The threat of quantum computing approaches, and cryptocurrencies may expose risks before banks do.

CN
2 hours ago
Experts Warn: The True Weakness of Bitcoin is Not the Cryptographic Algorithm, but the Slow Governance Consensus.

Written by: Omkar Godbol

Translated by: AididiaoJP, Foresight News

Quantum computing poses a potential risk to all systems that rely on cryptographic technology globally, from major banks to government networks, without exception. However, due to the decentralized nature of cryptocurrencies and the design of public ledgers, it is likely to be the first technology to be truly "tested."

"Cryptocurrency is like the canary in the coal mine." Quantum Xchange CEO Eddy Zervigon stated in an interview with CoinDesk. The company focuses on building cybersecurity infrastructure resistant to quantum attacks, covering fields such as finance. He pointed out that the cryptocurrency network is likely to experience issues first.

"Because it is decentralized, it will be the first place to be attacked," Zervigon said. "Once you see this happening there, it indicates that a quantum computer with cryptographic capabilities has appeared somewhere."

The so-called "quantum computer with cryptographic capabilities" refers to a machine that can effectively run Shor's algorithm to crack the elliptic curve cryptography (ECDSA over secp256k1) that cryptocurrencies like Bitcoin rely on. This algorithm can efficiently solve the elliptic curve discrete logarithm problem, allowing the reverse derivation of a private key from a public key, thus controlling the assets in the corresponding wallet. Currently, such machines do not exist. However, industry estimates of when they might appear are consistently being compressed rather than pushed back.

"Companies like Microsoft, IBM, and others that have invested billions in developing quantum computers generally believe that quantum computers with commercial and cryptographic capabilities will appear around 2029," Zervigon said. "This is not something I made up, but based on public statements from people like IBM's Arvind Krishna."

This timeline estimate aligns closely with recent advancements in hardware and algorithms. Earlier this year, research from Google's Quantum AI team showed that the number of physical qubits required to break the elliptic curve cryptography protecting mainstream cryptocurrencies such as Bitcoin and Ethereum has dropped to less than 500,000, approximately 20 times lower than the previous common estimates of millions. The research also noted that under the premise of precomputing certain fixed parameters, executing an attack on an exposed public key might only take about 9 minutes. Considering the average block time of Bitcoin is around 10 minutes, this implies that attackers have a certain chance of forging signatures and transferring funds prior to transaction confirmations. These findings have led multiple observers, including Google, to advance their estimates of the so-called "Q Day" (the point at which cryptographic quantum computers become practically usable) to around 2029.

Meanwhile, the White House is striving to develop powerful quantum computers by 2028 and plans to migrate high-value assets and federal data to post-quantum cryptographic standards before 2030. "This sets a timeline and creates urgency," Zervigon said.

The Speed of Consensus is the Real Risk Factor

It is not only Zervigon who points out that the core weakness of cryptocurrencies lies in the slow governance process, rather than the cryptography itself.

Deutsche Digital Assets explicitly described this issue as the speed difference between traditional finance and decentralized systems.

The agency wrote in an analysis on July 23: "The real difference—also an honest answer to the narrative that 'Bitcoin is particularly fragile'—lies in governance speed."

It explained that investment banks like JPMorgan do not need to obtain the consent of millions of anonymous global participants before upgrading their cryptographic infrastructure. "They only need a board resolution, a budget, and vendors. Large financial institutions can and will transition to post-quantum standards in a faster, quieter, and more predictable manner, far surpassing a decentralized public blockchain. This is not against Bitcoin; rather, it's a call to take its governance process seriously."

Academic research further corroborates this assessment. A paper published in 2024 on arXiv titled "Downtime Required for Bitcoin to Achieve Quantum Security" pointed out that the historical upgrade process of Bitcoin itself serves as a cautionary precedent.

The researchers wrote: "Before any upgrade process is initiated, a 90% consensus on the specific details of the upgrade must be reached among Bitcoin miners. Historically, significant changes to the Bitcoin network have faced high resistance. A notable example is the SegWit upgrade in 2017."

This upgrade caused severe divisions within the community, ultimately leading to the Bitcoin blockchain splitting into multiple versions through hard forks, giving rise to Bitcoin Cash and Bitcoin Gold networks. The paper also estimated that even under optimal conditions (with the network's full bandwidth devoted to the upgrade and zero additional overhead), the minimum cumulative processing time required to migrate all currently vulnerable transaction outputs (UTXO) to post-quantum secure addresses is about 76 days. If extended over a longer time, it could significantly slow down normal transaction speeds. More critically, due to the risk of "instant attacks," once users initiate transactions that expose public keys, attackers might complete the crack before new blocks are formed; thus, the entire migration must be completed before a quantum computer with cryptographic capabilities appears. Otherwise, existing assets may still be exposed.

Therefore, the post-quantum cryptographic algorithms themselves (such as ML-DSA standardized by NIST) may be timely ready, but the real uncertainty lies in whether Bitcoin's governance layer can achieve a sufficiently high consensus in a short enough time to complete deployment across the network.

"Q Day" is Not a Point in Time, but a Trend

The market often models quantum threats as a binary event: cryptographic algorithms are effective until a specific date, after which they suddenly fail completely. Zervigon believes this framework is flawed as it underestimates how early the risks actually begin to manifest.

This compresses the usual time calculations. A quantum computer does not need to have sufficient throughput to crack signatures in real-time to pose a threat; it only needs enough throughput to complete the crack before the underlying data or funds lose theft value. In reality, a significant proportion of Bitcoin (research estimates about one-third, corresponding to millions) has its public keys permanently exposed on the blockchain. Once quantum computers become available, these assets may face "static attacks"—attackers can slowly calculate without racing against block times.

For the entire cryptocurrency industry, this serves as both a warning and a stress test. Traditional financial institutions can quickly migrate due to centralized decision-making, while the decentralized advantages of public blockchains like Bitcoin may turn into obstacles when facing externally coordinated technological threats. The industry commonly believes that the technical solutions are already in place, and the real test is whether governance can keep up with the time window.

Cryptocurrencies may well be among the first fields to sound the alarm in the quantum era. Once the canary falls, broader financial infrastructure will have to confront the same challenges.

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink