized as exposed. The 2021 Taproot upgrade inadvertently expanded the problem by making transactions more efficient and private, but as a side effect, any bitcoin spent since Taproot's activation has published the key protecting the remaining balance at that address. While the quantum threat has sparked intense debate, bitcoin developers have yet to propose a concrete solution. In contrast, Ethereum, a major competitor, has had a formal quantum-resistant program in place since 2018, with four teams working full-time on the migration and multiple independent developer groups testing networks weekly. Ethereum has even launched a dedicated website to track its progress. Bitcoin, on the other hand, lacks a comparable strategy. There are, however, efforts underway to address the issue, including a formal proposal known as BIP-360, which suggests introducing new quantum-safe address types that holders could migrate to voluntarily. Another proposal from BitMEX Research recommends implementing a detection system that triggers defensive actions if a quantum attack is observed on the network. Neither proposal has garnered broad support from bitcoin's core developers, and they address different aspects of the problem. The challenge in implementing effective solutions lies in bitcoin's governance culture, which treats central authority as a failure mode and emphasizes rare and difficult protocol changes. This has kept the network stable for nearly two decades but makes the quantum problem more difficult to solve. Migrating the 6.9 million exposed coins requires decisions that the network has avoided for twenty years. The question remains whether a network built to resist coordinated change can coordinate the largest security upgrade in its history before quantum computers become a reality.