Bitcoin quantum threat spurs work on transactions, upgrades and custody
Researchers and companies are pursuing three Bitcoin quantum defenses, but none of the reported efforts makes the network quantum-safe on its own.
By Sofia Marchetti · Columnist
· 3 min read
The bitcoin quantum threat has pushed researchers and crypto companies to focus on three defenses: transaction-level workarounds, a potential network upgrade and new custody safeguards. For investors, the immediate point is that no publicly known quantum computer can break Bitcoin keys today, according to Galaxy Research, but the eventual transition would require technical changes and broad coordination.
Bitcoin uses elliptic-curve signatures, including ECDSA and Schnorr, to authorize payments. A sufficiently powerful, fault-tolerant quantum computer running Shor’s algorithm could theoretically work backward from an exposed public key to obtain its private key, allowing forged transactions, Galaxy Research and Decrypt reported.
That theoretical arrival is often called Q-Day. Its timing is unknown, and existing quantum machines lack the scale, stability and precision to attack Bitcoin’s cryptography, according to the Human Rights Foundation and Galaxy Research.
How are developers addressing the Bitcoin quantum threat?
The first approach aims to create quantum-resistant transactions under Bitcoin’s existing rules. Decrypt reported that StarkWare said a competition cut its estimate for the GPU computing cost to construct one of these transactions from about $320 to roughly $67 in a week.
That work remains a limited workaround. Decrypt said the transactions are nonstandard and protect only coins whose public keys have not already been revealed. It does not address funds associated with already exposed keys.
The second, broader route would change Bitcoin itself to use post-quantum signatures. StarkWare views a soft fork as the stronger long-term option, Decrypt reported. A soft fork is a backward-compatible upgrade: nodes that have not upgraded can still process transactions that follow the new rules, according to Chainlink.
Such a move would still take time. Bitcoin has no administrator who can order users to update. Forbes reported that developers, miners, exchanges, custodians, wallet providers and holders would need to coordinate a migration to quantum-resistant addresses. Decrypt said protocol changes of this kind require lengthy design, testing and deployment.
The third layer is custody. Decrypt reported that Coinbase’s head of cryptography outlined post-quantum custody systems designed to adapt to whichever signature scheme Bitcoin ultimately adopts, with a hardware fallback if that scheme does not work with current key-splitting methods.
Which Bitcoin holdings could face greater exposure?
The risk is uneven. Galaxy Research said long-exposed public keys, including some legacy holdings and reused addresses, are a principal concern. A public key can also be exposed when a holder spends coins. Estimates of potentially exposed bitcoin vary by methodology: Forbes cited Honey Island Capital’s estimate of roughly 6.9 million BTC, while Galaxy cited Project Eleven’s estimate of about 7 million BTC under its long-exposure definition.
Migration also leaves a hard policy question for dormant, lost or inaccessible coins. The Human Rights Foundation described a debate between leaving those funds exposed in a future attack or making them unspendable, which would create neutrality trade-offs. It also said quantum-resistant transactions could be substantially larger than today’s, adding pressure on Bitcoin’s limited block capacity.
None of the efforts reported this week makes Bitcoin quantum-safe on its own. The practical challenge is preparing compatible defenses and a network-wide migration before a cryptographically relevant quantum computer exists.
This story draws on original reporting from Decrypt.