Bitcoin Faces Urgent Threat from Quantum Computers, Putting 6.9 Million BTC at Risk
Not all aspects of bitcoin are vulnerable to quantum computer attacks. The process of bitcoin mining, which involves a type of mathematics known as hashing, is secure against quantum computers. The blockchain itself and the rule that new bitcoins can only be created through mining would remain intact in the event of a quantum attack, with blocks continuing to be produced and the chain remaining operational. However, ownership of bitcoins is a different matter. Bitcoin wallets rely on a specific type of mathematics that converts a private key into a public address that can be seen by anyone. This mathematics works in one direction but not the other, and it is the only thing preventing an unauthorized person from spending someone else's coins. A quantum algorithm known as Shor's algorithm can bypass this one-way math problem. Recently, Google published a paper demonstrating that such an attack could be carried out with fewer resources than previously thought, and within a time frame that competes with bitcoin's block times. This article, the final part of a series, explores the potential response to this threat, including what is at risk, the measures bitcoin has taken so far, and whether the network can coordinate a significant security upgrade before quantum computers become a reality. Approximately 6.9 million bitcoins, roughly one-third of all mined bitcoins, are stored in wallets whose public keys are visible on the blockchain. This includes early bitcoins from the network's first years, which were stored in an address format that published the public key by default, as well as any wallet that has been spent from, as spending reveals the key for any remaining balance. A quantum attacker would not need to compete with an ongoing transaction but could instead work through the wallets with exposed keys at their own pace. This includes the approximately 1 million bitcoins held by bitcoin's pseudonymous creator, Satoshi Nakamoto, which have remained untouched since the network's early days. The 2021 Taproot upgrade inadvertently expanded the problem by making transactions more efficient and private, but as a side effect, any bitcoin spent since Taproot's activation has published the key protecting the remaining balance at that address. While there has been heated debate about the quantum threat in recent months, and other blockchains like Ethereum are preparing, concrete steps from Bitcoin developers have yet to emerge. Ethereum has had a formal quantum-resistant program in place since 2018, with four full-time teams working on the migration and more than ten independent developer groups shipping weekly test networks. Ethereum's plan involves specific upgrades across four upcoming network-wide changes, transitioning its security to new mathematics that quantum computers cannot break. In contrast, Bitcoin lacks a comparable strategy. There are proposals, such as BIP-360, which suggests adding new quantum-safe address types that holders could migrate to voluntarily, and a proposal from BitMEX Research to install a detection system that triggers defensive action if a quantum attack is observed. However, neither proposal has gained broad support from bitcoin's core developers, and they address different aspects of the problem. Prominent bitcoin advocate Nic Carter has expressed concern, stating that the elliptic curve cryptography used by bitcoin is on the verge of becoming obsolete and praising Ethereum's approach as 'best in class' while criticizing bitcoin's as 'worst in class'. Adam Back, CEO of Blockstream and an early contributor to bitcoin, disagrees on the urgency but agrees that bitcoin should prepare now by implementing optional upgrades in advance. The biggest challenge in implementing effective solutions against the quantum threat is not the mathematics itself but bitcoin's governance structure. Ethereum's foundation and governance process allow for regular major upgrades, whereas bitcoin's development culture is skeptical of central authority, and changes to the protocol are rare and difficult. This has kept the network stable for nearly two decades but makes the quantum problem harder to solve. Migrating the 6.9 million exposed coins requires decisions that the network has historically avoided. Questions include whether old address formats should be frozen after a certain date to protect coins from future theft, whether exposed coins should be allowed to move to new quantum-safe addresses using their original keys, and what happens to coins whose owners cannot or will not migrate. The situation with Satoshi's coins is particularly complex, as freezing old formats would protect the coins but make them inaccessible, including to Satoshi, while leaving the old formats open would mean those coins are at risk of being stolen by the first entity to build a working quantum computer. Setting a migration deadline would force Satoshi to either move the coins, revealing their ownership, or lose them. Every option would change bitcoin's character in ways the network has historically refused to change. The Google paper frames the situation as a potential signal that the window to adopt post-quantum cryptography may already be closing. This means that by the time the threat becomes apparent, it may be too late to respond. Developers are faced with the question of whether a network built to resist coordinated change can coordinate the biggest security upgrade in its history before quantum computers become a reality. Ethereum's eight-year head start in addressing this issue suggests that starting now is the correct approach, but bitcoin's governance culture may lead to waiting until the threat is demonstrated before taking action. Only one of these approaches will work if the timeline turns out to be shorter than estimated.