‹ CHAPTER 17, ALL LESSONS

MASTER · CHAPTER 17 · LESSON 4 OF 5

Attacks & assumptions

Quantum computers

Could a quantum computer break Bitcoin? 6 min

A large enough quantum computer running Shor's algorithm could, in principle, compute a private key from its public key. That would break the signatures Bitcoin uses today, ECDSA and Schnorr.

Which coins are exposed

  • Outputs that show the public key directly, as the earliest pay to public key outputs do, including many coins mined in 2009 and 2010.
  • Addresses that were reused after spending, since spending reveals the public key.
  • Taproot outputs, whose locking script contains a public key.
  • Coins whose public key has never been revealed are protected by a hash until they are spent.

Mining is less affected

For SHA-256, the known quantum speed up, Grover's algorithm, at best reduces the work to about its square root, and the difficulty adjustment absorbs faster miners anyway. Signatures are the real concern.

Where things stand

No quantum computer today is anywhere near the size needed. Researchers and developers are discussing post quantum signature schemes and migration plans, including what to do with old coins whose owners may never move them. A change would require a soft fork and years of preparation.

What to remember

  • Shor's algorithm threatens ECDSA and Schnorr keys.
  • Coins with exposed public keys are most at risk.
  • Post quantum migration is being discussed, not deployed.

Quick check

What would a powerful quantum computer threaten most in Bitcoin?

Why are coins at a never used, hash based address less exposed?