HomeCryptoBitcoinBitGo targets quantum risk in Bitcoin wallets as 6.04M BTC sits exposed

BitGo targets quantum risk in Bitcoin wallets as 6.04M BTC sits exposed

Roughly 30% of all Bitcoin in circulation already has its public key exposed — and no one has stolen a coin yet. But that window won’t stay open forever, and BitGo isn’t waiting to find out when it closes. The institutional custody firm rolled out four new quantum risk management controls for Bitcoin wallets on July 22, making it one of the first major custodians to give clients concrete tools to measure and reduce their exposure before any cryptographically relevant quantum computer actually exists.

Key takeaways

  • BitGo launched four quantum risk controls on July 22: a Quantum Risk Score, guided address remediation, a new UTXO selection method, and updated default address settings.
  • Glassnode estimated in May that 6.04 million BTC — about 30.2% of issued supply — already has public-key exposure at rest.
  • No practical quantum attack on Bitcoin exists today; BitGo’s tools are operational preparation for a future scenario.
  • Taproot and Pay-to-Public-Key outputs are not yet covered by the current release and require separate remediation.
  • BIP 360, a draft Bitcoin soft-fork proposal designed to reduce long-duration quantum exposure, remains unactivated and under technical review.

BitGo launches four quantum risk controls for Bitcoin wallets

The move targets institutional holders using supported Bitcoin multi-signature wallets. The four controls work together as a risk management layer: a Quantum Risk Score surfaces each wallet’s exposure in-platform, a guided address remediation workflow moves at-risk funds to fresh addresses, a revised UTXO selection method prevents partial spends from leaving exposed coins behind, and updated default address settings reduce reliance on output types that create earlier key visibility.

BitGo framed the release as operational preparation rather than an emergency response. Blockstream co-founder Adam Back, quoted in BitGo’s announcement, put it plainly: “nobody has a quantum computer that can touch Bitcoin today.” The point is precisely that institutions shouldn’t need an active threat to start managing the risk — the time to reorganize exposure is while it’s still theoretical.

That framing matters strategically. Institutional custody is a business built on the promise that client assets are safe under every foreseeable scenario. Offering quantum risk tooling now signals preparedness to regulators, boards, and large allocators who are increasingly asking about long-tail threats — even ones measured in years or decades.

Technical details of the quantum risk controls

Quantum Risk Score and what it actually measures

The Quantum Risk Score gives clients a single in-platform metric for public-key exposure across their wallets. The concept is straightforward: the more visible public keys an institution has tied to unspent outputs, the higher their theoretical vulnerability to a future quantum attack capable of deriving private keys from those public keys.

There is a significant limitation, however. BitGo has not published the score’s formula, weighting system, or thresholds. That makes it a proprietary internal risk indicator rather than an independently verifiable security standard. Institutions relying on it should understand they are trusting BitGo’s undisclosed methodology — a meaningful caveat for any security-critical application.

UTXO selection and address remediation

The mechanics behind the UTXO controls address a well-known Bitcoin characteristic: spending a coin from an address reveals the public key associated with that address. If any unspent outputs remain at that same address afterward — through address reuse or an incomplete spend — those coins now sit behind a visible public key.

BitGo’s new UTXO selection method tackles this by grouping coins by address. When the wallet selects one UTXO from an address to fund a transaction, it attempts to pull in every other UTXO associated with that address at the same time. The goal is to avoid the scenario where a spend exposes a public key while leaving funds behind at that address.

The Fix Exposed Addresses workflow takes a more direct approach: it moves affected funds into newly generated addresses whose public keys have never appeared onchain. Combined with updated defaults designed to reduce early key exposure, the two tools give institutions an active remediation path for their most vulnerable balances.

Limitations on Taproot and Pay-to-Public-Key output remediation

The current release has a notable gap. Taproot outputs expose their public key from the moment the output is created, not just after spending — a fundamentally different exposure profile from standard hashed-key outputs. Pay-to-Public-Key outputs carry the same problem. Both require separate remediation workflows that BitGo has not yet supported in this release.

That gap is meaningful given the growing adoption of Taproot across institutional wallets. For now, clients holding funds in those output types cannot fully address their quantum exposure through the new tooling alone.

Contextualizing quantum risks and ongoing Bitcoin proposals

How much Bitcoin is actually at risk

Glassnode’s May estimates put hard numbers on the abstract concern. Of the 6.04 million BTC with public-key exposure at rest, the firm classified 1.92 million BTC as structurally exposed through output design — meaning the exposure is baked into how those outputs were created. A further 4.12 million BTC fell into an operational exposure category, covering address reuse, partial spending, and custody practices. Within that operational bucket, exchange-related balances alone accounted for 1.63 million BTC.

Glassnode was careful to note that none of those coins can be stolen today. The data maps where public keys are already visible, not where attacks are imminent. But it does illustrate why institutional custodians are the right first audience for these tools — exchanges and large custodians represent a concentrated slice of the exposure.

The BIP 360 soft-fork proposal

At the protocol level, Bitcoin developers are working through BIP 360, a draft soft-fork proposal for Pay-to-Merkle-Root outputs. The design removes Taproot’s key-path spend and aims to reduce the attack surface for long-duration quantum exposure. Its authors have also flagged that faster attacks — targeting keys revealed while transactions await confirmation — may ultimately require post-quantum signatures, a separate and still-developing area of cryptographic research.

BIP 360 remains a draft. Any network-wide activation would need to clear technical review, implementation, testing, and broad adoption across wallets, nodes, and infrastructure. That timeline is genuinely uncertain, which is part of why BitGo’s custody-layer approach is worth watching — it doesn’t wait for a protocol-level solution before giving institutions something actionable today.

In May, BitGo and Silence Laboratories also tested post-quantum signing inside an institutional custody workflow — a separate signal that the industry is actively building toward cryptographic solutions, not just monitoring them from a distance.

The deeper question for the sector isn’t whether quantum computers will eventually pose a real threat to Bitcoin — most serious researchers believe they will, on a long enough horizon. The question is whether the ecosystem will have upgraded its cryptographic infrastructure before that horizon arrives. BitGo’s new controls don’t answer that question, but they do give the institutions managing the largest BTC balances a way to reduce their exposure while the answer takes shape.

FAQ

What new quantum risk controls has BitGo introduced for Bitcoin wallets?

BitGo introduced four controls on July 22: a Quantum Risk Score that measures public-key exposure across supported wallets, a guided address remediation workflow that moves funds to fresh addresses, a new UTXO selection method that groups coins by address to prevent partial-spend exposure, and updated default address settings that reduce reliance on higher-risk output types.

How does BitGo’s Quantum Risk Score work and can it be independently verified?

The Quantum Risk Score gives clients an in-platform measure of their public-key exposure, but BitGo has not disclosed its formula, weighting system, or thresholds. That makes it a proprietary risk management indicator rather than an independently verifiable security standard, which limits external assessment of its accuracy.

Why is there concern about public-key exposure in Bitcoin wallets?

Bitcoin public keys become visible after a coin is spent, and any remaining funds at that address are then protected only by a visible key. Taproot outputs go further — they expose the public key from creation. A sufficiently powerful quantum computer could theoretically derive a private key from a visible public key, allowing theft of those funds. Glassnode estimated in May that 6.04 million BTC, around 30.2% of issued supply, already has some public-key exposure at rest.

Are Taproot outputs fully covered by BitGo’s new quantum risk controls?

No. Taproot and Pay-to-Public-Key outputs require separate remediation because their public keys are exposed from the moment the output is created, not just after spending. That separate remediation path is not yet supported in the current BitGo release.

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

Satoshi Voice
Satoshi Voice is an advanced artificial intelligence created to explore, analyze, and report on the world of cryptocurrency and blockchain. With a curious personality and in-depth knowledge of the industry, Satoshi Voice combines accuracy and accessibility to offer detailed analysis, engaging interviews, and timely reporting. Featuring sophisticated language and an unbiased approach, Satoshi Voice serves as a trusted source for those seeking to understand crypto market dynamics, emerging technologies, and the cultural and financial implications of Web3. This article was produced with the support of artificial intelligence and reviewed by our team of journalists to ensure accuracy and quality. Guided by the mission of making cryptocurrency information accessible to all, Satoshi Voice stands out for its ability to turn complex concepts into clear content, with an engaging and futuristic style that reflects the innovative nature of the industry.
RELATED ARTICLES

Stay updated on all the news about cryptocurrencies and the entire world of blockchain.

Featured video

LATEST