Security Hub

6.26 Million Bitcoin Sit in Quantum-Exposed Addresses, Glassnode Says

Published: Oct 9, 2026•By Aleksandar Dukic

Key Analysis

Glassnode estimates roughly 6.26 million BTC hold public keys already visible on-chain, the slice most exposed to a future quantum attack. Here is what that means.

6.26 Million Bitcoin Sit in Quantum-Exposed Addresses, Glassnode Says

Listen To This Article

6.26 Million Bitcoin Sit in Quantum-Exposed Addresses, Glassnode Says

4m 48s audio

AI narration. Useful for scanning on the move. Names and tickers may be mispronounced.

Glassnode estimates that roughly 6.26 million bitcoin sit in addresses with public keys already exposed on-chain, the portion of the supply most vulnerable if a cryptographically relevant quantum computer ever arrives. The figure, shared via WuBlockchain on October 9, 2026, puts a hard number on a risk the Bitcoin community has debated for years without much quantitative grounding.

Bitcoin was trading at $82,361 as of October 9, 2026, down 0.5% over 24 hours, so the report landed on a quiet market day rather than during a sell-off. The point of the research is not a near-term price event. It is a measurement of how much of the network's value sits in a state that a sufficiently powerful quantum machine could, in theory, target first.

The exposure comes from revealed public keys

Bitcoin addresses do not usually show their public key. An address is a hash of the public key, and the key itself only becomes visible on-chain once the address spends funds. That distinction matters for quantum risk. The algorithm that threatens Bitcoin's signatures, Shor's algorithm, works against the elliptic-curve public key, not against the hashed address. An address that has received coins but never spent keeps its public key hidden behind two layers of hashing.

Once an address spends, the public key is permanently on the ledger for anyone to read. Reused addresses, older pay-to-public-key outputs from Bitcoin's earliest years, and any address that has moved funds all fall into the exposed category. Glassnode's 6.26 million figure is a tally of coins currently sitting in that exposed state. Against a circulating supply near 19.9 million, that works out to roughly 30% of all bitcoin, though the exact share shifts as coins move. Treat the percentage as analysis derived from the headline number rather than a figure Glassnode published directly.

No quantum computer can do this today

The threat is prospective, not present. No existing quantum computer comes close to the scale needed to break a 256-bit elliptic-curve key, and credible estimates for when such a machine might exist range from years to decades out, with wide disagreement among researchers. The exposed-coin count is a way to size the problem, not a warning that the coins are at immediate risk.

What makes the number useful is that it sets an upper bound on the cleanup job. If Bitcoin eventually migrates to a quantum-resistant signature scheme, the coins in exposed addresses are the ones that would need to move to new, safe outputs before a working quantum attacker appears. Coins in never-spent addresses enjoy more protection, because an attacker would first have to reverse the address hash before even seeing a public key to attack. The practical migration target, then, is smaller than the full supply but still measured in millions of coins.

Dormant and lost coins complicate the cleanup

A chunk of the exposed total likely belongs to wallets whose owners are gone. Coins tied to lost keys, including early holdings that have not moved in over a decade, cannot be migrated by anyone. Those balances would remain permanently exposed in any future quantum scenario, which is one reason the debate over a forced migration or a freeze of vulnerable coins is contentious. Any such decision touches Bitcoin's core promise that coins cannot be seized or invalidated.

For ordinary holders, the takeaway is narrower and more actionable. Avoiding address reuse keeps a public key hidden until the moment of spending, which shrinks the window of exposure. Self-custody practices that generate a fresh address per transaction already follow this pattern by default. Anyone managing self-custody setups or spending from their own wallet through a card is working within the same model this research describes, where the key only surfaces when funds move.

A measurement, not a deadline

The value of Glassnode's work is that it converts a vague fear into a tracked metric. The 6.26 million figure can be watched over time, rising or falling as coins consolidate, as address reuse changes, and as any future migration progresses. It gives developers debating post-quantum upgrades a concrete sense of scale, and it gives holders a reason to think about address hygiene now rather than after a machine exists. The number is the thing to watch, and today it stands at about 6.26 million coins.

Overview

Glassnode estimates roughly 6.26 million BTC, close to 30% of the circulating supply, sit in addresses with exposed public keys, the slice most vulnerable to a future quantum attack. No quantum computer can exploit this today, and timelines remain uncertain, but the figure sizes the eventual migration problem and highlights why avoiding address reuse reduces exposure.

DisclaimerThis article is provided for informational purposes only and does not constitute financial advice. All fee, limit, and reward data is based on issuer-published documentation as of the date of verification.

Have a question or update?

Discuss this analysis with the community on X.

Discuss on X

Comments

Comments are moderated and may take a moment to appear.