Glassnode Maps Bitcoin’s Quantum Exposure: 6.04M BTC at Risk, Exchange Wallet Hygiene in Focus
Glassnode says 6.04M BTC (30.2% of supply) is exposed to future quantum attacks. Exchange address reuse drives 40% of operational risk. BIP-360 and migration plans enter the chat.

Because Bitcoin
May 22, 2026
If quantum computers ever reach Shor-capable scale, a large slice of Bitcoin already looks exposed on-chain. Fresh analysis from Glassnode estimates that 6.04 million BTC—30.2% of the issued supply, worth over $469 billion—has a publicly revealed key and could be directly targetable in a post–“Q-Day” world. The remaining 13.99 million BTC shows no public-key exposure. That figure is slightly below prior estimates that hovered closer to 7 million BTC, but the directional takeaway doesn’t change: the layout of keys on-chain matters.
What actually drives the risk is not transactions per se, but when a public key is known. A sufficiently powerful quantum computer running Shor’s algorithm could derive a private key from a revealed public key. Any UTXO with an already-known key would be in the crosshairs without waiting for a new spend.
Glassnode splits exposure into two buckets:
- Structural: 1.92 million BTC (9.6% of supply) resides in script types that reveal the public key by design—early pay-to-public-key outputs linked to Satoshi-era coins, legacy multisig structures, and Taproot outputs. Many of these coins are likely immobile or lost, which blunts remediation options but doesn’t erase the theoretical risk profile.
- Operational: 4.12 million BTC (20.6% of supply) became exposed through address reuse. When a reused address spends, the wallet broadcasts the public key; any leftover balance tied to that key is then exposed. This is the largest, most fixable piece of the problem.
The exchange footprint is the tell. Roughly 1.66 million BTC—8.3% of total supply and about 40% of the operationally exposed set—sits with exchanges. The spread is uneven: Coinbase’s labeled balances appear only about 5% exposed, while Binance and Bitfinex show far higher susceptibility at approximately 85% and 100%, respectively. Glassnode stresses this is not a solvency read or a safety ranking; it reflects custody design choices and UTXO management, not imminent danger.
This is the chokepoint worth focusing on. Custodians often optimize for throughput, fee efficiency, and simple accounting—habits that can entrench address reuse. That operational muscle memory created today’s visible attack surface. The fixes are mostly boring plumbing: stricter address hygiene, reserve segmentation, minimal key reuse, and structured migration plans. Those aren’t headline features, but they materially reduce the portion of coins that would be instantly targetable if a credible quantum adversary appeared.
Sovereign-held balances look cleaner. The United States, United Kingdom, and El Salvador show zero quantum exposure, underscoring how policy-led custodians can enforce stricter standards when incentives are aligned and governance is clear.
The timeline remains uncertain. Estimates for “Q-Day” commonly range from 2030 to 2032 and later, and Glassnode doesn’t forecast when—or even whether—a machine that can crack Bitcoin signatures will arrive. Still, the macro drumbeat is getting louder: the United States just earmarked over $2 billion for quantum startups and planned foundries, and Bitcoin developers are debating protocol-level responses. One proposal, BIP-360, aims to introduce more quantum-resilient transaction formats. Another official idea would freeze coins that fail to migrate by a deadline—an approach that could reduce systemic exposure but would trigger heated debate about property rights and network social contracts.
Practical takeaway: the actionable vector is operational exposure. Exchanges and large custodians can meaningfully compress risk by halting address reuse, refreshing UTXOs into non-exposed structures, and building automated migration pathways well before fees spike or headlines force a scramble. The technology conversation will evolve, and protocol proposals may mature, but disciplined wallet hygiene can move the needle now—quietly, predictably, and at scale.
