Glassnode has quantified a long-discussed risk for Bitcoin holders. According to a report from Wu Blockchain, Glassnode co-founder Rafael estimates that roughly 6.26 million BTC—about 31.2% of the total supply—have public keys exposed to potential quantum computing attacks. That does not mean those coins are immediately vulnerable, but it frames how large the eventual migration surface could become if quantum-resistant tooling is not adopted. The estimate arrives as Bitcoin’s security model faces renewed scrutiny from researchers, developers, and institutional users.
Why public key exposure matters
The distinction between public keys and public addresses sits at the center of this analysis. When Bitcoin is received, an address is a hash of a public key, which provides an additional layer of security. Once a wallet signs a transaction and reveals its public key, a sufficiently capable quantum computer could theoretically derive the private key from that public key. The Glassnode estimate therefore focuses on coins whose public keys have already been exposed on-chain. In Bitcoin’s current design, the public key is not needed until the owner spends from an address, which is why many older and unmoved balances remain less exposed. This is not a present-day attack, but a forward-looking inventory of addresses that may need to prove quantum-resistant upgrade paths. Such concerns are part of a broader Bitcoin security conversation, even as markets continue to track institutional flow data in cases such as US Bitcoin Spot ETFs Record $149 Million Net Outflow on September 30.
How much supply could be in scope
The scale matters for protocol watchers: 6.26 million BTC represents nearly a third of Bitcoin’s current supply. If a quantum-safe transition is treated as a consensus or best-practice problem rather than an individual wallet issue, the number of affected UTXOs may be far larger. The distinction matters because not all bitcoin supply carries the same degree of public key visibility. Coins in addresses that have never spent, for example, retain the hashed-address protection, while reused or spent addresses have revealed more information. The estimate also highlights a supply-side question that regularly shapes Bitcoin’s narrative. While not equivalent to lost coins or illiquid supply, exposed public keys create a distinct class of potentially at-risk bitcoin. Supply framing is a recurring theme for Bitcoin analysis, as seen in Saylor: $100B Bank Credit Could Match 10 Years of BTC Supply.
What to watch next
For investors and builders, the next milestone is not an imminent exploit but whether wallets, exchanges and layer-2 protocols begin publishing concrete quantum-resistance timelines. The policy response could range from new transaction types to address formats that avoid public key exposure until necessary. Because Bitcoin has no central body that can force upgrades, adoption would likely depend on community coordination and wallet default settings. The conversation may also push more users toward custody and lending models that assume longer holding periods, which in turn intensifies the need for robust key management. Bitcoin-backed lending discussions, including Arch Lending Co-Founder Makes Case for Bitcoin-Backed Loans, are part of that broader shift toward treating bitcoin as a long-term collateral asset. Until tooling changes, the 6.26 million BTC figure serves as a planning benchmark, not a security declaration.