https://en.wikipedia.org/wiki/Elliptic-curve_cryptography#Qu...
Not just Bitcoin, and not just all other popular cryptocurrencies, but all your web traffic and more are all susceptible to quantum attack.
Indicates the best known quantum speedup square roots the search space, and the search space in SHA256 is still too big to search exhaustively.
The thing with applied cryptography is that everyone is expecting the attacks to get better over time, sometimes in big and inconvenient bursts. There are several strategies to mitigate this, including oversizing security margins by a certain amount (so that an innovation that improves an attack by an order of magnitude or two isn't an instantaneous shattering of your whole security model), and having what's sometimes termed "algorithm agility" (which has somewhat fallen out of favor recently due to having its own class of bugs due to the implementations around, say, an optional NONE pluggable cipher type).
It's an awesome python library to create math animations, I would highly recommend it.
But it likely won't happen at all. Lots of work is being done on quantum proof cryptography[1]. IT systems and crypto can be upgraded to use it.
The real problem is going to be all the stashed encrypted data that US and China have stored on each other of a sensitive nature. The encryption on this information could be cracked by a quantum computer.
While there's no doubt they've stored lots of encrypted messages sent by each other, would it really be such a huge catastrophe if those messages were decrypted years after they were sent? Presumably neither side is sending the most sensitive information that has long-term value (like weapons designs) across a channel the other can read, encrypted or not. And the US and Chinese governments losing control of some of their secrets wouldn't necessarily be a net negative for the world anyway. Snowden "decrypted" some of the US's secrets and we are better off for it.
The bigger threat isn't both sides decrypting each other's stored messages, it's one side breaking the other's encryption without them knowing, like what happened with the Enigma in WWII.
https://youtu.be/I3BJVaioX_k at around the 10:30 mark should make the point.
There would probably be some competing chains as different communities tried to be "the one". Things might settle down at some point as it's really a "winner takes all" market.
That said, it would be such a feat of mathematics (if even possible) that it's highly unlikely a bad actor would be the first one to discover it.
The first thing to target would be the network operators, so that you have the technical ability to observe and inject packets into connections from leaf nodes. Then, you could redirect those connections to yourself, proxy their TLS undetected, or serve replies that contain (valid signature) updates or malware.
This is one of the many reasons that a defense in depth strategy (that is, not solely/blindly trusting TLS or digital signatures to ensure that your computer doesn't run unauthorized code) is a good idea.
It is also probably another reason why so many state-level intel agencies target telecoms first and foremost.
There are tens of billions of dollars worth of abandoned Bitcoins in addresses with exposed public keys. It would be trivial to get those if you can break ECDSA. Yes, there is much more outside of Bitcoin but I don't see why someone who had this capability wouldn't go after the easy targets first.
I was referring to if it was possible to break encryption using classical computers in polynomial time -- that would be a feat of mathematics, if it were even possible, and would likely have implications about P vs. NP.
Every bank account and every website will be able to be able to be hacked.