Rethinking the Quantum Menace: Bitcoin's Security Is More Fragile Than Assumed

A comforting narrative has gained traction: thanks to Bitcoin's Pay-to-Public-Key-Hash (P2PKH) design, roughly 70% of bitcoin is considered "safe" from future quantum computing attacks because its public keys have never been exposed on-chain. Charles Guillemet, CTO of hardware wallet firm Ledger, challenges this optimism, arguing it's based on flawed assumptions that dangerously underestimate the real threat landscape.

The On-Chain View Is Misleading: Public Key "Exposure" Is Everywhere

The "30% at risk" theory leans heavily on Glassnode data showing that about 30.2% of bitcoin has its spending public key visible on the blockchain—a clear quantum target.

Guillemet counters that this data presents a static and incomplete picture. The critical nuance is that "not publicly on the blockchain" is far from "never recorded or handled by any system." A Bitcoin address's public key can be generated, used, or stored in numerous scenarios:

  • Extended Public Keys (xpub): The master key for generating address hierarchies, commonly present in wallet software.
  • Signing Devices: Hardware or hot wallets interact with public keys, temporarily or permanently, when creating transaction signatures.
  • Partially Signed Bitcoin Transactions (PSBTs): In multi-signature or cross-device signing workflows, public key information is shared among participants.
  • System Logs & Backups: Applications, operating systems, or cloud backups may inadvertently log public key data.

Most crucially, the moment a user initiates a Bitcoin transaction, the corresponding public key must be broadcast to the network for signing and verification before the transaction is confirmed. This means even a long-dormant address exposes its public key during the brief window when its funds are being spent—a window that could be an eternity for a future quantum attacker.

The Quantum Countdown: Not Science Fiction

Guillemet cites research from Google's Quantum AI team to underscore the urgency. Simulations suggest that a powerful, fault-tolerant quantum computer (which does not yet exist) could theoretically break the elliptic-curve cryptography (secp256k1) used by Bitcoin in approximately 9 minutes.

This figure starkly illustrates the devastating efficiency with which practical quantum computers could crack current encryption. Relying on the static "hiding" of public keys would then be as futile as hiding treasure on a map you believe is secret, but is actually covered in surveillance cameras.

The Only Path Forward: Upgrade, Don't Just Hide

Therefore, Guillemet's central argument is that attempting to evade quantum risk by hiding public keys is a superficial and fragile approach. The long-term security of Bitcoin and the broader crypto ecosystem cannot depend on attackers "not finding" keys, but must be built on the cryptographic foundation of them "not being able to compute" keys.

The definitive solution is singular: a proactive migration to post-quantum cryptography. This requires a concerted global effort among cryptographers, Bitcoin core developers, and the community to research, develop, and deploy new encryption algorithms resistant to quantum attacks, culminating in a consensus-driven system upgrade. The race against time is already underway.