KOSUNI CRYPTO
Korea's Crypto Pulse, in English
$BTC $ETH $XRP $SOL $DOGE
News
Neutral

1.6 Million BTC at Risk as Exchange Addresses Exposed to Quantum Threat

Published September 20, 2026 3:57 PM · 0 views $BTC
1.6 Million BTC at Risk as Exchange Addresses Exposed to Quantum Threat

Public keys related to Bitcoin (BTC) exchange addresses have been exposed in quantities of approximately 1.6 million coins, according to Glassnode's report. The network upgrade remains undecided as exchanges and custodians face the challenge of addressing address reuse and key management systems.

Coinbase ($COIN) held a closed 'Post-Quantum Bitcoin Workshop' on May 9 with Stanford University and Localhost Research participants, including developers, cryptographers, institutional custodians, and hardware wallet experts. While no specific signing methods or network upgrade schedules were agreed upon, Coinbase highlighted discussions on the trade-offs between security, transaction size, hardware performance, key management, and implementation difficulty.

Glassnode reported on May 20 that exposed public keys for Bitcoin amounted to 6.04 million coins, representing 30.2% of total supply. Of this, 4.12 million were exposed during operations, with exchange-related balances totaling approximately 1.63 million (reported as ~1.6 million in the article). Glassnode clarified that its data does not assess individual exchanges' security or solvency but measures on-chain identifiable exchange addresses and public key exposure.

Continued use of reused addresses or holding balances at exposed keys increases vulnerability to quantum attacks, leading exchanges to prioritize reducing address reuse, identifying exposed funds, and reviewing key generation, backup, and approval processes. This issue was previously highlighted in a previous report discussing the need for quantum-safe transactions without altering existing Bitcoin rules.

BIP-360 draft proposes 'Pay-to-Merkle-Root (P2MR)' output format to reduce long-term public key exposure by removing key path spending. However, short-term attacks during transaction malleability may require additional quantum-resistant signing methods. BIP-360 remains in 'Draft' status with no activation timeline. Even after implementation, existing balances must be manually transferred by exchanges and custodians, requiring full support from wallet systems and withdrawal processes.

Blockstream Research announced on August 19 that hash-based quantum-resistant signing was feasible across four hardware wallets, though the experiment was limited to internal signature generation without quantum-resistant firmware validation or lattice- and isogeny-based methods. Meanwhile, BitGo and Silence Laboratories completed a quantum-resistant transaction simulation using ML-DSA in multi-party computation (MPC) wallets on May 26, including distributed key management and policy enforcement, but not yet verified for live exchange deployment.

Google Quantum AI researchers noted in March that Bitcoin holdings with lost or inaccessible private keys cannot voluntarily transition to new signing systems. They estimated dormant assets could reach up to 2.3 million coins across all script types, though this is a rough estimate. Coinbase plans further workshops, but final signature methods and network upgrade schedules remain undetermined.

Korean Source

This article is an English localization of a Korean-language crypto news report. Original headline: 160만 BTC 노출…거래소 양자 대응은 주소 관리부터