Exchanges Face Quantum Exposure Before Bitcoin Upgrade
A recent workshop on post-quantum Bitcoin hosted by Coinbase highlighted the need for exchanges and custodians to adopt new rules to protect against quantum computer attacks. The event brought together developers, cryptographers, institutional custodians, and hardware-wallet experts, but no consensus was reached on an exact approach.
A Glassnode study in May found that approximately 1.6 million BTC ($78,749) are stored in exchange-related outputs with visible public keys, making them vulnerable to attacks. While a sufficiently capable quantum computer could break the public key and derive the private key, no such machine currently exists, and Coinbase considers the risk non-immediate.
However, the study identified 6.04 million BTC (30.2% of issued supply) with public-key exposure at rest in May. Exchanges are the largest contributors to this figure, with approximately 1.63 million BTC attributed to them. The results varied widely among exchanges, and custody scale alone did not determine exposure.
Exchanges can reduce their operational exposure by implementing address hygiene, change-output rotation, and reserve management. These measures can shrink the attack surface for long-exposure attacks, but will not eliminate it entirely. A new Bitcoin Improvement Proposal (BIP-360) suggests adding Pay-to-Merkle-Root (P2MR) as a new SegWit output through a soft fork, which would reduce the visibility of public keys in outputs.