TechNewsReel
Live

Quantum Risk Looms Over 30% of Bitcoin Supply as Exchange Hygiene Falters

Glassnode research reveals 6.04 million BTC is vulnerable to quantum attacks, with custodial exchanges driving a significant portion of the risk.

TechNewsReel Newsroom · September 14, 2026

Nearly one-third of the total Bitcoin supply is currently vulnerable to potential quantum computing attacks, according to new on-chain research from Glassnode. The findings highlight a critical security gap where revealed public keys create a measurable attack surface for future quantum adversaries.

Data shows that 6.04 million BTC, or 30.2% of the issued supply, is exposed to quantum risk. A substantial portion of this is categorized as "operational exposure," which accounts for 4.12 million BTC (20.6% of the supply). This specific risk is driven by address reuse, partial spending, and specific custody behaviors. Cryptocurrency exchanges are central to this vulnerability, accounting for roughly 40% of the operationally exposed set, which equates to approximately 1.66 million BTC.

The Mechanics of Exposure

The vulnerability stems from how Bitcoin handles public keys. While addresses are hashed, the actual public key is revealed on-chain the moment an address is used to send a transaction. If a user or entity reuses that same address to hold remaining funds, the public key remains known to the network.

This creates a window for quantum computers utilizing Shor's algorithm, which could theoretically derive a private key from a revealed public key. While a capable quantum computer does not yet exist, the "quantum attack surface" is being built in real-time through poor wallet hygiene. This risk exists independently of whether the Bitcoin protocol has been upgraded to post-quantum cryptography.

Custodial Negligence

The research reveals a stark contrast in how major exchanges manage their custodial reserves. According to the data, Bitfinex is the most susceptible, with approximately 100% of its labeled balances exposed. Binance follows closely with roughly 85% exposure. In contrast, Coinbase has maintained significantly better wallet hygiene, with only about 5% of its labeled balances showing exposure.

These findings place exchanges at the center of measurable exposure due to operational wallet practices tied to their massive custodial reserves. Because this exposure is a result of operational choices—specifically address reuse—rather than a limitation of the Bitcoin protocol, exchanges have the immediate power to mitigate the risk by migrating funds to new addresses.

The Path to Resilience

To address these systemic vulnerabilities, the community is exploring protocol-level protections. BIP-360 is a current proposal aimed at introducing quantum-resilient transaction formats to the network, specifically the Pay-to-Merkle-Root (P2MR) format.

However, a network-wide upgrade is a long-term solution. In the interim, the industry's immediate defense relies on the willingness of large custodians to abandon address reuse. Until a majority of the 6.04 million exposed BTC is migrated to fresh addresses, a significant portion of the market remains a potential target for the arrival of "Q-Day."

Sources

Get a notification when a big story breaks. A few a day at most — no spam.