Crypto Prices

Assessing Bitcoin’s Vulnerabilities: How Wallet Design Affects Quantum Risks

3 hours ago
2 mins read
4 views

Evaluating Bitcoin Vulnerabilities in the Quantum Computing Era

Michael Gutkin, the VP of Research at Fireblocks, recently evaluated the vulnerabilities associated with Bitcoin in the context of potential quantum computing threats. He identified publicly accessible keys as a significant risk factor, estimating that between 6.7 to 7 million Bitcoins are held behind keys that are currently exposed on the blockchain.

Risk Assessment Based on Transaction History

Gutkin elaborated that the degree of risk associated with a Bitcoin holder depends more on the type of transaction history and blockchain used than on whether the holder is a private individual or a larger institution like an exchange. He emphasized that the visibility of the public key is the primary criterion for assessing exposure.

“Frequent transactions can significantly increase the risk of exposure due to practices like address reuse.”

While a treasury that rarely transacts may keep its public keys hidden, this isn’t guaranteed, especially if the address format or past activity has already revealed them. He mentioned that early Bitcoin outputs, specifically those structured as pay-to-public-key (P2PK), have keys that are visible from inception, which is the case for many outputs from the Satoshi era that have never moved.

Address Formats and Their Implications

In contrast, newer formats such as pay-to-public-key-hash (P2PKH) and native SegWit (P2WPKH) addresses keep public keys concealed until the first spending transaction is made. Gutkin noted that, once an address has been used to spend Bitcoin, its key becomes permanently exposed, which poses a risk if that same address later receives more Bitcoin.

He further discussed the implications of Taproot, a recent Bitcoin upgrade, indicating that public keys are visible from the point of creation for Taproot outputs. This means theoretically, a sufficiently advanced quantum computer could exploit exposed public keys to derive private keys. However, he underscored that this remains a future concern, noting that as of September 17, no quantum computer exists that is capable of breaking Bitcoin’s current cryptographic defenses.

Strategies for Managing Public Key Exposure

Fireblocks’ Gutkin suggested that rather than a one-time mass migration, institutions should adopt a continuous management strategy concerning their public key exposure. He recommended that any new Bitcoin deposits be directed to new addresses to avoid exposing old ones and that the change from transactions also return to fresh addresses. Institutions should actively track their unspent transaction outputs (UTXOs) to understand which funds are already vulnerable.

As current practices evolve, custody service providers like BitGo have started implementing measures such as exposure scoring and transaction input selection to help manage risks tied to key exposure. These practices aim to minimize the likelihood of inadvertently leaving funds behind when revealing public keys through transaction activity.

Preparing for Urgent Transactions

Moreover, Gutkin advised institutions to prepare thoroughly before executing urgent transactions, highlighting the need for established protocols to minimize errors and phishing attempts. With heightened awareness about the risks of public-key exposure, he asserted that even improved address management would necessitate a shift toward quantum-resistant transaction authorization methods.

Proposed Solutions and Innovations

In direct response to the quantum threat, BIP 360 has been proposed, which includes a mechanism called pay-to-Merkle-root designed to mitigate the dangers of exposed keys. While this proposal does offer a pathway to reduce long-term exposure, it does not completely solve the quest for post-quantum security. Gutkin underscored that Bitcoin’s protocol may require alterations to accommodate new signature schemes, unlike Ethereum, which can utilize flexible contracts through a general application layer.

As for Ethereum wallets, Gutkin explained that typical accounts face their own risks since their public keys are exposed post-signature. Still, Fireblocks is exploring various innovations, including the ML-DSA-44 post-quantum signature scheme, which has made significant efficiency gains during testing so far. However, he reinforced that without comprehensive audits and the maturation of the technology, many of these advances remain in the research phase.

Conclusion

Ultimately, as the industry navigates the potential threat of quantum computing, both Bitcoin and Ethereum investors must remain vigilant about the security of their holdings, particularly in regards to key management and exposure strategies.

Popular