For Bitcoin to become quantum-safe in the future, it will need to navigate through the existing frameworks that facilitate the transfer and storage of current coins. This involves exchanges, custodians for institutions, hardware wallets, and key management platforms all adopting new protocols while simultaneously handling deposits, withdrawals, approvals, backups, and recovery processes.

This operational hurdle gained prominence following a report from Coinbase detailing a post-quantum Bitcoin workshop held on September 9 in collaboration with Stanford and Localhost Research. Coinbase noted that this closed discussion brought together developers, cryptographers, institutional custodians, and hardware wallet specialists. No consensus was reached on a specific post-quantum solution, but participants acknowledged various trade-offs in transaction size, hardware efficiency, key management, and user acceptance.

A prior study by Glassnode highlighted this rollout challenge with quantifiable data. Their May report identified approximately 1.6 million $BTC in exchange-related outputs, with public keys already accessible on the blockchain.

However, having a visible public key does not mean it is immediately vulnerable to theft. Reports through September revealed that no quantum computer currently exists that could compromise Bitcoin’s signatures, and Coinbase described the risk as not being immediate. Instead, this measurement highlights coins that a sufficiently advanced future quantum computer could target without needing to wait for their owners to transact.

A cohort of 1.6 million $BTC under scrutiny

Bitcoin signatures serve to confirm that a spender possesses a corresponding private key. Standard computers are not capable of deriving the private key from its public equivalent. In theory, Shor’s algorithm executed on a powerful quantum computer could potentially invalidate this assumption.

This visibility of public keys introduces a division of risk into two temporal scenarios. A long-exposure attack would focus on keys that have been publicly visible on-chain for an extended period. In contrast, a short-exposure attack would capitalize on keys unmasked during transactions that have yet to be confirmed, offering a narrow opportunity for attackers.

According to Glassnode, an estimated 6.04 million $BTC, or approximately 30.2% of the total supply, had on-chain public key exposure as of May. The firm categorized 1.92 million $BTC as structurally exposed due to their output type inherently revealing a key or its equivalent. The remaining 4.12 million $BTC, accounting for 20.6%, stemmed from operational practices such as address reuse or leaving balances linked to exposed keys after transactions.

Balances associated with exchanges formed the largest segment of this operational bucket. Glassnode reported 1.63 million $BTC, or 8.1% of the total supply, aligned with this category, while their detailed breakdown indicated 1.66 million $BTC, around 8.3%. Together, these figures suggest approximately 1.6 million $BTC, representing roughly 40% of the operationally exposed total from the study.

It’s important to note that this categorization has its limits. Glassnode presented exchanges as merely a segment of on-chain balances, rather than a comprehensive account, and cautioned against interpreting this data as indicative of security, solvency, or immediate risk. The results varied significantly: while Coinbase’s attributed balances showed only 5% exposure, several other peers reported much higher figures. Exposure was not solely determined by custody scale.

Active management provides exchanges advantages that inactive holders do not possess. Glassnode suggested that techniques like address hygiene, rotation of change outputs, and better reserve management could diminish operational exposure prior to Bitcoin implementing a post-quantum signature framework. While custodians need to manage policies, approvals, backups, and both deposits and withdrawals, they retain the flexibility to move controlled balances.

Conversely, dormant or lost-key coins exist at the opposite end of the spectrum. A white paper from Google Quantum AI published in March differentiated between active assets that can be migrated and abandoned or inaccessible coins owned by individuals who cannot perform valid transactions. While protocol modifications can create safer options, they cannot enable an absent owner to sign.

This differentiation transforms the exchange pool into a significant test of practical execution, rather than simply a verdict on the more challenging aspects of migration.

BIP-360 lays groundwork as operational aspects evolve

BIP-360 differentiates between strategies for mitigating long-exposure threats and deciding on a post-quantum signature. This draft Bitcoin Improvement Proposal suggests incorporating Pay-to-Merkle-Root (P2MR) as a new SegWit output via a soft fork.

P2MR maintains the functionality of Taproot’s script tree while eliminating Taproot’s key-path spending feature. This means funds can be assigned to a script tree without automatically rendering a public key visible in the output, thus decreasing the potential attack area for long-exposure threats.

The draft does not introduce any specific post-quantum signature algorithm. Existing exchange balances, legacy outputs, and current Taproot coins would remain unchanged until their holders choose to move them. Additionally, P2MR does not completely eliminate the risk of short-exposure, since spending typically exposes a public key while transactions await confirmation. BIP-360 indicates that a separate proposal for post-quantum signatures might be necessary for that scenario.

Thus, activating this would create an optional destination followed by the operational work required to add wallet support and migrate balances. The draft status is also significant: it currently lacks a timeline for activation and is simply one method under review.

Recent studies have begun to clarify specific deployment questions. On August 19, Blockstream Research published benchmarks indicating that several tested hardware wallets were capable of generating the hash-based post-quantum signatures utilized in their analysis. The evaluation focused on signature generation on these devices and did not include verification of post-quantum firmware, lattice-based structures, or isogenies.

The findings highlight the limitations of individual devices. Manufacturers must still select algorithms to support, secure firmware, ensure adequate backups, construct recovery protocols, and harmonize with whatever regulations Bitcoin ultimately decides upon.

Institutional custody is at a similar early testing phase. BitGo, a regulated custodian, and MPC security firm Silence Laboratories reported a simulation of post-quantum transactions conducted in May, employing ML-DSA within a multi-party computation wallet process. This exercise included distributed key control, policy enforcement, and separation of roles. However, since it was merely a simulation, real-world deployment across Bitcoin exchanges remains untested.

These examinations segment a broad migration into distinct engineering challenges. A device’s ability to create a signature, a custody platform’s ability to enforce policies, and Bitcoin’s capability to validate a new algorithm are separate components. Each can function successfully on its own, while a comprehensive migration may still lag behind.

Two pathways to readiness

Coinbase’s workshop report places cryptographic design and operational implementation on parallel tracks. Different signature families entail varying costs related to transaction size, hardware efficiency, security paradigms, and key management. The deployment phase must effectively transition the selected design across institutions and individual users without disrupting access to funds.

The available evidence does not indicate a hierarchy between these tracks. Exchanges hold substantial, actively managed exposure, which may facilitate coordination better than inactive holders. However, their complexity also serves as a rigorous test of secure implementation. A theoretically sound proposal achieves little if custodians and wallets cannot execute it; flawless operations would have no endpoint until Bitcoin decides on revised protocol standards.

Progress in the short term can be gauged without assigning a timeline to a quantum threat. Custodians can mitigate key reuse, map exposed balances, and refine processes for key generation, backups, approvals, deposits, and withdrawals. Hardware manufacturers can assess potential algorithmic candidates and firmware options. Developers may evaluate P2MR alongside signature proposals that address the short-exposure scenario.

Glassnode’s identification of roughly 1.6 million $BTC transforms an abstract shift into a tangible group. The active participants in this cohort have both the capability to respond and the responsibility to demonstrate that large-scale migration is feasible. A successful effort in this area would address one significant aspect of Bitcoin’s vulnerability, but challenges remain with dormant coins, consensus within the ecosystem, and the ultimate cryptographic decision.

Share.