
Fireblocks’ research chief has identified exposed public keys as the main factor in Bitcoin’s future quantum risk, citing public estimates that roughly 6.7 million to 7 million BTC sit behind keys already visible onchain.
Summary
- Older Bitcoin outputs and reused addresses can leave funds behind public keys that are already exposed.
- Fireblocks recommends fresh deposit and change addresses, with continuous tracking of exposed balances.
- Bitcoin’s BIP 360 proposal reduces long-term key exposure but does not provide complete quantum protection.
- Fireblocks has cut Ethereum post-quantum signature verification from 8.09 million to 1.23 million gas.
Fireblocks Vice President of Research Michael Gutkin told crypto.news that a holder’s exposure depends on the blockchain, address type, and transaction history, rather than whether the owner is an exchange, institution, or individual.
“Exposure ultimately comes down to whether the public key is already visible onchain.”
In Gutkin’s assessment, frequent transactions can create exposure through address reuse and the handling of unspent Bitcoin. A treasury that rarely moves its holdings may keep public keys hidden for longer, he said, but only if the address format and previous activity have not already revealed them.
Bitcoin’s older outputs and reused addresses expose keys
For early Bitcoin outputs known as pay-to-public-key, or P2PK, Gutkin explained that the public key is visible from the start. Many outputs dating to the Satoshi era use that format, leaving their keys exposed even when the coins have never moved, he said.
By comparison, Gutkin said pay-to-public-key-hash and native SegWit addresses, known as P2PKH and P2WPKH, hide the public key until the first spend. Once a holder spends from an address, however, the key becomes permanently visible, according to his explanation.
If the same address receives more Bitcoin afterward, Gutkin said those new funds sit behind a key that has already been revealed. For holders checking their exposure, he recommended examining whether addresses have spent before and whether they continue receiving funds.
Taproot introduces another distinction. The authors of BIP 360 identify Taproot outputs as exposed to long-duration quantum attacks because their output public keys are visible when created.
According to the proposal, a sufficiently capable quantum computer could derive a private key from an exposed public key. Its authors distinguish attacks against keys visible for long periods from faster attacks attempted after a transaction reveals a key but before it confirms.
The concern remains a future threat. In a Sep. 17 report on Bitcoin’s migration challenges, Ledger Chief Technology Officer Charles Guillemet said no cryptographically relevant quantum computer capable of breaking Bitcoin’s current signatures was known to exist.
Guillemet nevertheless warned that research, software changes, hardware-wallet upgrades and user adoption could take years, making preparation a separate issue from the arrival of a working attacker.
Gradual wallet changes can reduce Bitcoin exposure
Responding to calls for “bunker mode” preparation, Gutkin argued that institutions should manage public-key exposure continuously rather than plan a single mass transfer.
“For an institution, I don’t think the goal should be a one-time mass migration,” he said.
Under his proposed approach, new Bitcoin deposits would go to fresh addresses, while change from transactions would also return to fresh addresses. Gutkin said institutions should track individual unspent transaction outputs, or UTXOs, to identify which funds already sit behind exposed keys.
Through normal spending, Gutkin explained, exposed addresses could gradually empty while new funds arrive at addresses whose public keys remain hidden. He said a live exposure dashboard should show both the remaining exposed balance and the transactions creating additional exposure.
Fireblocks already supports several components of that process, according to Gutkin, and is developing tools for selecting transaction inputs based on exposure and displaying affected balances.
Other custody providers have introduced related controls. In its July 22 announcement, BitGo detailed four Bitcoin wallet controls covering exposure scoring, address remediation, transaction-input selection, and updated address defaults.
BitGo said its input-selection method attempts to spend all unspent outputs associated with a selected address, reducing the chance of leaving funds behind after a transaction reveals the key. The company described the controls as operational preparation rather than a replacement for a future Bitcoin upgrade.
For a rushed migration, Gutkin warned that large holders competing for limited Bitcoin transaction capacity could drive fees higher and slow confirmations. Within institutions, he said, additional transactions and approvals could increase mistakes, including sending change back to an exposed address.
To limit phishing and handling errors, Gutkin recommended establishing destination addresses, approval policies and trusted communication channels in advance. He said an urgent transfer should not require customers or staff to follow unfamiliar instructions or bypass existing controls.
Bitcoin still needs a quantum-resistant spending method
Even with better address practices, Gutkin said Bitcoin would still need a quantum-resistant method for authorizing transactions.
In his explanation, BIP 360 addresses one part of the problem by proposing pay-to-Merkle-root outputs, which remove Taproot’s exposed key-spending path. Gutkin stressed that reducing long-term public-key exposure does not make the proposal a complete post-quantum solution.
The proposal’s authors likewise state that protection against attacks during the brief period before a transaction confirms may require post-quantum signatures. BIP 360 remains listed as a draft.
Unlike Ethereum, Gutkin said Bitcoin cannot simply accept a new signature-verification contract through a general-purpose application layer. Depending on the chosen design, he explained, protocol changes may be necessary to support the scheme and keep transaction fees manageable.
Gutkin also pointed to research into hash-based signatures, including designs that track signing state to reduce overhead. Such approaches involve trade-offs in signature size, wallet design and recordkeeping, he said.
For U.S. investors holding Bitcoin through funds, custody arrangements are also part of the preparation. A Sep. 23 report on Coinbase’s post-quantum custody plans noted that spot Bitcoin and Ethereum ETF investors do not control the private keys securing fund holdings; the issuers’ selected custodians manage them.
In that report, Coinbase Chief Cryptographer Yehuda Lindell described plans for custody infrastructure capable of supporting different post-quantum signature schemes. Lindell said Coinbase was exploring programmable hardware security modules as an alternative when a blockchain’s chosen scheme cannot work with its existing distributed-signing systems.
Ethereum’s cheaper verification still requires wallet changes
On Ethereum, Gutkin said standard accounts expose their public keys once they sign a transaction because the key can be recovered from the signature. Unlike Bitcoin address rotation, he explained, regularly replacing an Ethereum account is less practical because balances, token approvals and application activity are tied to it.
For Solana’s standard wallets, Gutkin noted that the address is the public key itself, so the key is exposed without any initial spending transaction.
Programmable Ethereum accounts offer a way to change transaction authorization while retaining the account, according to Gutkin. Fireblocks’ research has reduced verification of ML-DSA-44, a post-quantum signature scheme, from 8.09 million gas to 1.23 million gas.
In a Sep. 2 research post, Fireblocks reported that the verifier follows FIPS 204, the digital-signature standard published by the U.S. National Institute of Standards and Technology. Gutkin said the team improved the implementation rather than changing the standardized algorithm.
Among the changes, Gutkin identified more efficient hashing, mathematical operations, signature decoding, public-key handling, and memory use. Peak memory consumption fell from nearly a megabyte to about 41 kilobytes, he said.
The design still carries costs. Gutkin put the one-time deployment cost for the expanded public key at roughly 4.1 million gas, alongside the 1.23 million gas required for each verification.
For a treasury or cold wallet making relatively few transactions, Gutkin said those costs may be reasonable. He cautioned that a standard Ethereum account cannot simply switch to ML-DSA, while smart-account integration, custody support and compatibility with decentralized applications still require engineering work.
Gutkin also said the verifier does not make Ethereum’s entire system post-quantum secure, with separate research continuing at its consensus and data layers.
Despite extensive testing and formal verification, Gutkin said Fireblocks’ implementation remains research code requiring audits and hardening before production use. For institutional custody, he added, the company is separately researching production-grade post-quantum signing systems.


