Skip to content

InvestNot yet confirmed elsewhere1 publisher3 min readPublished

Fireblocks wants custodians to shrink Bitcoin's quantum exposure one spend at a time

Fireblocks' Michael Gutkin ties Bitcoin's quantum risk to exposed public keys, citing estimates that 6.7 million to 7 million BTC already sit behind them. Custodians can apply his remedy, fresh addresses plus a running count of exposed coins, without waiting for BIP 360.

The Investor · Invest desk

How we use AISend a correction

Illustration accompanying Fireblocks wants custodians to shrink Bitcoin's quantum exposure one spend at a time
Generated illustration

What happened

  • P2PKH and native SegWit addresses hide a public key until the first spend, and any bitcoin later sent to a spent address sits behind a key already revealed.
  • BIP 360's authors count Taproot outputs among those open to long-duration quantum attacks, since a Taproot output's public key shows onchain from the moment the output is created.
  • Gutkin wants new deposits and change sent to fresh addresses, with each UTXO tracked so exposed addresses empty out through normal spending.
  • BitGo announced four Bitcoin wallet controls on July 22 covering exposure scoring, address remediation, transaction-input selection and updated address defaults.

Why it matters

  • constraint A custodian that defaults fresh addresses to Taproot keeps long-duration exposure on every new output, so the choice of address type counts as much as the rotation policy.
  • decision Treasuries that seldom spend have to choose between waiting out a slow drain of coins already behind exposed keys and moving those coins on purpose.
  • exposure Every spend still reveals a key before it confirms, so even a clean fresh-address book stays open to a fast attack until the protocol covers that window.
  • precedent With BitGo and Fireblocks both building exposure scoring or tracking, clients now have grounds to ask custodians for a reported exposed-balance figure.

If exposure "ultimately comes down to whether the public key is already visible onchain," as Gutkin told crypto.news [2], then the type of holder drops out of the model. He said the chain, the address type and the transaction history decide it, whether the owner is an exchange, an institution or an individual [3]. A custodian controls the third of those, and only going forward.

Gutkin's plan is a policy for flows. Address reuse is the part a custodian can stop at once. A spent address keeps its key visible, and every later deposit to it lands behind that key [5]. Fresh deposit and change addresses end the reuse, and tracking each UTXO finds the coins already behind visible keys [7]. "For an institution, I don't think the goal should be a one-time mass migration," he said, answering calls for "bunker mode" preparation [8]. That rules out a single sweep of the whole book. The move happens through payments the institution would make anyway [7].

Address format is the first limit. A fresh address hides its key only if its format does. P2PK outputs, many from the Satoshi era, expose the key from creation even if the coins never move [4]. The BIP 360 authors say Taproot output keys are visible at creation too [6]. BitGo's July 22 controls include updated address defaults [10], so at least one custodian treats the default format as part of the job.

Speed is the second. Exposed addresses empty only as fast as the holder spends from them [7]. Gutkin said a treasury that rarely moves its holdings may keep its keys hidden longer, provided format and past activity have not already revealed them [17]. That same low activity means coins already behind an exposed key leave slowly. BitGo's input selection tries to spend every unspent output tied to a selected address [18], so one payment can clear an address outright.

The third limit is the window between broadcast and confirmation. The BIP 360 authors separate attacks on keys visible for long periods from faster attacks launched after a transaction reveals a key and before it confirms [11]. BIP 360 itself reduces long-term key exposure but does not offer complete protection, according to crypto.news [12].

Ledger CTO Charles Guillemet said in a Sep. 17 report that no cryptographically relevant quantum computer capable of breaking Bitcoin's current signatures is known to exist [13]. He also warned that research, software changes, hardware-wallet upgrades and user adoption could take years [14].

I think the case holds for coins a custodian holds and moves. Fresh addresses and a UTXO ledger cut exposure now, with no protocol change. Fireblocks says it already supports parts of the process and is building exposure-based input selection and displays of affected balances [15]. None of that touches coins behind visible keys whose owners never spend, within an estimated 6.7 million to 7 million exposed BTC [1]. On Ethereum, Fireblocks is working on the signature side instead, and has cut post-quantum signature verification from 8.09 million to 1.23 million gas [16], about 85% less [19].

Gutkin's own dashboard is the test. He said it should show the remaining exposed balance next to the transactions adding to it [9]. Suppose a custodian runs fresh addresses for a year and the first figure stays flat. Then the gradual approach has failed for that book.

What to watch

  • Whether BIP 360 advances, and whether it or a later proposal covers the short window between a transaction revealing a key and its confirmation.
  • Which address type Fireblocks, BitGo and other custodians set as the default for fresh addresses, given that Taproot output keys are visible at creation.
  • Fireblocks' release of exposure-based input selection and exposed-balance displays, and whether any custodian publishes the exposed balance it holds.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence52
Adoption30
Hype gap+10
Incentives65
Confidence48
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Fireblocks' research chief identified exposed public keys as the main factor in Bitcoin's future quantum risk, citing public estimates that roughly 6.7 million to 7 million BTC sit behind keys already visible onchain.

    ReportedSupportedSource: crypto.news, citing Fireblocks' Michael Gutkin and public estimatesView cited source
  2. [2]

    Exposure ultimately comes down to whether the public key is already visible onchain.

    ReportedSupportedSource: Michael Gutkin, Fireblocks VP of Research, told crypto.newsView cited source
  3. [3]

    Gutkin said a holder's exposure depends on the blockchain, address type and transaction history, rather than whether the owner is an exchange, institution or individual.

    ReportedSupportedSource: Michael Gutkin to crypto.newsView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. crypto.news

    1 article · October 9, 2026

    Bitcoin quantum threat: Which wallets face the most risk?

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories