Point Estimates Understate Quantum Theft Risk in Bitcoin: A Distributional Race Model for Commit–Delay–Reveal
Published assessments of Bitcoin’s exposure to a cryptographically relevant quantum computer convert resource estimates into risk figures by substituting a point estimate of the key derivation time into an exponential tail. We show that this procedure is systematically optimistic. Because the exponential tail is strictly convex, its expectation over any non-degenerate break time distribution exceeds its value at the mean, so every such figure is a provable lower bound on the true risk: at an unchanged nine-minute mean, exponential dispersion moves Bitcoin’s on-spend theft probability from 41% to 53%. We develop the distributional model this requires, a race between a Poisson block-arrival process and a random time-to-key embedded in a Nakamoto reorganization contest and a replace-by-fee contest, and obtain closed forms for the theft probability, for the commit–reveal delay attaining a given security target, and for the coin value an owner retains in the fee war. Replacing the zero-delay catch-up bound with a delay-aware one raises the required delay by a factor of 1.2 to 20.4, a correction driven almost entirely by the adversary’s pre-mining lead rather than by propagation delay. Reconciling our results with a concurrent round-based analysis shows that an apparent threefold disagreement in the literature is a difference in security target, not in substance. Finally, we test the block-arrival assumption against 40,320 block headers: the exponential marginal law holds, but a conditional uniformity test detects within-epoch rate drift invisible to a Kolmogorov–Smirnov test, an effect worth under a third of a percentage point and again conservative.
Authors
- Thawatchai Chomsiri (ORCID: https://orcid.org/0000-0001-5998-9376)
- Suwichai Phunsa (ORCID: https://orcid.org/0000-0003-1093-6999)
Institutions
- Mahasarakham University (TH)
Publication Details
- Journal
- Journal of Cybersecurity and Privacy
- Published
- 2026-09-15
- DOI
- https://doi.org/10.3390/jcp6050162
- Primary Topic
- Blockchain Technology Applications and Security
- Type
- article
- Field-Weighted Citation Impact
- 0.00