Time is running out for bitcoin to mitigate quantum computer threats, with 6.9 million BTC at risk, including Satoshi's
While not all aspects of bitcoin are vulnerable to quantum computer attacks, certain components are at significant risk. The process of bitcoin mining, which involves adding new blocks to the blockchain, utilizes a type of mathematics known as hashing that quantum computers are currently unable to break. As a result, the blockchain itself and the rule that new bitcoins can only be created through mining would remain intact in the event of a quantum attack. However, ownership of bitcoins is a different matter. Bitcoin wallets rely on a specific type of mathematics that converts a secret private key into a public address. This math works effortlessly in one direction but is virtually impossible to reverse, which is the primary factor preventing unauthorized individuals from spending someone else's coins. A quantum algorithm known as Shor's algorithm can bypass this limitation. A recent paper by Google demonstrated that such an attack could be executed with fewer resources than previously estimated, and within a timeframe that competes with bitcoin's block creation times. This article, the final installment in a series, examines the potential consequences and the response of the bitcoin community. Approximately 6.9 million bitcoins, equivalent to one-third of all mined coins, are stored in wallets whose public keys are already visible on the blockchain. This includes early bitcoins from the network's inception, which were stored in an address format that published the public key by default, as well as any wallet that has been used for a transaction, as spending reveals the key for the remaining balance. A quantum attacker would not need to compete with an ongoing transaction; instead, they could systematically target wallets with exposed keys at their leisure. This includes the approximately 1 million bitcoins held by bitcoin's pseudonymous creator, Satoshi Nakamoto, which have remained untouched since the network's early days and are now at risk. The 2021 Taproot upgrade inadvertently expanded the problem by making bitcoin addresses more efficient and private, but as a side effect, any bitcoin spent since the upgrade has exposed the key protecting the remaining balance at that address. Although the quantum threat has sparked intense debate, bitcoin developers have yet to propose a concrete solution. In contrast, Ethereum, a major competitor, has had a formal quantum-resistant program in place since 2018, with four teams working full-time on the migration and a dedicated website to track progress. Bitcoin has no equivalent strategy, although there are proposals, such as BIP-360, which suggests introducing new quantum-safe address types, and a competing proposal from BitMEX Research for a detection system to trigger defensive actions in the event of a quantum attack. However, neither proposal has gained broad support from bitcoin's core developers, and they address different aspects of the problem. Prominent bitcoin advocate Nic Carter has criticized bitcoin's approach, describing it as 'worst in class' compared to Ethereum's 'best in class' strategy. Adam Back, CEO of Blockstream and an early bitcoin contributor, agrees that bitcoin should prepare for the quantum threat but disagrees on the urgency. The main challenge in implementing effective solutions is bitcoin's lack of a centralized authority and formal governance process, which makes coordinating a major upgrade more difficult. The migration of the 6.9 million exposed coins requires decisions that the network has historically avoided, such as whether to freeze old address formats or allow exposed coins to move to new quantum-safe addresses. Every option would alter bitcoin's character in ways the network has traditionally resisted. The future of bitcoin hangs in the balance, as the window to respond to the quantum threat may already be closing.