Bitcoin's Quantum Risk Hinges on Exposed Public Keys, Fireblocks Research Chief Says
Key Takeaways
- •An estimated 6.7 million to 7 million BTC, about one-third of Bitcoin's 21 million supply cap, sits behind public keys already visible onchain and therefore exposed to quantum attack.
- •Pay-to-public-key outputs from the Satoshi era expose keys from creation, while P2PKH and SegWit addresses hide keys only until the first spend, after which address reuse keeps new funds vulnerable.
- •No cryptographically relevant quantum computer capable of breaking Bitcoin's current signatures is known to exist, but experts warn that research, software changes, and user adoption could take years.
- •Gutkin recommends continuous public-key management—directing deposits and change to fresh addresses while tracking UTXOs—instead of a one-time migration that could raise fees and increase operational errors.
- •Fireblocks reduced gas costs for verifying the post-quantum signature scheme ML-DSA-44 on Ethereum from 8.09 million to 1.23 million gas, though the implementation remains research code requiring audits before production use.

Bitcoin's future vulnerability to quantum computing will be decided less by who owns the coins than by how they are stored. Michael Gutkin, Vice President of Research at digital asset custodian Fireblocks, told crypto.news that a holder's exposure is determined by the blockchain involved, the address type in use, and the address's transaction history — not by whether the owner is an exchange, an institution, or an individual.
"Exposure ultimately comes down to whether the public key is already visible onchain," he said.
That distinction is mathematical rather than organizational. Bitcoin's signatures rest on elliptic-curve cryptography, and Shor's algorithm — first described in 1994 — is known to allow a sufficiently powerful quantum computer to derive a private key from its matching public key. A key that has never been broadcast leaves an attacker with only a hash to work from, which is why storage history, rather than ownership, shapes the risk.
Public estimates cited by Gutkin suggest roughly 6.7 million to 7 million BTC sit behind keys that are already visible onchain — about a third of the network's fixed 21 million coin supply cap — making exposed public keys the central factor in Bitcoin's quantum risk.
When Coins Move Matters as Much as Where They Sit
In Gutkin's assessment, frequent transactions can generate exposure through address reuse and the handling of unspent Bitcoin. A treasury that rarely moves its holdings may keep its public keys hidden for longer, but only if the address format and previous activity have not already revealed them.
Satoshi-Era Outputs and Reused Addresses Expose Keys
For the earliest Bitcoin outputs, known as pay-to-public-key (P2PK) outputs, the public key is visible from the start. Many outputs dating to the Satoshi era use that format, Gutkin explained, meaning their keys remain exposed even if the coins have never moved.
Pay-to-public-key-hash (P2PKH) and native SegWit (P2WPKH) addresses work differently, hiding the public key until the first spend from the address. Once a holder spends, however, the key becomes permanently visible. If the same address later receives more Bitcoin, those new funds sit behind a key that has already been revealed.
For holders assessing their own exposure, Gutkin recommended examining whether addresses have spent before and whether they continue to receive funds.
Taproot adds another distinction. According to the authors of BIP 360, Taproot outputs are exposed to long-duration quantum attacks because their output public keys are visible the moment they are created. The proposal states that a sufficiently capable quantum computer could derive a private key from an exposed public key, and its authors distinguish attacks against keys visible for long periods from faster attacks attempted after a transaction reveals a key but before it confirms.
The concern remains a future one. In a Sep. 17 report on Bitcoin's migration challenges, Ledger Chief Technology Officer Charles Guillemet said no cryptographically relevant quantum computer capable of breaking Bitcoin's current signatures was known to exist. He nevertheless warned that research, software changes, hardware wallet upgrades, and user adoption could take years, making preparation a separate problem from the arrival of a working attacker.
Gradual Wallet Changes Can Reduce Exposure
Responding to calls for "bunker mode" preparation, Gutkin argued that institutions should manage public-key exposure continuously rather than plan a single mass transfer.
"For an institution, I don't think the goal should be a one-time mass migration," he said.
Under the approach he described, new Bitcoin deposits would go to fresh addresses, and change from transactions would also return to fresh addresses. Institutions should track individual unspent transaction outputs (UTXOs) — Bitcoin represents holdings as discrete unspent outputs rather than account balances — to identify which funds already sit behind exposed keys. Through normal spending, exposed addresses would gradually empty while new funds arrive at addresses whose public keys remain hidden. Gutkin said a live exposure dashboard should show both the remaining exposed balance and the transactions creating additional exposure.
Fireblocks already supports several components of that process, according to Gutkin, and is developing tools for selecting transaction inputs based on exposure and for displaying affected balances.
Other custody providers have introduced related controls. In a July 22 announcement, BitGo detailed four Bitcoin wallet controls covering exposure scoring, address remediation, transaction-input selection, and updated address defaults. The company said its input-selection method attempts to spend all unspent outputs associated with a selected address, reducing the chance of leaving funds behind after a transaction reveals the key. BitGo described the controls as operational preparation rather than a replacement for a future Bitcoin upgrade.
Gutkin cautioned that a rushed migration carries risks of its own. Large holders competing for limited Bitcoin transaction capacity could drive fees higher and slow confirmations. Within institutions, additional transactions and approvals could increase mistakes, including sending change back to an exposed address. To limit phishing and handling errors, he recommended establishing destination addresses, approval policies, and trusted communication channels in advance, so that an urgent transfer does not require customers or staff to follow unfamiliar instructions or bypass existing controls.
Bitcoin Still Needs a Quantum-Resistant Way Spend
Even with better address practices, Gutkin said Bitcoin would still need a quantum-resistant method for authorizing transactions. BIP 360 addresses part of the problem by proposing pay-to-Merkle-root outputs, which remove Taproot's exposed key-spending path. He stressed, however, that reducing long-term public-key exposure does not make the proposal a complete post-quantum solution. The proposal's authors likewise state that protection against attacks during the brief window after a transaction is broadcast but before it confirms may require post-quantum signatures. BIP 360 remains listed as a draft.
Unlike Ethereum, Bitcoin cannot simply accept a new signature-verification contract through a general-purpose application layer, Gutkin said. Depending on the design chosen, protocol changes may be necessary to support the scheme and keep transaction fees manageable. He also pointed to research into hash-based signatures, including designs that track signing state to reduce overhead, though such approaches involve trade-offs in signature size, wallet design, and recordkeeping.
For U.S. investors holding Bitcoin through funds, custody arrangements are another part of the preparation. A Sep. 23 report on Coinbase's post-quantum custody plans noted that spot Bitcoin and Ethereum ETF investors do not control the private keys securing fund holdings; the custodians selected by issuers manage them. In that report, Coinbase Chief Cryptographer Yehuda Lindell described plans for custody infrastructure capable of supporting different post-quantum signature schemes, and said Coinbase was exploring programmable hardware security modules as an alternative when a blockchain's chosen scheme cannot work with its existing distributed-signing systems.
Cheaper Verification, but Ethereum Still Requires Wallet Changes
On Ethereum, Gutkin said standard accounts expose their public keys as soon as they sign a transaction, because the key can be recovered from the signature. Unlike Bitcoin's address rotation, regularly replacing an Ethereum account is less practical, since balances, token approvals, and application activity are tied to it. Solana's standard wallets face an even simpler problem: the address is the public key itself, so the key is exposed without any initial spending transaction.
Programmable Ethereum accounts — the approach the ecosystem calls account abstraction — offer a way to change transaction authorization while retaining the account, according to Gutkin. Fireblocks' research has reduced verification of ML-DSA-44, a post-quantum signature scheme, from 8.09 million gas to 1.23 million gas. In a Sep. 2 research post, Fireblocks reported that the verifier follows FIPS 204, the digital-signature standard finalized by the U.S. National Institute of Standards and Technology in 2024. Gutkin said the team improved the implementation rather than changing the standardized algorithm, with more efficient hashing, mathematical operations, signature decoding, public-key handling, and memory use. Peak memory consumption fell from nearly a megabyte to about 41 kilobytes.
The design still carries costs. Gutkin put the one-time deployment cost for the expanded public key at roughly 4.1 million gas, alongside the 1.23 million gas required for each verification. For a treasury or cold wallet that transacts relatively rarely, those costs may be reasonable, he said. He cautioned, however, that a standard Ethereum account cannot simply switch to ML-DSA, and that smart-account integration, custody support, and compatibility with decentralized applications still require engineering work.
Gutkin also noted that the verifier does not make Ethereum's entire system post-quantum secure, with separate research continuing at its consensus and data layers. Despite extensive testing and formal verification, Fireblocks' implementation remains research code that requires audits and hardening before production use. For institutional custody, the company is separately researching production-grade post-quantum signing systems. Whether BIP 360 moves beyond draft status, whether early implementations clear audits and hardening, and whether custodians carry post-quantum signing research into production are the concrete markers of how that preparation progresses.