Key Highlights:
- More than 6 million Bitcoin—accounting for 31.2% of the circulating supply—currently sit behind exposed public keys onchain.
- Major platforms display vastly different exposure rates: Binance holds 83% of its Bitcoin behind visible public keys, while Coinbase sits at 10% and Fidelity at just 2%.
- The vulnerability risk has intensified following warnings from Ethereum researcher Justin Drake regarding artificial intelligence potentially cracking cryptography faster than expected.
Over 6 Million Bitcoin Exposed to Onchain Public Key Vulnerabilities
More than 6 million bitcoin sit behind public keys that are already visible onchain, underscoring the massive scale of digital assets that could be jeopardized if future breakthroughs in artificial intelligence or quantum computing manage to crack Bitcoin’s underlying cryptographic defenses. According to data provided by analytics firm Glassnode, this exposed cache accounts for 31.2% of the circulating Bitcoin supply, marking an increase of roughly 5% to 6% above the low point recorded in 2023.
Glassnode co-founder Rafael Schultze-Kraft noted that the exposed supply has expanded by 222,000 BTC—valued at approximately $18.2 billion—since the analytics provider published its May report. Over that identical timeframe, the total supply of Bitcoin grew by only 64,000 BTC, indicating that public key exposure is outpacing the pace of asset issuance.
Discrepancies in Institutional and Exchange Custody Practices
Centralized cryptocurrency exchanges are a primary driver behind the surge, representing 123,000 BTC of the recent increase. In total, exchanges now hold approximately 1.79 million BTC behind exposed public keys. However, custody methodologies and exposure levels vary drastically across leading trading venues. For instance, Coinbase maintains an exposed share of only 10%, whereas rival exchange Binance has an exposure rate of 83%.
Similar disparities exist among traditional financial institutions, retail brokerages, and sovereign holders. Fidelity holds roughly 375,000 BTC with an exposure rate of merely 2%. In stark contrast, Grayscale’s exposed balance sits at 49%, Revolut’s at 99%, and Robinhood shows 100% exposure under the tracked metrics. On the sovereign side, national reserves—including holdings by the United States, the United Kingdom, and El Salvador governments—register zero exposure under the Glassnode methodology.
Mechanisms Behind Public Key Exposure
Public keys typically become visible on the blockchain through address reuse or via specific transaction scripts, such as early pay-to-public-key (P2PK) outputs and Taproot. Under normal conditions, Bitcoin addresses are derived from cryptographic hashes of the public key, keeping the raw public key hidden until a spending transaction is published. However, once a public key is exposed, a sufficiently powerful quantum computer or an unexpected mathematical exploit could theoretically allow a bad actor to reverse-engineer and derive the corresponding private key to drain the wallet.
Why This Matters
The findings arrive during a period of mounting scrutiny regarding the timeline and resilience of modern cryptographic standards against emerging technologies. The urgency of the issue was highlighted by Ethereum researcher Justin Drake, who recently urged the digital asset industry to prepare for bunker mode.
Drake warned that artificial intelligence could theoretically discover an algorithmic shortcut to compromising wallet cryptography in months, not years
under a worst-case scenario, potentially breaching existing security measures long before fault-tolerant quantum computers are fully realized.
Frequently Asked Questions
Why are public keys exposed on the Bitcoin blockchain?
Public keys become visible primarily through the practice of address reuse or when using specific transaction output types. In particular, early Bitcoin transactions utilizing pay-to-public-key (P2PK) scripts as well as Taproot outputs expose the public key directly onchain, unlike standard single-use hashed addresses.
What is the risk of an exposed public key?
Under standard elliptic curve cryptography (ECDSA), deriving a private key from an exposed public key is mathematically infeasible with classical computers. However, if advanced quantum computing or rapid AI-driven mathematical breakthroughs occur, attackers could theoretically derive the private key from the visible public key and steal the associated funds.
Which major holders show the highest and lowest exposure levels?
Custodians and exchanges show significant divergence in exposure: Robinhood (100%), Revolut (99%), and Binance (83%) report high public key exposure, whereas Fidelity (2%), Coinbase (10%), and sovereign holdings from the U.S., U.K., and El Salvador show minimal to zero exposure.




