Home Crypto Bitcoin quantum threat: Which wallets face the most risk?

Bitcoin quantum threat: Which wallets face the most risk?

0
3

Fireblocks’ head of research has warned that exposed public keys are one of the biggest factors in Bitcoin’s potential quantum computing risk. Public estimates suggest that around 6.7 million to 7 million BTC may be held in addresses where public keys are already visible on the blockchain.

Michael Gutkin, Fireblocks’ vice president of research, told crypto.news that the level of risk depends on the blockchain, wallet type and transaction history. It does not matter whether the holder is an individual, exchange or large institution.

“Exposure ultimately comes down to whether the public key is already visible onchain,” Gutkin said.

He explained that older Bitcoin outputs and reused addresses can leave funds exposed for long periods. Institutions that move their Bitcoin less frequently may avoid revealing their keys for longer, but this depends on the address type and whether the key has already been exposed.

The concern relates to future quantum computers that could potentially break the cryptographic signatures used to protect digital assets. However, no quantum computer capable of breaking Bitcoin’s current signatures is known to exist today.

Older Bitcoin addresses face greater exposure

Some of Bitcoin’s earliest outputs use a format called pay-to-public-key, or P2PK. These outputs reveal their public keys from the beginning, meaning the keys remain exposed even if the coins have never been moved.

Other formats, including pay-to-public-key-hash (P2PKH) and native SegWit (P2WPKH), generally keep the public key hidden until the first transaction spends funds from the address.

Once a transaction reveals the key, however, it remains visible on the blockchain. If more Bitcoin is later sent to the same address, those new funds are also associated with an already-exposed key.

Taproot addresses have a different limitation. Their output public keys are visible when the outputs are created, making them potentially vulnerable to long-term quantum attacks if sufficiently powerful technology becomes available.

Bitcoin’s BIP 360 proposal aims to address part of this problem by introducing a new output type that removes Taproot’s exposed key-spending path. However, it does not provide complete protection against every type of quantum attack.

crossorigin="anonymous">

Ledger Chief Technology Officer Charles Guillemet previously warned that preparing Bitcoin for quantum threats could take years because changes would involve research, software development, hardware wallets and user adoption.

Fireblocks recommends gradual wallet changes

Gutkin believes institutions should manage public-key exposure continuously rather than wait for a quantum threat to become urgent and then move all their funds at once.

“For an institution, I don’t think the goal should be a one-time mass migration,” he said.

His recommendations include sending new Bitcoin deposits to fresh addresses and directing transaction change to new addresses instead of reusing exposed ones.

Institutions should also track individual unspent transaction outputs, known as UTXOs, to identify which funds are already linked to exposed public keys.

Over time, normal spending can reduce balances held at exposed addresses while new deposits go to addresses whose public keys have not yet been revealed.

Gutkin said Fireblocks is developing tools to help institutions monitor exposed balances and select transaction inputs based on their exposure.

Other custody providers are taking similar steps. BitGo has introduced controls for assessing key exposure, updating address practices, selecting transaction inputs and moving funds away from potentially vulnerable addresses.

However, a large-scale migration could create problems if many holders try to move their Bitcoin simultaneously. Limited transaction capacity could push fees higher and delay confirmations.

Gutkin also warned that rushed transfers could increase operational mistakes, including sending change back to an exposed address. He recommended preparing destination addresses, approval procedures and trusted communication channels in advance.

Bitcoin still needs quantum-resistant transaction security

Better wallet practices can reduce exposure, but they cannot replace a long-term upgrade to Bitcoin’s transaction-signing system.

BIP 360 proposes pay-to-Merkle-root outputs to reduce exposure associated with Taproot. Its authors note that additional post-quantum signature protection may still be needed to defend against attacks launched after a transaction reveals a public key but before the transaction is confirmed.

The proposal remains a draft.

Gutkin also highlighted research into hash-based signature systems, which can offer post-quantum security but bring trade-offs involving signature size, wallet design and the management of signing records.

Bitcoin faces additional challenges because it does not offer the same general-purpose application layer available on Ethereum. Depending on the chosen approach, supporting a new signature system could require changes to Bitcoin’s protocol while keeping transaction fees manageable.

For investors holding Bitcoin through exchange-traded funds, custody arrangements are another consideration. These investors generally do not control the private keys securing the funds’ Bitcoin holdings. Instead, the issuers rely on custodians to manage those assets.

Coinbase has also discussed developing custody infrastructure that can support different post-quantum signature schemes, including research into hardware security modules that could work with new signing systems.

Ethereum research reduces post-quantum verification costs

Ethereum faces a different challenge because standard accounts reveal their public keys when they sign transactions. Replacing an Ethereum account is also less straightforward because balances, token approvals and decentralized application activity are tied to that account.

Solana’s standard wallet addresses present another difference: the address itself is the public key, meaning the key is visible without the user first making a transaction.

On Ethereum, programmable accounts offer a possible way to introduce new transaction authorization methods without replacing the account itself.

Fireblocks says its research team has reduced the gas cost of verifying ML-DSA-44, a post-quantum signature scheme, from 8.09 million gas to 1.23 million gas.

In a Sept. 2 research post, the company said its verifier follows FIPS 204, the digital-signature standard published by the U.S. National Institute of Standards and Technology. The team improved the implementation without changing the standardized algorithm.

The work included improvements to hashing, mathematical operations, signature decoding, public-key handling and memory use. Peak memory consumption fell from nearly one megabyte to around 41 kilobytes.

The system still has significant costs. Deploying the expanded public key requires roughly 4.1 million gas, while each signature verification requires another 1.23 million gas.

Gutkin said these costs may be manageable for institutions and cold wallets that make relatively few transactions. However, ordinary Ethereum accounts cannot simply switch to ML-DSA without additional engineering, and smart-account integration, custody support and compatibility with decentralized applications remain challenges.

He also stressed that a post-quantum signature verifier alone would not make the entire Ethereum network quantum-resistant. Its consensus and data layers require separate research.

Despite extensive testing and formal verification, Fireblocks’ implementation remains research code that needs further audits and security hardening before production use. The company is also researching production-grade post-quantum signing systems for institutional custody.

Overall, Fireblocks’ message is that crypto holders can begin reducing their exposure now through better wallet practices, even though a quantum computer capable of breaking current blockchain signatures has not been demonstrated. Long-term protection will still depend on developing and adopting new cryptographic systems.