The Bitcoin industry is fixated on the wrong half of the quantum problem, according to Andrew Gault, a venture capitalist and CEO of networking firm ZeroTier. Instead of focusing on wallet keys, Gault argues that the industry should be more concerned about the encrypted messages already in transit between exchanges, bridges, and custodians. This shift in perspective is supported by Google's security team, which has also moved in the same direction, setting a 2029 target for completing a post-quantum cryptography migration.
Gault's concern is rooted in the idea that the financial system's most dangerous vulnerability lies in the data moving between institutions, not in stored data. He notes that sophisticated adversaries are already collecting encrypted traffic, and they are building a library of this data to decrypt it once quantum capability becomes available. This strategy, known as 'harvest now, decrypt later', is a significant threat to the security of financial institutions.
The potential impact of quantum computing on Bitcoin is often discussed in terms of wallet keys, but Gault argues that the real risk lies in the authentication records being harvested. These records determine ownership, transaction authorization, and legal liability, making them a critical target for adversaries. While Ethereum has launched a coordinated post-quantum migration, Bitcoin has not, and major crypto exchanges and custodians have not publicly committed to one either.
The urgency of the situation is further emphasized by the potential economic impact of a quantum-enabled attack on the U.S. banking system. Citi estimated that such an attack could trigger a $2 trillion to $3.3 trillion cascade across the U.S. economy, equal to a 10% to 17% decline in real GDP. The probability of a cryptographically relevant quantum computer arriving by 2034 is estimated to be between 19% and 34%, according to the Global Risk Institute.
In conclusion, Gault's perspective highlights the need for the Bitcoin industry to re-evaluate its priorities and address the vulnerabilities in the data in transit between institutions. The industry must move beyond the wallet key focus and tackle the more pressing issue of encrypted message security to ensure the long-term viability of Bitcoin in a quantum-threatened world.