BTCBTC$82,298-0.51%|
ETHETH$2,489.81-3.02%|
USDTUSDT$0.99928-0.02%|
BNBBNB$740.8900-3.63%|
XRPXRP$1.3900-0.90%|
USDCUSDC$0.99961-0.01%|
SOLSOL$110.2700-4.41%|
TRXTRX$0.33176-0.99%|
FIGR_HELOCFIGR_HELOC$1.0300+1.17%|
ZECZEC$1,220.14-2.00%|
HYPEHYPE$85.4800-1.94%|
DOGEDOGE$0.08500-3.04%|
USDSUSDS$0.99958+0.07%|
XMRXMR$536.9500-4.00%|
LINKLINK$12.8600-2.21%|
WBTWBT$80.9600-1.89%|
ADAADA$0.23540-7.33%|
LEOLEO$8.8900-0.03%|
RAINRAIN$0.01031-5.61%|
XLMXLM$0.19460-2.25%|
NEARNEAR$4.7800-12.11%|
BCHBCH$280.2000-5.40%|
LTCLTC$64.0300-0.85%|
USDEUSDE$0.99924-0.02%|
CCCC$0.11813+1.07%|
UNIUNI$7.3600-5.99%|
DAIDAI$1.0000+0.04%|
AVAXAVAX$10.2500-5.35%|
SUISUI$1.0610-6.43%|
USD1USD1$0.99921+0.05%|
BTCBTC$82,298-0.51%|
ETHETH$2,489.81-3.02%|
USDTUSDT$0.99928-0.02%|
BNBBNB$740.8900-3.63%|
XRPXRP$1.3900-0.90%|
USDCUSDC$0.99961-0.01%|
SOLSOL$110.2700-4.41%|
TRXTRX$0.33176-0.99%|
FIGR_HELOCFIGR_HELOC$1.0300+1.17%|
ZECZEC$1,220.14-2.00%|
HYPEHYPE$85.4800-1.94%|
DOGEDOGE$0.08500-3.04%|
USDSUSDS$0.99958+0.07%|
XMRXMR$536.9500-4.00%|
LINKLINK$12.8600-2.21%|
WBTWBT$80.9600-1.89%|
ADAADA$0.23540-7.33%|
LEOLEO$8.8900-0.03%|
RAINRAIN$0.01031-5.61%|
XLMXLM$0.19460-2.25%|
NEARNEAR$4.7800-12.11%|
BCHBCH$280.2000-5.40%|
LTCLTC$64.0300-0.85%|
USDEUSDE$0.99924-0.02%|
CCCC$0.11813+1.07%|
UNIUNI$7.3600-5.99%|
DAIDAI$1.0000+0.04%|
AVAXAVAX$10.2500-5.35%|
SUISUI$1.0610-6.43%|
USD1USD1$0.99921+0.05%|
News/Wallets & Security
Wallets & Security

Nearly a Third of Bitcoin Has Visible Public Keys. What Does That Mean for Holders?

Nearly a Third of Bitcoin Has Visible Public Keys. What Does That Mean for Holders? — Wallets & Security crypto news

Summary

  • Approximately 6.26 million BTC, or 31.2% of circulating supply, sits behind visible public keys.

  • Address reuse accounts for roughly 4.33 million BTC, making operational practices the largest exposure category.

  • Exchanges hold approximately 1.79 million BTC with exposed public keys.

  • Public-key exposure measures address and custody arrangements; it is not a security ranking or evidence of theft.

Bitcoin quantum risk is drawing renewed attention after an October 8 update attributed to Glassnode co-founder Rafael Schultze-Kraft put 6.26 million BTC—31.2% of circulating supply behind public keys already visible on-chain. The measurement identifies cryptographic exposure; it does not establish that those coins have been hacked.

The distinction matters. A public key is routinely used to verify transactions. Its visibility becomes relevant to the quantum debate because a sufficiently capable future quantum computer could potentially use it to recover the private key that authorizes spending.

The figures therefore raise a question about preparedness: how much Bitcoin would require attention if the underlying cryptographic assumptions changed?

Bitcoin quantum risk: the numbers behind the headline

The latest reported breakdown separates exposure caused by address-management practices from exposure inherent in particular Bitcoin output types.

Measurement

Reported figure

What it describes

Total exposed balance

6.26 million BTC

Coins associated with visible public keys

Share of circulating supply

31.2%

Exposure under this methodology

Operational exposure

About 4.33 million BTC

Primarily address reuse

Structural exposure

About 1.94 million BTC

Output designs that reveal keys

Exchange-held exposed balance

About 1.79 million BTC

A subset of the total, not an additional category

Figures are rounded independently, so the category totals may not add precisely to the headline balance.

The exposed share was reported at 24.8% in early 2021. Its rise to 31.2% represents an increase of 6.4 percentage points, calculated from those figures.

Why reusing an address changes the picture

Bitcoin’s public and private keys perform different jobs. The private key authorizes spending; the public key allows the network to verify that authorization.

Some Bitcoin output formats conceal the public key behind a hash while coins remain unspent. Once a spend reveals that key, remaining or subsequently received coins associated with the same key can enter the exposed category.

Glassnode calls this operational exposure. Its methodology distinguishes that from structural exposure, where the output design makes the key visible from the outset.

For readers unfamiliar with the terminology, Bitnxt’s crypto glossary provides background on addresses, private keys and other wallet concepts.

The practical takeaway is specific: address management affects measurable public-key exposure. Simply installing a different wallet application does not necessarily change the keys controlling existing coins.

Taproot needs a careful explanation

Older pay-to-public-key outputs expose keys directly. Modern Taproot outputs also make an output public key visible.

That does not make Taproot generally defective. Glassnode’s research explicitly distinguishes its privacy, efficiency and scripting benefits from the narrower question of exposure under a future quantum attack model.

The relevant question is whether an attacker already has the public-key information needed for a hypothetical key-recovery attack. That is different from asking whether an address is currently compromised.

A fresh address can therefore mean different things depending on its output type. “New” and “post-quantum secure” are not interchangeable descriptions.

Exchanges face a coordination challenge

Reported exposure has increased by approximately 222,000 BTC since Glassnode’s May study, while circulating supply grew by around 64,000 BTC. Exchanges accounted for 123,000 BTC of the exposure increase.

Those figures suggest that the change involves existing coins moving into exposed arrangements, rather than simply new Bitcoin entering circulation.

For custodians, reducing exposure would involve reviewing receiving addresses, change outputs, signing systems and reserve-management practices. Large balances make that an operational project requiring planning and testing.

Glassnode cautions that its methodology does not assess a custodian’s solvency or overall security. Exposure figures should consequently not be used as a league table of “safe” and “unsafe” exchanges.

Hardware storage and quantum protection address different problems

A hardware wallet can be part of a signing and storage arrangement, but choosing a device does not by itself establish resistance to future attacks on Bitcoin’s signature cryptography.

Readers comparing storage approaches can explore Bitnxt’s crypto wallet directory and hardware wallet comparison. The relevant questions include how an account generates addresses, whether it reuses keys and what the device protects against.

That distinction also explains why an exposure headline should not trigger an improvised transfer. Any proposed move needs a clearly defined security benefit.

You might also like: Vitalik Buterin Warns Against Rushed Wallet Moves as AI Raises New Cryptography Questions.

A protocol proposal targets part of the problem

Bitcoin Improvement Proposal BIP 360, currently marked Draft, proposes a new output type called Pay-to-Merkle-Root, or P2MR.

It would remove Taproot’s key-path spending mechanism while retaining script-tree functionality. The proposal targets long-exposure attacks, where public-key information remains available for an extended period.

Its authors distinguish that protection from attacks occurring during the short window when a spending transaction reveals a key. Broader protection could require post-quantum signatures. BIP 360 is therefore a proposed mitigation, not an activated, comprehensive replacement for Bitcoin’s cryptography.

Bitnxt’s view: measure the exposure, then define the response

Bitnxt’s assessment is that the most useful part of this research is its separation of problems that require different responses.

Address reuse is an operational issue. Structurally exposed outputs involve design choices. A future weakness in signature cryptography would require a broader technical response.

Combining them into a single alarm obscures those differences. The better approach is to identify the output types and signing arrangements involved, understand what a proposed change would accomplish, and test the process before moving significant balances.

The 6.26 million BTC figure illustrates the scale of preparation that might be needed. It does not provide a countdown to a quantum attack.

Research note: The original October 8 X thread was inaccessible during verification. Current figures were cross-checked against accessible reporting; technical explanations were checked against Glassnode’s published methodology and the BIP 360 specification. 

#Bitcoin#QuantumComputing#Glassnode#WalletSecurity#PublicKeys#AddressReuse#Taproot#SelfCustody
Pankajj Purohit

Author

Pankajj Purohit

Exchange & Industry News Writer

Pankajj Purohit has covered exchange news and industry developments for 3 months, reporting on listings, platform updates, and company announcements across the crypto space. He focuses on delivering timely, accurate industry coverage for Bitnxt.

More Wallets & Security News

Share: