Bitcoin

Quantum Isn’t Coming For Your Bitcoin


For as long as Bitcoin has existed, new forms of FUD (fear, uncertainty, and doubt) have been used to predict its demise. Despite this, Bitcoin has grown into a multi-trillion dollar asset and begun to take its place in the global monetary order. In recent months, the specter of a cryptographically relevant quantum computer (CRQC) enabling an attacker to recreate secret keys from public keys and sign Bitcoin transactions moving other people’s coins has returned as an evolved form of FUD. Is this a realistic threat to Bitcoin’s continued growth? In a word, no. There is no evidence that a CRQC will be built within a decade, and it remains unknown whether such a machine will ever be built. The quantum threat remains FUD.

State of the Art

To date, no quantum computing machine has computed anything out of reach of a precocious 6-year-old (confirmed empirically). Quantum computers are remarkable technology and showcase the truly science fiction worthy capabilities of the modern world. These devices harness foundational technologies such as optical tweezers, laser cooling, superconducting flux qubits, electromagnetic traps, dilution refrigerators, and many more. Within these devices individual qubits are coerced into specific subatomic states (different for each candidate technology), entangled into superpositions, manipulated to represent computations, and then their subatomic properties are read and interpreted. The astounding truth is that these devices exist, and can be manipulated to produce meaningful computations across a handful of inputs. The cold reality check is that (for an example candidate tech.) to do a computation that a small child can do requires enough power to air condition a Texas high school, many hours of setup, and further hours of post-processing.

Reading the Future

I know what you’re thinking, “but there’s so much money flowing into quantum computing”. Does money flowing into a field correlate with the rate of real-world technological progress in that field? Not really. In fact, it can be argued that until the correct underlying technology has been developed and the product-market fit confirmed, money flowing into an area has a negative correlation with the likelihood of applicable technology being developed. This can be clearly seen by comparing NASA’s Space Shuttle program to SpaceX’s Falcon 9. SpaceX took (mostly) known science and reduced it to practice to satisfy a demonstrable market need for reliable and lower cost access to space, at a program cost of less than $5 billion to first crewed mission. The Space Shuttle cost roughly $50 billion to reach its first crewed mission. Not only did Falcon 9 cost an order of magnitude less to develop, but it has a perfect crew safety record to date. There are many reasons for these differences, but it goes to show that no amount of money makes a technology that is not ready practicable. Translating this to quantum computing: we can see that with tons of money being thrown at the problem, technology demonstrations at massive cost are possible. But this tells us nothing about whether more money will bring us the holy grail of stable, low-error qubits (like the reliability of the Falcon 9). No amount of continued development on the Space Shuttle program would ever have produced the low cost, high reliability of Falcon 9, and it’s entirely probable that no amount of continued development, at any cost, will ever make any of the current quantum computing technologies reliable enough to break a single key pair.

Now, you might be thinking, “but what about all the recent advancements?” There are two important things to keep in mind about recently published advancements. First, many of these advancements have been advancements in pure mathematics only. For example, the recent Google paper which had such an important result that they chose to redact the theoretical quantum circuit rather than risk it being used to break important cryptographic systems. This may seem like massive progress toward the future of CRQCs, but in fact it changed nothing. Unless (or until) the quantum hardware has its Falcon 9 moment, there simply is no device which comes anywhere near the stability and scale needed to run the redacted circuit. It’s pure theater to hide a circuit designed for a device which may never exist. Second, on the hardware side itself, we see many new results and bits of progress published in a given year, but how many of these relate to the same quantum computing candidate technology? How many represent merely a starting over after a prior result ended in a dead end? The reality is that these advancements do not represent some linear track toward eventual success. They represent the breadth-first search of an infinite possibility space within which quantum researchers are hoping to find a path along which they can proceed for even a modest distance without reaching yet another dead end.

When we look at the reality of the future of quantum computing, it’s hazy at best. There are promising technological developments. Especially, to my eye, in the area of neutral atom devices. But it’s far too early to tell if there’s a path open toward an eventual CRQC along any of the currently known branches or if more restarts are in our future. If, at some point, we see many iterations of the same candidate technology implementing progressively more capable devices, and computing meaningful results that a precocious child cannot also compute, we can revisit this discussion with different evidence.

In Theory

There are two possible explanations for the repeated failure of quantum research to develop a CRQC over many decades. It’s possible that it’s just a hard problem and we’re continuing to apply science and engineering to solve it and one day the ingenuity of the human species will prevail as it has in the development of the Internet, the smart phone, social media, and Bitcoin (left to the reader to decide which of these are positive developments). On the flip side, it may be that developing a CRQC is either impossible or will remain forever outside our grasp. Consider what it would mean for a CRQC to exist: the machine would have to represent within its superposition a field of possibilities the same size as the complexity of the cryptographic problem to be solved. I.e. to break the 128-bit security of the elliptic curve discrete log on Bitcoin’s secp256k1 curve, the quantum superposition would have to represent all possible values of a 128-bit number. In classical computing, representing all such values would require more computer storage (by many orders of magnitude) than humans have ever produced. If there is even the slightest granularity to the quantum superposition (i.e. the quantum superposition is not perfectly continuous across all possible values) then the quantum computer cannot ever become cryptographically relevant. If the energy required to hold a superposition scales with the complexity of the field being represented then a quantum computer cannot ever be cryptographically relevant. The contemporary understanding of quantum physics does not rule out either of these possibilities.

Conclusion: Bitcoin Cannot Rest

Despite all of the preceding, Bitcoin development toward new cryptographic algorithms must continue. While a quantum attack on Bitcoin’s cryptography is not imminent by any means, it’s entirely possible that another flaw could be found through other means. We know that certain elliptic curves have been found to have weaknesses, and secp256k1 could be next. Bitcoin has survived as long as it has because attacks on the system have strengthened it and that will continue to be true as the quantum FUD attack plays out. The development of P2MR or P2TRv2, of SHRINCS, SPHINCS, IBC, ML-DSA, and more post-quantum signature schemes will eventually lead to improvements to Bitcoin’s resilience in the face of future attacks even if an actual CRQC is never developed.

This piece is featured in the latest Print edition of Bitcoin Magazine, The Quantum Issue. We’re sharing it here as an early look at the ideas explored throughout the full issue.



Source link

What's your reaction?

Excited
0
Happy
0
In Love
0
Not Sure
0
Silly
0

You may also like

More in:Bitcoin

Leave a reply

Your email address will not be published. Required fields are marked *