>_ Skip to main content
Menu
Search
Post-Quantum Security

BitGo Adds Four Quantum Controls to Institutional Bitcoin Wallets

BitGo shipped four quantum-risk controls for institutional Bitcoin wallets. The tools measure how much of a client’s Bitcoin sits behind a visible public key and give custodians a way to move those funds before any quantum computer can act on them. BitGo says the release is operational preparation and doesn’t replace a future protocol upgrade.

How BitGo’s quantum risk controls work

According to the company’s July 22 announcement, the controls apply to supported Bitcoin multi-signature wallets. There’s a Quantum Risk Score that scores exposure inside the platform, a guided workflow that moves at-risk funds to fresh addresses, a new method for picking which coins a wallet spends, and updated default address settings. They work as one layer with an aim to shrink the number of public keys a client has already revealed onchain.

Here’s the mechanics behind it: spending a coin reveals its public key, because the network needs that key to verify the transaction. If funds stay tied to the same address afterward, through reuse or a partial spend, they now sit behind a key anyone can see. BitGo’s new coin-selection method groups outputs by address and tries to pull in every coin at that address when it spends one, so nothing gets stranded behind an exposed key. The Fix Exposed Addresses workflow moves affected funds into freshly generated addresses whose keys have never appeared onchain.

BitGo was blunt about the timing. The company quoted Blockstream co-founder Adam Back, who said, “nobody has a quantum computer that can touch Bitcoin today.” So the controls address a future risk, not an active theft method. They reduce exposed public keys. They don’t change Bitcoin’s signature system, and they don’t protect the network on their own.

What the new controls don’t solve

The Quantum Risk Score has a real limitation. BitGo hasn’t published its formula, weighting, or thresholds, so it’s a proprietary metric rather than an independent security standard. Clients relying on it are trusting a methodology they can’t inspect.

Two output types fall outside the current release. Taproot outputs expose their key from the moment they’re created, and Pay-to-Public-Key outputs carry the same problem. BitGo says both need separate remediation and hasn’t confirmed support for those paths yet. Given how much institutional money now sits in Taproot, that’s a meaningful hole. The company also hasn’t disclosed how many clients can reach the controls, whether they carry fees, or when coverage might expand.

The scale of the concern comes from onchain data. Glassnode estimated in May that 6.04 million BTC, about 30.2% of issued supply, had public-key exposure at rest, splitting that into 1.92 million BTC exposed through output design and 4.12 million BTC through reuse, partial spends, or custody habits. The firm added a caveat: this doesn’t mean those coins can be stolen today. At the protocol level, developers are working through BIP-360, a draft soft-fork proposal aimed at long-duration quantum exposure. It remains a draft and hasn’t been activated on Bitcoin, so any fix there is years of review, testing, and adoption away.