BitGo Launches Bitcoin Quantum Risk Score for Institutions
Blockchain company BitGo has rolled out a set of quantum-risk tools for institutional Bitcoin wallets. The headline feature is a Quantum Risk Score that tells clients which of their addresses have already exposed a public key onchain. Useful, very, but hardly a fix for the quantum problem.
What BitGo announced
The launch adds four things to BitGo’s existing multi-signature custody platform. There’s the Quantum Risk Score, which measures exposure across supported Bitcoin wallets. A guided workflow called Fix Exposed Addresses moves funds out of higher-risk addresses into freshly generated ones. A new coin-selection method groups and prioritizes unspent transaction outputs (UTXOs) by address. And BitGo changed some default wallet behaviors to lean away from address types that reveal key material sooner than necessary.
BitGo filed a provisional patent on the UTXO-grouping method, important because the patent-related method has a hole in it, which I’ll get to.
CEO Mike Belshe put the logic plainly. “We believe the safest key is one whose public key has never been revealed onchain,” he said in the announcement. That single sentence explains the entire product. Bitcoin addresses that haven’t been spent from keep their public key hidden behind a hash. Spend from one, and the public key goes public. A powerful enough quantum machine could, in theory, work backward from an exposed public key to the private key.
So BitGo’s pitch is basic hygiene. Keep public keys hidden, consolidate carefully. Move funds off exposed addresses before it becomes a scramble.
Why the timing looks early on purpose
Nobody can break Bitcoin with a quantum computer today. Adam Back, Blockstream’s CEO, said as much, per a July 9 press release:
“Nobody has a quantum computer that can touch Bitcoin today, but that’s exactly why the work should start now, while it’s calm and optional rather than urgent and forced.”
I agree with the framing. Building migration procedures during a panic is how institutions lose money and make mistakes.
There’s a number worth remembering here. Coinbase’s Independent Advisory Board on Quantum Computing and Blockchain estimated in a June 2026 report that around 7 million BTC sit in addresses already exposed to a future quantum attack. At current prices that’s a staggering pool of value sitting in the open. Most of it belongs to people who reused addresses or spent from them years ago and never cleaned up.
That’s the case for acting now. Custodians holding large balances can’t just wave a wand and migrate later. They need procedures that get audited, repeated, and explained to clients.
How UTXO exposure creates the risk
Bitcoin wallets hold value as unspent transaction outputs. Each UTXO is a chunk of BTC that can be spent in a later transaction. When a client spends part of a balance, the transaction can reveal the public key tied to that address.
The distinction BitGo cares about is between addresses that have never been spent from and addresses where a spend already leaked the key. Reduce the number of exposed public keys and you reduce future quantum risk as you leave the day-to-day custody setup intact.
Here’s the catch that BitGo stated directly, and it’s a real limit. The patent-related coin-selection method doesn’t cover funds held in address types that expose a public key from creation. Taproot and Pay-to-Public-Key (P2PK) addresses reveal key material from the moment they exist. Those need separate remediation. So two institutions holding the same amount of BTC can face very different exposure depending on how their wallets were built and whether addresses got reused.
That’s not a small footnote. Taproot adoption has grown across the ecosystem, and any institution leaning on Taproot addresses gets less protection from this particular tool than the marketing might suggest.
The two versions of BitGo’s “quantum protection”
Reading across the coverage, there’s some genuine confusion about what BitGo actually shipped, and it’s worth clearing up. Most outlets described the risk-scoring and UTXO tools. Crypto Briefing reported something different: a partnership with Silence Laboratories completing a post-quantum MPC transaction simulation using the ML-DSA signature standard (FIPS 204).
These are two separate things. One is a production risk-management feature for existing wallets. The other is a proof-of-concept simulation at the cryptography layer. The scoring tools ship now and work with what institutions already hold. The ML-DSA work is a demonstration that the math runs inside a regulated custodian’s workflow. Both belong to the same strategy, but only one of them is something a client can turn on this quarter.
What I’d do with this
If I ran a treasury with meaningful BTC at a BitGo custody arrangement, here’s my order of operations.
First, run the Quantum Risk Score and get a clear picture of how much of the balance sits in exposed addresses. That report costs nothing to generate and doesn’t require changing custody arrangements, which makes it the obvious first step.
Second, use Fix Exposed Addresses on anything flagged as high-risk, starting with the largest exposed balances. The tool automates work that would otherwise eat analyst hours.
Third, check the wallet’s address-type composition. If a chunk of the holdings sits in Taproot or P2PK addresses, the patent-related UTXO method won’t help, and separate remediation planning has to start there.
The ML-DSA simulation I’d file under “watch, don’t wait for.” The signal to care about is when BitGo moves from simulation to live post-quantum transactions. Until then, it’s a research milestone as opposed to being a product.
The competitive pressure this creates
BitGo is a qualified custodian for a large slice of the institutional market. By shipping named quantum tools first, it puts every rival custodian on the spot. Coinbase, Fidelity Digital Assets, Anchorage, all of them now face the same client question: what’s your quantum plan, and can I see a report?
I think that pressure does more good than the tools themselves in the near term. Quantum risk was easy to deprioritize when no competitor had a product. Now there’s a named feature, a public-key exposure score, and a patent filing to point at. This all reframes quantum-readiness as part of custody due diligence rather than a distant research topic.
Future outlook
Bitcoin’s base layer will eventually need a protocol-level answer, likely a post-quantum signature scheme adopted through a soft fork after years of debate. BitGo said its tools complement that future upgrade rather than replace it, which is the honest position. Wallet hygiene buys time. It doesn’t rewrite the protocol.
My call: the Quantum Risk Score is the piece worth using today, because it’s free to run and shows exactly where an institution stands. The UTXO method helps if the wallet composition suits it, and does nothing if the funds sit in Taproot. The ML-DSA partnership is the more interesting long-term bet, but it’s a demo for now. Institutions holding large BTC balances should generate their exposure report this quarter and remediate the biggest exposed positions before any migration pressure arrives. Waiting for the quantum machine to show up is the one plan guaranteed to fail.