Bitcoin's Vulnerability to Quantum Attacks: What We Know

4 replies 488 views
LoneLordFull Member
Posts: 10 · Reputation: 281
#1May 25, 2018, 04:05 PM
So, I dug into the blockchain from the very start to block 952,694 using Bitcoin Core 28.0.0. Turns out, about 5.07 million BTC, which is 25.3% of the total supply, is at risk from quantum threats. This affects over 12 million addresses. If you were active between 2009 and 2013, some of that might belong to you.
3 Reply Quote Share
coin88Full Member
Posts: 8 · Reputation: 287
#2May 25, 2018, 10:23 PM
I mean, sure, quantum computing is scary, but when it really gets rolling, it’s not gonna matter whether your keys are exposed or not. Everything’s at risk. Whether we’re talking about secp256k1 or SHA256, it’s a ticking time bomb. Honestly, the internet as we know it could be toast. But hey, don’t freak out just yet there are ways to keep things afloat, just gonna need some funds to back that up.
0 Reply Quote Share
alexsatNewbie
Posts: 131 · Reputation: 15
#3May 26, 2018, 03:57 AM
Wait, I thought Satoshi’s funds in P2PK were over a million coins? Or did he switch to P2PKH? You know, like the Patoshi theory. These numbers seem lower than I imagined. If those coins were compromised, it wouldn’t crash the market instantly, more like a slow burn. Anyway, wallets really need to step up their game on address re-use alerts.
0 Reply Quote Share
LoneLordFull Member
Posts: 10 · Reputation: 281
#4May 28, 2018, 06:45 AM
It's important to differentiate the two quantum risks here. Shor's algorithm is a big issue for ECDSA on secp256k1, actual threat to exposed pubkeys. Grover’s algorithm affects SHA256 too, but it’s more of a downgrade than a full-on breach. Saying the risk is less than 1 isn’t the best way to frame it. Pubkey hashes can be safe until they’re spent. By the way, about that 20k BTC estimate where’s that figure coming from?
1 Reply Quote Share
LoneLordFull Member
Posts: 10 · Reputation: 281
#5May 28, 2018, 08:37 AM
Agreed on the already-exposed addresses; if you’ve reused them, another transaction doesn’t change the threat level. But the 'don’t panic' approach is more for never-spent P2PKH/P2WPKH where the key is still hidden. Migrating during a quantum scare could actually expose your key when it matters most. For those at risk, better to migrate now. Target fresh P2PKH or P2WPKH until we have post-quantum signatures in place.
2 Reply Quote Share

Related topics