Researchers have calculated that a future quantum computer could recover a Bitcoin private key with far fewer qubits than once thought. No such machine exists. Bitcoin’s challenge is to prepare before one does.
Bitcoin is protected by a secret number called a private key. Its owner uses that number to approve a payment. A public key lets the network check that approval without revealing the secret.
For an ordinary computer, working backwards from a public key to the private key is effectively impossible. A sufficiently powerful quantum computer could do it. It could then sign a payment as though it owned the coins.
This month, researchers at the quantum computing company IonQ calculated what such an attack might require. In their proposed design, a machine with about 20,000 qubits — the building blocks of a quantum computer — could recover a Bitcoin private key in roughly 26 days per attempt.
A separate research team has estimated that as few as 10,000 qubits could run a related cryptographic calculation using a different design. That figure is not an estimate for stealing a Bitcoin key in days. Both studies describe machines that have yet to be built. No quantum computer can carry out this attack today.
Which coins would be exposed first?
The 26-day estimate helps answer that question. Some Bitcoin public keys have been visible on the blockchain for years. An attacker could work on one of those keys while its coins remained untouched. Other addresses keep the public key hidden until the owner makes a payment. A machine needing 26 days would generally be too slow to attack that payment before it was confirmed.
This is a threat to ownership, not to Bitcoin’s record of past transactions. An attacker would not have to erase a payment or seize control of the network. Recovering a private key would let them create a new transaction that the network could accept as genuine.
There is still an immense gap between a proposed design and a working computer that can run accurately for weeks. IonQ has a commercial interest in demonstrating what its technology might achieve. Its study did not break a wallet or move a single bitcoin.
A slow migration
Bitcoin developers are already discussing defences. One draft proposal would help protect coins whose public keys would otherwise be exposed for a long time. Protecting payments against a much faster quantum computer would require a further change to Bitcoin’s signatures. Neither change is in place.
Even after developers agreed on a solution, wallets, exchanges and coin holders would need to adopt it. Some old coins may never move because their owners have lost their keys or died. If a future quantum machine could take those coins, should Bitcoin’s rules leave them available to whoever builds it first, or prevent them from being spent? A draft migration plan raises that question, but there is no agreed answer.
Bitcoin faces no demonstrated quantum theft today. Yet the designs for a machine capable of attacking its keys are becoming more precise, while the plan to protect those keys remains unfinished.