Technology & Security

Glassnode Flags 6.26 Million BTC With Exposed Public Keys

Glassnode says 31.2% of issued Bitcoin sits behind visible public keys, renewing debate over address reuse, quantum preparedness and controlled migration.

Glassnode Flags 6.26 Million BTC With Exposed Public Keys
Glassnode’s latest figures put 31.2% of issued Bitcoin behind visible public keys, renewing discussion of address reuse and preparations for future cryptographic threats. Photo: Kaboompics.com / Pexels

Key Notes

  • Glassnode estimates 6.26 million BTC, or 31.2% of issued supply, sits behind public keys already visible on the blockchain.
  • Address reuse accounts for 4.33 million BTC, while other exposure comes from output designs including early public-key payments and Taproot.
  • Fresh addresses can reduce some exposure, but the data does not establish an attack timeline and address rotation is not full post-quantum protection.

About 6.26 million Bitcoin, equivalent to 31.2% of issued supply, is held behind public keys already visible on the blockchain, according to Glassnode co-founder Rafael Schultze-Kraft. The estimate measures the amount potentially exposed if advances in computing make recovering private keys practical.

Schultze-Kraft published the figures on October 8, saying the share had risen from 24.8% in early 2021 and returned to levels last seen in 2016. The percentage refers to coins already issued, rather than Bitcoin’s eventual 21 million maximum.

The update adds scale to the debate over wallet migration and quantum preparedness. It does not report a quantum theft, demonstrate a working key-recovery attack or forecast when such an attack might become possible.

Address Reuse Accounts for Most of the Exposure

The largest component is 4.33 million BTC associated with address reuse. In these cases, an address has already spent funds and revealed its public key, leaving coins still controlled by that key exposed to a potential future cryptographic attack.

A further approximately 1.94 million BTC falls into a different category: transaction outputs that expose public keys through their design. Schultze-Kraft’s breakdown identifies 1.71 million BTC in early pay-to-public-key outputs and about 222,000 BTC in Taproot outputs. The published component figures are rounded.

Those categories require different responses. Avoiding address reuse can reduce exposure created by spending history, while an output that publishes a key from the outset requires a different destination design. Simply choosing an unused address does not guarantee that its public key will remain hidden.

The new figures update the framework behind CoinScreamer’s May coverage. That earlier dataset put total exposed supply at about 6.04 million BTC. Schultze-Kraft says exposure has since increased by roughly 222,000 BTC, compared with about 64,000 BTC added to issued supply.

A Visible Public Key Is Not a Stolen Private Key

Bitcoin uses private keys to authorize spending and public keys to verify signatures. Glassnode’s methodology examines where the public information needed for a hypothetical attack is already available. It does not establish that the corresponding private keys have been recovered.

The quantum concern is that a sufficiently capable computer could use Shor’s algorithm to undermine the elliptic-curve mathematics protecting those keys. Where a key is already visible, an attacker would not need to wait for the owner to broadcast another transaction before beginning that attempt.

Keys hidden behind hashes present a different situation. Spending can reveal them while a transaction awaits confirmation, creating a shorter attack window. Reducing exposure during storage therefore does not make an address fully resistant to every future quantum attack.

Exchange Balances Have Become More Exposed

Schultze-Kraft says exchanges hold about 1.79 million BTC behind visible public keys. Such coins now represent 57% of the exchange balances tracked in the analysis, up from 55% in May and 39% at the beginning of 2021.

Exchanges accounted for approximately 123,000 BTC of the increase since May. That gives custodians a substantial role in any coordinated effort to reduce public-key exposure, alongside individual holders and wallet developers.

The figures nevertheless have important limits. Schultze-Kraft explicitly cautioned that entity totals cover labeled addresses only. The percentages are not rankings of exchange security, evidence of insolvency or predictions about whether and when a threat will materialize.

Fresh Addresses Require Careful Planning

The discussion follows Ethereum Foundation researcher Justin Drake’s call for a controlled migration toward appropriate addresses whose public keys remain hidden behind hashes. As CoinScreamer’s Drake coverage explains, his warning also considered hypothetical AI-assisted mathematical advances, a separate route from quantum hardware.

Bitcoin.org’s privacy guidance already recommends using a new address to receive each payment. That practice can also help avoid the public-key exposure associated with reuse, provided the chosen output type actually keeps the key hidden before spending.

Generating another address is not necessarily the same as replacing a wallet or creating a new seed phrase. Drake has advocated deliberate preparation rather than rushed transfers. Vitalik Buterin’s separate migration warning likewise emphasized the operational dangers of moving assets hastily.

Protocol Changes Remain a Separate Task

Developers are also considering changes to Bitcoin itself. The draft BIP 360 proposes pay-to-Merkle-root outputs, retaining script-tree functionality while removing Taproot’s public-key spending path. Its aim includes reducing exposure to attacks that can work on a visible key over an extended period.

The proposal is not an activated network upgrade. It also does not introduce post-quantum signatures or, by itself, solve attacks fast enough to recover a key while a spending transaction remains unconfirmed.

Glassnode’s update quantifies the balances involved in preparing for that challenge. It leaves the attack timeline unresolved and makes the distinction between better address management and changes to Bitcoin’s cryptography central to any migration plan.

Disclaimer: CoinScreamer is an independent media brand owned and operated by NuvexMedia LLC, publishing news, research, and market insights on digital assets and related technologies. NuvexMedia LLC invests in and collaborates with companies across the digital asset, blockchain, and technology sectors. These relationships do not influence CoinScreamer’s editorial coverage, and the publication maintains full editorial independence to provide accurate, timely, and objective information. © 2025 NuvexMedia LLC. All rights reserved. This content is for informational purposes only and should not be considered legal, tax, investment, financial, or other professional advice.

News, Technology & Security