The potential threat of quantum computers to Bitcoin's security has ignited a complex debate within the cryptocurrency community, forcing a difficult choice between upholding property rights and ensuring system security. At the heart of the controversy is how to handle coins vulnerable to future quantum attacks, which could allow unauthorized spending of funds.
Bitcoin's current authorization mechanism relies on elliptic-curve cryptography, specifically ECDSA and Schnorr signatures using the secp256k1 curve. While classical computers find it computationally infeasible to derive a private key from a public key, a sufficiently powerful quantum computer running Shor's algorithm could break this assumption. This vulnerability creates two main attack classes: long-range attacks targeting outputs with already visible public keys (like old pay-to-public-key or Taproot outputs), and short-range attacks that occur when a transaction is broadcast, making the public key visible for a brief window.
The debate presents a dilemma with no easy answers. Doing nothing preserves current consensus rules but risks future theft by quantum-capable actors. Freezing vulnerable coins could prevent theft but retroactively invalidates past spending conditions. A forced migration to quantum-resistant signatures, while prudent, could be perceived as a deadline-backed confiscation. The core issue is minimizing property-rights violations once elliptic-curve signatures are no longer reliable.
However, the threat itself is in a 'quantum state of superposition,' with significant skepticism regarding the feasibility of building the necessary quantum computers. Critics argue that current noisy quantum processors require many reliable logical qubits, extremely low error rates, and successful quantum error correction at scale, conditions that may not be physically satisfiable. Arguments from Mikhail Dyakonov and Gil Kalai suggest that correlated noise and noise accumulation in realistic quantum systems could prevent the formation of high-quality quantum error-correcting codes, making scalable quantum computers unreliable.
Even if a cryptographically relevant quantum computer emerges, simply offering post-quantum cryptography as an option may not be enough. On-chain analysis suggests that a significant pool of Bitcoin, estimated at least 2.6 million BTC, could remain vulnerable even if active users migrate their wallets. This lingering vulnerability poses a systemic risk that could be exploited by quantum attackers.