Coinbase quantum workshop reveals Bitcoin exchange risks and mitigation strategies
In brief
- Coinbase convened developers, cryptographers, and custodians September 9 to discuss quantum risks to Bitcoin
- 1.6 million BTC in exchange outputs have visible public keys vulnerable to quantum attacks
- Exchanges can reduce exposure through address hygiene, key rotation, and reserve management
The quantum threat to Bitcoin's signature model
Shor's algorithm running on a sufficiently capable quantum computer could break Bitcoin's signature assumption. This risk isn't immediate — Coinbase called it non-immediate — but it divides into two exposure windows. An at-rest attack would target public keys already visible on-chain. A short-exposure attack would target keys revealed only in the mempool during a transaction.
Approximately 1.6 million BTC were in exchange-related outputs with visible public keys on-chain according to May Glassnode data. Broader still, Glassnode estimated that 6.04 million BTC, or 30.2% of issued supply, had public-key exposure at rest in May. That exposure breaks into two categories: structural (where the output type reveals a key by design) and operational (from address reuse or poor key hygiene).
Where exposure concentrates
Glassnode classified 1.92 million BTC as structurally exposed because the output type reveals a key by design. The remaining quantum-exposed balance stems from behavior. Glassnode attributed 4.12 million BTC to operational behavior such as address reuse or leaving a balance after a spend revealed a key.
Exchange-related balances represented the largest labeled part of operationally exposed Bitcoin. This matters because exchanges have leverage that dormant holders don't. Coinbase-attributed balances showed 5% quantum exposure under Glassnode's methodology, while several peers showed much higher shares. Custody scale alone did not determine quantum exposure levels.
Operational tools to reduce exposure
Exchanges have active control tools that dormant holders lack to reduce quantum exposure. Three levers stand out. Exchanges can reduce quantum exposure through address hygiene, change-output rotation and reserve management before Bitcoin adopts a post-quantum signature scheme.
Address hygiene means avoiding key reuse. Change-output rotation means rotating keys that appear in transaction change. Reserve management means cycling capital through fresh addresses. These aren't novel practices — they're already part of institutional custody playbooks.
The September workshop didn't resolve how Bitcoin itself will migrate to quantum-resistant signatures. Participants reached no consensus on an exact post-quantum approach and identified open tradeoffs involving transaction size, hardware performance, key management and adoption. But the session clarified that signature choices and operational migration must advance together. Exchanges that tighten key hygiene now won't face a cliff when the network upgrade arrives.


