A quantum computer would not be able to create new bitcoins. It could do something far worse: deduce the secret code of a wallet from information that is publicly available, and then transfer its contents. Developers are beginning to test the security measures designed to prevent this from happening.
On 26 August, an experimental transaction was recorded on the Bitcoin blockchain. It involved just 10,000 satoshis – one ten-thousandth of a bitcoin – but StarkWare describes it as the first transaction protected against a quantum attack to be carried out on the main network without altering its rules. The test required several hours of computation and cost between $150 and $200. Nor did the transaction follow the usual route. As its format was not accepted by standard software, it was submitted directly to Mara Pool, the company that recorded it in block 964,199.
This experiment does not make Bitcoin resistant to quantum computers. It shows that a holder could add protection to their tokens without having to wait for a complete overhaul of the network. However, given the cost and time involved, the process seems more like a stopgap solution than a means of payment suitable for everyday use.
From the public key to the private key
To understand how it works, we need to look at the lock that secures a wallet. The owner has a private key – similar to a secret code – which allows them to authorise a transaction. A public key, derived from this secret, enables the network to verify that the transaction really does come from them.
Conventional computers can perform this calculation in one direction, but cannot work backwards from the public key to the private key within a realistic timeframe. A sufficiently powerful quantum computer could break this protection. It would then be able to reconstruct the secret, sign a transaction in the owner’s place and send the bitcoins to another address.
The method devised by Avihu Levy, a researcher at StarkWare, adds a second lock based on a different branch of cryptography. In particular, it protects the brief period during which a payment is awaiting recording on the blockchain. During these few minutes, the holder’s public key becomes visible and could be exploited by a sufficiently fast quantum computer.
Another threat concerns public keys that have been exposed for several years. Some coins issued in the early days of Bitcoin were deposited in wallets where the public key appears directly on the blockchain. More recent addresses, particularly those using Taproot technology, also reveal it before any transactions take place. In other wallets, it remains hidden as long as the address has never been used or reused.
2.3 million bitcoins at risk
The bitcoins attributed to Satoshi Nakamoto are among the assets potentially at risk. The network’s anonymous creator has not moved them since its early years. If their private keys are no longer accessible to anyone, their owner cannot transfer them to a more secure wallet. An attacker equipped with a quantum computer could, however, attempt to recover them.
The extent of the risk depends on the definition used. An academic study published in June estimates that around 6 million bitcoins are linked to a private key that has already been compromised. Not all of them are doomed: their owners could move a large proportion of them before a malicious machine gains access. The researchers estimate that around 2.3 million bitcoins remain genuinely at risk, particularly because their owners have disappeared or lost access to them.
The timeline remains highly uncertain. The same study estimates the probability of a computer capable of breaching these defences emerging by 2035 at around one in six, nearly 30% by 2040 and around 60% by 2050. These results are based on a prospective model. They do not constitute a definite forecast or a deadline.
Google Quantum AI has, however, brought the theoretical threat closer to reality. In a research paper published in March, its specialists concluded that the computing power required to recover a private key would be lower than previously estimated. Depending on the chosen architecture, a future machine with fewer than 500,000 error-corrected quantum components could perform the calculation in a matter of minutes. No machine currently available comes close to this capability. The attack would primarily target wallets, not the creation of bitcoins. The system that organises mining would be better able to withstand the advantages offered by quantum computing. The most direct threat would therefore be the theft of tokens by forging their owners’ signatures, rather than the creation of counterfeit coins or the immediate rewriting of the entire blockchain.
Two further projects that have already been trialled
The security measure tested by StarkWare comes into play at the time of the transfer. Two other projects aim to bring about more fundamental changes to the way the network operates.
The first, known as BIP-360, would create a new category of addresses. Instead of immediately publishing the key used to authorise a transaction, these addresses would retain only an indecipherable hash of it. A hacker would no longer have several months or years to prepare their attack. The key would only be revealed at the moment the funds are spent. This solution would not be sufficient against a machine capable of breaking the protection in the few minutes leading up to the payment’s confirmation. It would, however, provide a safer destination to which holders could move their bitcoins before the threat becomes imminent. BIP-360 remains a proposal. Its publication does not imply that the Bitcoin community has approved it, nor that it will be implemented on the network.
The second project aims to replace the current signature. Presented by researchers affiliated with Blockstream, Shrincs is based on the hash functions already used by Bitcoin. It has been designed to be resistant to both conventional computers and future quantum computers. However, this protection takes up considerably more space. A Shrincs signature would be at least 548 bytes in size, plus a 48-byte public key, compared with 64 bytes for Bitcoin’s most recent signature. The larger the signatures, the fewer transactions a block can accommodate. This could slow down the network or make it more expensive.
Shrincs also requires the wallet to keep a record of certain keys that have already been used, in order to prevent them from being reused. Incorrectly restoring a backup or using the same wallet on multiple devices simultaneously could create a risk of loss. Finally, its developers acknowledge that a complete mathematical proof of its security has yet to be established. The project represents a concrete avenue of exploration, not a solution ready for deployment.
This issue directly affects professionals in Luxembourg. Since the CSSF provided further clarification in February, alternative investment funds have been able to invest directly in crypto-assets. UCITS funds may hold indirect exposure to them, subject to certain conditions and up to a limit of 10% of their net assets. Custodians may also act on behalf of funds that hold crypto-assets directly, provided they adapt their organisational arrangements to the specific risks associated with their safekeeping.
Offline storage protects against many of today’s cyber-attacks. It does not automatically make a key quantum-resistant. The iShares Bitcoin ETP offered in Luxembourg, for example, states that its bitcoins are held offline by Coinbase Luxembourg. The real challenge will be determining the type of addresses in which these assets are stored, whether their keys have already been compromised, and how quickly the custodian will be able to move them to post-quantum protection.



