The Quantum Threat
Understanding why quantum computers threaten cryptocurrency security
The Quantum Threat
Quantum computers pose an existential threat to the cryptography that secures most cryptocurrencies. This page explains the threat and why BTQ provides protection.
What Are Quantum Computers?
Quantum computers use quantum mechanical phenomena to perform calculations:
- Qubits: Unlike classical bits (0 or 1), qubits can be both simultaneously (superposition)
- Entanglement: Qubits can be correlated in ways impossible for classical bits
- Interference: Quantum states can be combined to amplify correct answers
This allows quantum computers to solve certain problems exponentially faster than classical computers.
The Threat to Cryptography
Shor's Algorithm
In 1994, mathematician Peter Shor discovered a quantum algorithm that can:
- Factor large numbers in polynomial time
- Solve discrete logarithms in polynomial time
This breaks:
- RSA: Based on factoring difficulty
- ECDSA: Based on discrete log difficulty (used by Bitcoin and most cryptocurrencies)
- Diffie-Hellman: Used for key exchange
Shor's algorithm doesn't just make these problems "a bit easier" - it reduces the difficulty from billions of years to hours or minutes.
What This Means for Bitcoin/ECDSA
ECDSA security relies on the hardness of the Elliptic Curve Discrete Logarithm Problem (ECDLP):
Given: Public Key P = k * G (where G is the generator point)
Find: Private Key kClassical computers: Would take longer than the age of the universe Quantum computers: Could solve in hours with ~2,300 logical qubits
Grover's Algorithm
Grover's algorithm provides a quadratic speedup for search problems:
- Classical: O(N) operations to search N items
- Quantum: O(sqrt(N)) operations
This affects:
- Hash functions: Security effectively halved (256-bit becomes 128-bit)
- Mining: Quantum miners would have an advantage
However, this is less severe than Shor's algorithm - doubling key sizes provides protection.
Timeline: When Will This Happen?
Current State (2024-2025)
- Largest quantum computers: ~1,000+ physical qubits
- Error rates: Still too high for useful cryptography attacks
- Logical qubits: Very few (physical qubits needed for error correction)
Expert Estimates
| Timeframe | Probability | Source |
|---|---|---|
| By 2030 | 5-10% | NIST |
| By 2035 | 15-25% | Various researchers |
| By 2040 | 50%+ | Industry consensus |
These are estimates for breaking RSA-2048 and ECDSA. The actual timeline is highly uncertain.
The Real Concern: Harvest Now, Decrypt Later
Even if quantum computers are years away:
- Attackers record blockchain data today
- When quantum computers arrive, they decrypt historical signatures
- Public keys are revealed when transactions are broadcast
- Funds can be stolen from addresses with exposed public keys
This means the threat is already real for long-term security.
What's at Risk in Bitcoin/Cryptocurrencies?
Exposed Public Keys
When you spend from a Bitcoin address, your public key is revealed:
Before spending: Only address (hash of public key) is known
After spending: Full public key is on the blockchainAt risk: Any address that has ever sent a transaction (~30% of all Bitcoin)
Reused Addresses
Address reuse compounds the problem:
- Public key known from first spend
- Additional funds sent to same address are vulnerable
Lost Coins with Known Public Keys
Early Bitcoin transactions used pay-to-public-key (P2PK):
- Public key directly in the transaction
- Includes Satoshi's ~1 million BTC
How BTQ Solves This
Dilithium: Post-Quantum Signatures
BTQ replaces ECDSA with Dilithium, a lattice-based signature scheme:
| Property | ECDSA | Dilithium |
|---|---|---|
| Security basis | Elliptic curves | Lattices |
| Vulnerable to Shor? | Yes | No |
| NIST standardized | Yes | Yes (FIPS 204) |
| Quantum security | 0 bits | 128 bits |
Why Lattice Cryptography?
Lattice problems are believed hard for quantum computers:
- No known quantum algorithm provides exponential speedup
- Studied for decades with no efficient attacks found
- NIST selected Dilithium after 7 years of evaluation
Migration Path
BTQ provides a path to quantum safety:
- Generate Dilithium address:
btq-cli getnewdilithiumaddress - Move funds: Transfer from ECDSA to Dilithium addresses
- Future-proof: Quantum computers cannot steal from Dilithium addresses
The NIST Post-Quantum Standardization
Timeline
- 2016: NIST begins post-quantum cryptography competition
- 2017: 69 submissions received
- 2019: 26 advance to second round
- 2020: 7 finalists selected
- 2022: 4 algorithms selected for standardization
- 2024: FIPS 203, 204, 205 published
Selected Algorithms
| Algorithm | Type | Use Case | BTQ? |
|---|---|---|---|
| Dilithium | Signatures | Transaction signing | Yes |
| Falcon | Signatures | Alternative signatures | Future |
| SPHINCS+ | Signatures | Stateless signatures | Future |
| Kyber | Key exchange | Not applicable | No |
BTQ chose Dilithium because:
- Primary NIST recommendation
- Simpler implementation than Falcon
- Better side-channel resistance
- Reasonable signature sizes
Comparison of Risks
Bitcoin Today
Security: ECDSA (256-bit)
Quantum: Completely broken by Shor's algorithm
Risk: Total loss of funds when quantum computers arriveBTQ
Security: Dilithium2 (128-bit quantum)
Quantum: No known quantum attack
Risk: Protected against foreseeable quantum threatsWhat About Mining?
SHA-256 and Grover's Algorithm
BTQ uses SHA-256 for Proof of Work, same as Bitcoin.
Grover's algorithm could provide advantage:
- Current: 256-bit security
- Post-quantum: ~128-bit security (still very secure)
Why This Is Less Concerning
- Still extremely difficult: 128-bit security is plenty
- Hardware limitations: Quantum mining hardware doesn't exist
- Economic factors: Cost of quantum computers vs. mining rewards
- Upgradeable: Hash function can be changed if needed
The signature vulnerability is far more urgent than the mining vulnerability. Signatures protect your money directly; mining is about network security.
Frequently Asked Questions
"Quantum computers are decades away, why worry now?"
- Harvest now, decrypt later: Data recorded today can be decrypted later
- Migration takes time: Moving entire ecosystems is slow
- Better safe than sorry: Cryptographic agility is valuable
"Can't Bitcoin just upgrade?"
Yes, but it's complicated:
- Consensus required: Hard fork needs community agreement
- Address migration: Users must move funds manually
- Lost coins: Funds in lost wallets remain vulnerable
BTQ demonstrates this upgrade is possible.
"What if Dilithium is broken?"
- Unlikely: Based on 30+ years of lattice research
- NIST vetted: 7-year standardization process
- Upgradeable: BTQ can adopt new algorithms if needed
- Defense in depth: Hybrid signatures possible
"Is my Bitcoin safe?"
For now, probably:
- Quantum computers can't break ECDSA yet
- You have time to migrate
- Watch for quantum computing advances
Recommendation: Don't panic, but plan for migration.
Summary
| Threat | Classical Computers | Quantum Computers |
|---|---|---|
| ECDSA signatures | Secure | Broken (Shor) |
| SHA-256 hashing | Secure | Weakened (Grover) |
| Dilithium | Secure | Secure |
BTQ provides protection against the quantum threat by:
- Using NIST-standardized post-quantum cryptography
- Maintaining Bitcoin's proven PoW security model
- Offering backward compatibility for migration
Learn More
- Dilithium Overview - Our quantum-resistant signature scheme
- Dilithium Cryptography - Technical deep-dive
- NIST Post-Quantum Cryptography
- Shor's Algorithm (Wikipedia)