BitGo just added quantum safety tools for Bitcoin custody. 6.9M coins are already exposed.
The quantum threat is still not here, but exposed public keys are already an inventory problem for custodians.

CryptoVibe Desk · bitcoin · custody · quantum

- →BitGo launched quantum-risk controls for institutional Bitcoin custody on July 9, covering exposed addresses, coin selection, and address defaults.
- →The real move is operational: institutions can now find exposed-key Bitcoin before protocol-level post-quantum fixes exist.
- →Watch whether BitGo adds Taproot and Pay-to-Public-Key cleanup this year, because those addresses sit outside the first workflow.
- UTXO → A UTXO is a chunk of Bitcoin that has not been spent yet, like one uncashed bill in your wallet.
- Multi-signature custody → Multi-signature custody requires more than one key to move funds, usually so one lost or stolen key is not enough.
- Public key → A public key is the visible cryptographic identity tied to a wallet key, and some Bitcoin address types reveal it earlier than others.
- Post-quantum signature → A post-quantum signature is a new signing method designed to stay safe against future quantum computers.
BitGo just made quantum risk operational. On July 9, 2026, the custodian launched tools for institutional Bitcoin wallets. The set includes a Quantum Risk Score, a Fix Exposed Addresses Workflow, a new UTXO Selection Method, and updated address defaults.
The stance is simple. This is not panic. It's inventory. BitGo says no quantum computer can break Bitcoin today. For now, the real problem is knowing which coins already sit behind exposed public keys.
According to Bitcoin Magazine, BitGo cited 6.9 million BTC in addresses with exposed public keys. That number is not independently corroborated in the brief, so treat it as a company-cited estimate. Still, the direction matters. A future quantum break would not hit all Bitcoin equally. It would hit coins whose public keys are already visible first.
At the wallet level, BitGo is trying to prevent new cleanup debt. The UTXO Selection Method can avoid spending from riskier outputs when safer ones exist. The default address controls push institutions toward address types that do not reveal public keys until funds move. That is not a protocol fix. It is better hygiene at the custody layer.
If you're running treasury Bitcoin through a custodian, this boring part decides whether your bag becomes an emergency queue later. The tradeoff is workflow friction today for less forced triage tomorrow. Engineers know this pattern. Backups are theoretical until the restore fails.
The catch is scope. BitGo says the tools apply to UTXO-based wallets and its multi-signature custody service. The brief also says Taproot and Pay-to-Public-Key addresses fall outside the current cleanup scope. They reveal public keys from creation, so those wallets need separate handling.
That makes this release useful, but incomplete. It gives institutions a map, a score, and a guided path for some exposed funds. It does not make Bitcoin quantum-safe. BitGo frames the controls as complementary to future post-quantum signature upgrades, and that framing is correct.
Read the mechanism, not the threat headline. Bitcoin does not need a quantum computer to make this work matter. It only needs large holders to realize voluntary cleanup gets harder when everyone waits for the same protocol upgrade window.
BitGo's gap is Taproot and Pay-to-Public-Key. Those addresses expose keys from creation, so leaving them outside the first workflow makes the cleanup map incomplete.
By the end of 2026, watch whether BitGo release notes add Taproot or Pay-to-Public-Key remediation; if they still exclude both, the highest-visibility cleanup remains manual.
Primary links and supporting reads used by the desk for this story.
Forward this.











