Blockchain analytics firm Glassnode has published a report estimating that approximately 6.04 million Bitcoin (about 30% of circulating supply) are potentially vulnerable to quantum computing attacks. The study divides the risk into two categories: structural risk and operational risk, highlighting stark differences in exposure across major exchanges.
Structural Risk: 1.92M BTC Locked in Legacy Addresses
Structural risk covers 1.92 million BTC (9.6% of total supply), dominated by early "Satoshi-era" addresses using Pay-to-Public-Key (P2PK) outputs. These addresses expose their public keys directly on the blockchain even when untouched. The category also includes outdated multi-signature structures and certain Taproot addresses where public keys may become visible under some conditions. Glassnode notes that many Satoshi-era coins may be lost or abandoned, permanently locked in vulnerable states with no way to migrate to newer, safer address types.
Operational Risk: 4.12M BTC at Stake from Address Management
Operational risk accounts for 4.12 million BTC, stemming from user behaviors like address reuse or key exposure during transactions. Such practices increase traceability and raise susceptibility to potential quantum attacks. Of these, roughly 1.66 million BTC (8.3% of all BTC) are held in exchange wallets, representing about 40% of the operationally vulnerable class.
Exchange Risk Gradient: Coinbase Lowest, Bitfinex Fully Exposed
Glassnode’s data reveals a striking disparity among top exchanges. Coinbase has only 5% of its Bitcoin holdings flagged as at risk; Binance shows 85% vulnerable; and Bitfinex has 100% of its holdings classified under operational risk. Government-held Bitcoin tells a different story: reserves of the United States, the United Kingdom, and El Salvador show zero addresses exposed to quantum risk, and state reserves have maintained over 99% operational security for years.
Address Management Trends Reversible, No Immediate Threat
In 2018, about 55% of exchange-held BTC was stored in operationally secure addresses; that share has since dropped to 45%. The report states: “Public keys exposed on the blockchain are a potential foundation for long-term quantum attack vulnerability. These risks can be greatly reduced with improved address management. However, there is currently no evidence of an urgent threat.” Regular address rotation and careful management of spending outputs can significantly lower the risk profile.
Overall, the findings underscore the importance of diligent address management for Bitcoin holders. Avoiding address reuse and adopting newer security standards could help crypto assets become more resilient against future quantum challenges.

