Exchanges Can Cut Bitcoin Quantum Exposure Before Protocol Fix

Coinbase hosted a Sept. 9 workshop; Glassnode data show exchanges control about 1.6 million BTC with public keys visible on-chain that custodians can reduce by moving funds and improving address hygiene.

Coinbase hosted a closed-door post-quantum Bitcoin workshop on Sept. 9 with Stanford and Localhost Research that brought together developers, cryptographers, institutional custodians and hardware-wallet experts. Workshop participants did not reach agreement on a single post-quantum approach and discussed tradeoffs involving transaction size, hardware performance, key management and adoption.

On-chain analysis from Glassnode shows exchanges control roughly 1.6 million BTC whose public keys are already visible on the blockchain. Glassnode’s May report estimated 6.04 million BTC, or about 30.2% of issued supply, had public-key exposure at rest. That total was split into about 1.92 million BTC structurally exposed by output type and about 4.12 million BTC exposed through operational behaviors such as address reuse and leftover balances after spends. Exchange-related outputs made up roughly 1.6 million BTC of the operationally exposed group, equal to about 8% of supply and about 40% of the operational exposure under Glassnode’s labeling.

Visible public keys do not allow immediate theft with current computers. Bitcoin’s cryptography relies on private keys that conventional machines cannot feasibly derive from public keys today. A future quantum computer running Shor’s algorithm could, in principle, derive private keys from public keys. Analysts describe two windows of risk: long-exposure attacks that target outputs already revealing a public key at rest, and short-exposure attacks that target keys revealed by a transaction while it sits in the mempool awaiting confirmation.

One technical proposal under review is BIP-360, a draft Bitcoin Improvement Proposal that would add Pay-to-Merkle-Root (P2MR) as a SegWit output. P2MR would preserve Taproot-style script-tree functionality while removing Taproot’s key-path spend, allowing outputs to avoid publishing a public key by default and reducing the long-exposure attack surface. The draft does not select a post-quantum signature algorithm and would not close the short-exposure window, because spending typically reveals a public key during confirmation. If adopted, P2MR would create an optional destination; exchanges and wallets would still need to move funds and add support.

Operational changes remain substantial. Exchanges, custodians, hardware-wallet manufacturers and key-management platforms must adapt processes for deposits, withdrawals, approvals, backups and recoveries without interrupting customer access. Glassnode noted custodians can act on active balances in ways dormant holders cannot and that improving address hygiene, rotating change outputs and moving funds to safer output types could reduce the pool of exposed coins before any protocol-level cryptographic decision.

Recent device and custody tests have examined parts of the transition. Blockstream Research published benchmarks on Aug. 19 showing several tested hardware wallets could generate certain hash-based post-quantum signatures in laboratory conditions; the study excluded post-quantum firmware verification and some signature families. In May, a regulated custodian and a multi-party-computation security firm reported a simulated post-quantum transaction using ML-DSA inside an MPC wallet workflow that covered distributed key control and policy enforcement but stopped short of a production deployment.

Coinbase characterized the quantum risk as non-immediate and urged practical testing. Workshop participants described readiness as two parallel tracks: selecting and standardizing a post-quantum signature family, and executing a coordinated operational rollout across devices, custody platforms and the network. Progress can be tracked through device benchmarks, custody simulations and mappings of exposed balances, while no timeline was set for a protocol change.

Articles by this author