#reusedbitcoinaddresseshold4.33mbtc
Nearly a third of all Bitcoin has a visible public key on-chain today, and most of it got there through ordinary address reuse, not a flaw in Bitcoin itself.
Glassnode co-founder Rafael Schultze-Kraft published new on-chain data on October 8 showing that $BTC exposure to a future quantum attack is larger than previously mapped. No hack has occurred. This is a measurement of theoretical future risk, not a present vulnerability.
KEY FACTS
▪️ 4.33 million BTC (21.5% of circulating supply) sit in reused addresses, a figure up 14% recently.
▪️ Combined with structurally exposed coins, 6.26 million BTC (31.2% of total supply) now hold visible public keys on-chain.
▪️ Structural exposure adds 1.94 million BTC, spanning legacy Pay-to-Public-Key (P2PK) outputs, bare multisignature outputs, and modern Taproot outputs - Taproot addresses reveal their public key by design, so "newer" doesn't automatically mean "hidden."
▪️ About 1.10 million BTC in P2PK outputs are linked to Satoshi Nakamoto's early wallets, which cannot be migrated unless whoever controls those keys moves them.
▪️ Exchanges hold roughly 1.79 million BTC under exposed keys, representing 57% of all exchange-held Bitcoin, according to Glassnode's breakdown.
HOW ADDRESS EXPOSURE ACTUALLY WORKS
A Bitcoin address normally shows only a hashed version of its public key, not the key itself. Spending from that address reveals the real public key on-chain. If the same address receives funds again afterward, that new balance sits behind an already-exposed key. That's the "address reuse" problem: it's entirely avoidable, since generating a fresh address costs nothing, but a large and growing share of holders aren't doing it.
IS ANYTHING AT RISK RIGHT NOW?
No. Deriving a private key from an exposed public key requires a cryptographically relevant quantum computer, and nothing close to that capability exists today. Visible public keys are a normal, designed part of Bitcoin's cryptography and don't by themselves compromise funds. Glassnode's data doesn't predict a timeline for when, or if, that threat becomes real - it's mapping which coins would need to move first if a credible timeline ever emerges.
WHAT TO BE CAUTIOUS OF
▪️ Don't reuse addresses. This is the one piece of advice that holds regardless of how the quantum debate plays out, and it's free.
▪️ Don't assume a "new" address type is automatically safe. Taproot is widely recommended for other reasons, but it still exposes the public key.
▪️ Watch exchange custody practices. With 57% of exchange-held BTC sitting under exposed keys, this is a meaningful concentration point, separate from any individual user's habits.
▪️ Be skeptical of panic-driven content. Any post implying coins can be stolen today, or giving a specific "doom date," is overstating what this data shows.
▪️ Satoshi-linked coins (1.10M BTC) are a unique case. They can't be migrated by community action alone, which is a real, unresolved structural question for Bitcoin's long-term security design.
WHAT TO WATCH
▪️ Further quantum hardware milestones and how they compare against real-world Bitcoin address exposure
▪️ Any movement toward Bitcoin post-quantum proposals (BIP-360, BIP-361) gaining developer consensus
▪️ Whether exchanges begin proactively migrating exposed reserves to fresh, unspent addresses
▪️ Whether large reused-address balances start moving, which would itself be a notable on-chain signal
BOTTOM LINE
This is a real and growing figure & threat worth tracking, not a crisis. The near-term, practical takeaway is simple and doesn't require a quantum computer to matter: stop reusing addresses.
Does this change how you think about holding BTC long-term, or is the quantum threat still too distant to factor into today's decisions? Share your view below.
Sources: Glassnode (Rafael Schultze-Kraft, Oct. 8), TheDefiant, Bloomingbit, Phemex, CryptoNews.
Not financial advice. Always DYOR.
Follow for Daily Trade Analytics & Insider News . @MistralAK
