
BitGo detailed four quantum-risk management controls for institutional Bitcoin wallets in a July 22 product announcement, aiming to measure and reduce public-key exposure before quantum attacks become practical.
Summary
- Four new BitGo controls score exposure, consolidate UTXOs, remediate addresses, and adjust wallet defaults automatically.
- Bitcoin public keys become visible after spending, while Taproot outputs expose keys from their creation.
- No practical quantum attack can break Bitcoin today, leaving BitGo’s tools focused on operational preparation.
The tools apply to supported Bitcoin multi-signature wallets. They include a Quantum Risk Score, a guided address-remediation workflow, a new UTXO selection method and updated default address controls. BitGo said the release supports operational preparation and does not replace any future Bitcoin protocol upgrade.
BitGo turns public-key exposure into a wallet metric
For common hashed-key Bitcoin outputs, spending reveals the public key needed to verify the transaction. If coins remain tied to that key through address reuse or a partial spend, they could become targets if a cryptographically relevant quantum computer eventually derives private keys from public keys.
Taproot requires a separate distinction. Its output key is visible when the output is created, rather than only after a later spend. The draft BIP 360 proposal also identifies Pay-to-Public-Key outputs, reused outputs and Taproot outputs as exposed to long-duration attacks under a future quantum scenario.
BitGo’s Quantum Risk Score gives clients an in-platform measure of exposure across supported wallets. However, the company has not published the score’s formula, weighting system or thresholds. It is therefore a company risk-management measure, not an independent Bitcoin security standard.
Four controls change how institutions handle UTXOs
The new UTXO selection method groups coins by address. When a wallet selects one UTXO from an address, it attempts to include every other UTXO associated with that address. The approach is intended to avoid leaving funds behind after a spend exposes the relevant public key.
The Fix Exposed Addresses workflow moves affected funds into newly generated addresses whose public keys have not appeared onchain. Updated defaults are also intended to reduce reliance on address types and transaction patterns that create earlier exposure.
BitGo said Taproot and Pay-to-Public-Key funds require separate remediation because those formats expose public-key information from creation. The company did not identify support for those remediation paths in the current product release.
BitGo quoted Blockstream co-founder Adam Back as saying “nobody has a quantum computer that can touch Bitcoin today.” That assessment means the product addresses a future risk rather than an active method of stealing Bitcoin. It also does not change Bitcoin’s signature system or protect the network by itself.
Bitcoin developers are separately discussing BIP 360, a draft soft-fork proposal for Pay-to-Merkle-Root outputs. The design removes Taproot’s key-path spend and aims to reduce long-exposure attacks. However, its authors say faster attacks against keys revealed while transactions await confirmation may require post-quantum signatures.
BIP 360 remains a draft and has not been activated on Bitcoin. Any network-wide change would still need technical review, implementation, testing and broad adoption across wallets, nodes and other infrastructure.
Onchain data explains the institutional focus
Glassnode estimated in May that 6.04 million BTC, or 30.2% of issued supply, had public-key exposure at rest. It classified 1.92 million BTC as structurally exposed through output design and 4.12 million BTC as operationally exposed through address reuse, partial spending or custody practices.
The research did not claim those coins can be stolen today. Instead, it measured where public keys are already visible and where better wallet management may reduce exposure. Exchange-related balances represented 1.63 million BTC within Glassnode’s operational category.
However, BitGo and Silence Laboratories tested post-quantum signing inside an institutional custody workflow in May. In related coverage, nine companies pledged $15 million over three years to a Bitcoin security consortium that named post-quantum research as its first focus.
BitGo has not disclosed how many clients can access the controls, whether they carry separate fees or when support may expand. Institutions can use the tools to review and move exposed balances, while wider protection will depend on future Bitcoin proposals and adoption.










Leave a Reply