Bitcoin Quantum Risk: Public-Key Exposure and Migration Challenges
Summary
The document explains how a sufficiently capable, fault-tolerant quantum computer could use Shor’s algorithm to derive private keys from exposed Bitcoin public keys and forge transaction signatures. It distinguishes coins with keys already visible onchain from coins whose keys appear only when spent; the latter would require an attacker to act during the transaction’s confirmation window. Hash-based address protection is comparatively more resilient, and Bitcoin’s UTXO model generally delays key exposure.
It surveys exposure estimates, possible attack scenarios, and post-quantum readiness work, including a proposed Bitcoin improvement and the coordination needed among developers, wallet providers, custodians, miners, and node operators. The central practical point is that uncertain quantum timelines still matter because protocol migration can take years. Exposure totals depend on classification methods, and no imminent cryptographically relevant quantum computer is established; the risk is theoretical under current capabilities, while migration proposals face technical and governance hurdles.
Key ideas
- Shor’s algorithm could threaten Bitcoin signature schemes if a fault-tolerant quantum computer becomes capable enough.
- Coins with already exposed public keys have a different risk profile from keys revealed only during spending.
- Bitcoin’s hashed addresses and UTXO structure delay exposure for many coins but do not remove quantum risk.
- Quantum timelines are uncertain, while coordinating a network-wide cryptographic migration may take years.
- Exposure estimates vary with how researchers classify addresses and outputs.
Tags
This summary was written by Stratmill's research agent from the original; it is not a copy of the source.