Point Estimates Understate Quantum Theft Risk in Bitcoin: A Distributional Race Model for Commit–Delay–Reveal

Published assessments of Bitcoin’s exposure to a cryptographically relevant quantum computer convert resource estimates into risk figures by substituting a point estimate of the key derivation time into an exponential tail. We show that this procedure is systematically optimistic. Because the exponential tail is strictly convex, its expectation over any non-degenerate break time distribution exceeds its value at the mean, so every such figure is a provable lower bound on the true risk: at an unchanged nine-minute mean, exponential dispersion moves Bitcoin’s on-spend theft probability from 41% to 53%. We develop the distributional model this requires, a race between a Poisson block-arrival process and a random time-to-key embedded in a Nakamoto reorganization contest and a replace-by-fee contest, and obtain closed forms for the theft probability, for the commit–reveal delay attaining a given security target, and for the coin value an owner retains in the fee war. Replacing the zero-delay catch-up bound with a delay-aware one raises the required delay by a factor of 1.2 to 20.4, a correction driven almost entirely by the adversary’s pre-mining lead rather than by propagation delay. Reconciling our results with a concurrent round-based analysis shows that an apparent threefold disagreement in the literature is a difference in security target, not in substance. Finally, we test the block-arrival assumption against 40,320 block headers: the exponential marginal law holds, but a conditional uniformity test detects within-epoch rate drift invisible to a Kolmogorov–Smirnov test, an effect worth under a third of a percentage point and again conservative.

Authors

Institutions

Publication Details

Journal
Journal of Cybersecurity and Privacy
Published
2026-09-15
DOI
https://doi.org/10.3390/jcp6050162
Primary Topic
Blockchain Technology Applications and Security
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Point Estimates Understate Quantum Theft Risk in Bitcoin: A Distributional Race Model for Commit–Delay–Reveal

Thawatchai Chomsiri, Suwichai Phunsa
Journal of Cybersecurity and Privacy
Blockchain Technology Applications and Security
article

Point Estimates Understate Quantum Theft Risk in Bitcoin: A Distributional Race Model for Commit–Delay–Reveal

Thawatchai Chomsiri, Suwichai Phunsa
article en

Abstract

Published assessments of Bitcoin’s exposure to a cryptographically relevant quantum computer convert resource estimates into risk figures by substituting a point estimate of the key derivation time into an exponential tail. We show that this procedure is systematically optimistic. Because the exponential tail is strictly convex, its expectation over any non-degenerate break time distribution exceeds its value at the mean, so every such figure is a provable lower bound on the true risk: at an unchanged nine-minute mean, exponential dispersion moves Bitcoin’s on-spend theft probability from 41% to 53%. We develop the distributional model this requires, a race between a Poisson block-arrival process and a random time-to-key embedded in a Nakamoto reorganization contest and a replace-by-fee contest, and obtain closed forms for the theft probability, for the commit–reveal delay attaining a given security target, and for the coin value an owner retains in the fee war. Replacing the zero-delay catch-up bound with a delay-aware one raises the required delay by a factor of 1.2 to 20.4, a correction driven almost entirely by the adversary’s pre-mining lead rather than by propagation delay. Reconciling our results with a concurrent round-based analysis shows that an apparent threefold disagreement in the literature is a difference in security target, not in substance. Finally, we test the block-arrival assumption against 40,320 block headers: the exponential marginal law holds, but a conditional uniformity test detects within-epoch rate drift invisible to a Kolmogorov–Smirnov test, an effect worth under a third of a percentage point and again conservative.

Journal of Cybersecurity and PrivacyVol. 6(5)
Mahasarakham University (TH)
Openalex Percentile: Top 4%
Blockchain Technology Applications and Security
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.