Over 6 million bitcoin sit behind exposed public keys as AI warnings mount
Glassnode co-founder's latest figures show growing public-key exposure as Justin Drake urges preparations for potential AI attacks on wallet cryptography.
More than 6 million bitcoin BTC$83,083.10 sit behind public keys already visible onchain, highlighting the scale of holdings potentially exposed if advances in AI or quantum computing undermine Bitcoin’s cryptography.
Those coins represent 31.2% of circulating supply, roughly 5 to 6% above the low reached in 2023, according to Glassnode data.
Glassnode co-founder Rafael Schultze-Kraft said exposed supply has increased by 222,000 BTC ($18.2 billion) since the firm’s May report, while total bitcoin supply grew by just 64,000 BTC.
Exchanges accounted for 123,000 BTC of that increase and now hold 1.79 million BTC behind visible public keys.
The proportions vary considerably. Coinbase’s exposed share stands at 10%, compared with 83% at Binance.
Beyond exchanges, Fidelity holds approximately 375,000 BTC with just 2% exposed. Grayscale’s share is 49%, Revolut’s 99% and Robinhood’s 100%. U.S., U.K. and El Salvador government holdings show no exposure under this methodology.
Public keys can become visible through address reuse or appear directly in certain bitcoin output types, including early pay-to-public-key outputs and Taproot. A sufficiently capable quantum computer, or a hypothetical mathematical breakthrough could potentially allow an attacker to derive the corresponding private keys.
The update comes amid warnings from Ethereum researcher Justin Drake, who urged the industry to prepare for “bunker mode.” Drake argued that AI could potentially uncover a shortcut to breaking wallet cryptography “in months, not years” in a worst-case scenario, before quantum computers arrive.
As stablecoins move into regulated finance, APAC is becoming a key proving ground. This report maps the region’s rules, use cases, and RLUSD’s role.
Asanat Analysis — Why it matters
The exposure of 6M BTC behind public keys represents a structural vulnerability in Bitcoin's security model that has existed since its inception but is gaining urgency as quantum-capable AI systems approach. Once a private key holder broadcasts a transaction, their public key becomes visible on-chain—a necessary step in ECDSA validation. Traditional post-quantum migration windows (like Bitcoin's potential Taproot upgrade to hide public keys by default) suddenly feel less theoretical when credible researchers flag accelerating AI capabilities. This isn't a Bitcoin-specific flaw; it affects all ECDSA-based systems (Ethereum, Solana, etc.).
The signal matters more than the number itself. Glassnode publishing these figures and Drake's coordinated messaging suggests the cryptographic community is shifting from academic concern to practical preparation mode. This mirrors pre-Y2K infrastructure audits—manageable if started now, catastrophic if delayed. The real second-order effect: institutions holding large custody positions may begin pressure on developers to implement quantum-resistant standards sooner than planned. Bitcoin's governance already moves slowly; a market-driven race toward post-quantum signatures could fragment liquidity or create painful migration incentives.