According to BlockBeats, Glassnode co-founder Rafael said on Oct. 9 that about 6.26 million BTC currently have public keys exposed on-chain, equal to 31.2% of Bitcoin’s total supply.
He said that if those coins were to be moved to addresses where the public key has not been revealed and only the hash identifies the address, at least the same amount of BTC would need to be transferred. The share has climbed from 24.8% in early 2021 to the current level, returning to roughly where it stood around 2016.
Two main sources of public key exposure
Roughly 4.33 million BTC have exposed public keys because of address reuse, according to Rafael. Those addresses had previously made outgoing transactions, and moving the coins to new addresses would remove that type of exposure.
Another 1.94 million BTC are exposed because of script type. Of that amount, 1.71 million BTC are in P2PK addresses, including about 1.1 million BTC attributed to Satoshi Nakamoto. A further 222,000 BTC are held in Taproot addresses.
Exchange and institutional holdings
Among exchange-held Bitcoin, about 1.79 million BTC correspond to exposed public keys. Exposure ratios vary sharply by platform: Coinbase stands at 10%, while Bitfinex is at 100%. Among the 15 largest platforms by Bitcoin holdings, seven have ratios above 99%.
For other institutions, Fidelity holds 375,000 BTC, with about 2% showing public key exposure. Bitcoin held by the governments of the United States, the United Kingdom, and El Salvador is listed at 0%. The ratio is 49% for Grayscale, 99% for Revolut, and 100% for Robinhood.
Change since May
Compared with data released in May this year, the amount of Bitcoin with exposed public keys increased by 222,000 BTC, while total Bitcoin supply rose by only 64,000 BTC over the same period. Exchange holdings contributed 123,000 BTC of that increase.
At present, about 57% of Bitcoin held by exchanges has exposed public keys, up from 55% in May this year and 39% in early 2021.
Rafael said the ratios reflect address usage patterns. They are not a risk ranking for the platforms or assets involved, and they do not represent a security assessment.

