Over $500B in Bitcoin Has Publicly Visible Keys: Glassnode

Understanding Bitcoin Address Exposure
Imagine putting your money inside a clear glass box versus a heavy steel safe. Both might be locked with a strong combination, but anyone walking past the glass box can peek inside and see the exact lock mechanism. That is essentially what is happening with over $500 billion worth of Bitcoin today.
According to new data from on-chain analytics firm Glassnode, more than 6.26 million Bitcoins currently reside in blockchain addresses where the public key is plainly visible to anyone inspecting the ledger. That represents roughly 31.2% of the entire circulating supply of Bitcoin.
While this situation does not mean these coins are immediately vulnerable to theft today, it has sparked widespread discussion across the crypto community. The conversation comes at a time when researchers are closely analyzing how emerging technologies, including artificial intelligence and quantum computing, might interact with classical encryption algorithms over the coming years.
What Did the Glassnode Report Uncover?
On October 9, 2026, Glassnode co-founder Rafael Schultze-Kraft shared findings detailing the steady rise of exposed Bitcoin public keys. The total count has climbed significantly over the past few years, returning to exposure levels last seen around 2016.
- Circulating Supply Affected: 6.26 million BTCBTC-0.74% (31.2% of total supply) currently sits in addresses with exposed public keys.
- Recent Growth: This figure is up from 24.8% in early 2021. Just five months prior, in May 2026, Glassnode tracked 6.04 million BTC (30.2%), meaning about 220,000 additional Bitcoins joined the exposed category in under five months.
- Exchange Exposure: Roughly 1.79 million BTC held on centralized exchanges has exposed public keys, representing about 57% of all identified exchange holdings.
- Address Reuse Impact: Simple address reuse accounts for 4.33 million BTC of the total exposed supply.
To put these numbers into context, digital asset holdings fluctuate in market value continuously, and past performance of digital assets is not a guarantee of future performance. However, the raw coin volume shows a clear structural trend toward higher public key visibility on the blockchain.
How Bitcoin Key Protection Works in Simple Terms
To understand why public key exposure matters, it helps to review how Bitcoin addresses are generated. Think of Bitcoin cryptography as having three distinct layers:
- The Private Key: This is like your secret master password. It grants full control to sign transactions and spend your coins. It must never be shared with anyone.
- The Public Key: This is derived mathematically from your private key. It acts like an account identifier. In original cryptography, knowing the public key allows someone to verify that a transaction signature was created by the matching private key.
- The Bitcoin Address (The Hash): To add an extra layer of defense, Bitcoin usually runs the public key through mathematical hash functions (like SHA-256 and RIPEMD-160). This creates a shortened address that hides the original public key completely.
When you send Bitcoin out of an address for the very first time, your wallet must broadcast your public key to the network so miners can verify your authorization. Once that transaction is complete, the public key for that specific address is permanently visible on the public blockchain ledger.
If you never spend from an address, your public key remains hidden inside its cryptographic hash. But if you spend partial funds and leave the rest in the same address, or receive new funds at that old address, your remaining coins sit in a location where the public key is fully exposed.
Where Is the Exposure Coming From?
Glassnode broke down the 6.26 million exposed Bitcoins into three main operational causes: address reuse, native script design choices, and centralized exchange wallet architecture.
1. Address Reuse (4.33 Million BTC)
The largest contributor to key exposure is address reuse, accounting for 4.33 million BTC—or roughly 21.5% of all circulating Bitcoin. This occurs when a user receives new funds at a Bitcoin address that has already been used to send outbound transactions in the past.
Over the past year alone, the balance of coins sitting in reused addresses grew from 3.79 million BTC to 4.33 million BTC. Most modern wallet software automatically generates a fresh address for every new receiving transaction precisely to prevent this issue, but manual transfers and older wallet setups still cause address reuse to happen frequently.
2. Script Types and Legacy Formats (1.94 Million BTC)
The remaining exposed balance stems from specific technical transaction formats used on the Bitcoin network:
- Pay-to-Public-Key (P2PK): This early Bitcoin script format accounts for 1.71 million BTC. By original protocol design, P2PK outputs display the public key directly on the blockchain without hashing it first. Notably, around 1.10 million BTC of this total is attributed to early holdings associated with Satoshi Nakamoto.
- Taproot Outputs: Approximately 222,000 BTC sits in Taproot outputs. Introduced in the 2021 soft fork upgrade, Taproot addresses reveal a public key by default as part of their advanced smart-contract and privacy architecture.
3. Centralized Crypto Exchange Storage
Centralized crypto exchanges handle millions of user deposits and withdrawals daily, making address management complex. Glassnode noted that about 1.79 million BTC stored across exchange infrastructure has exposed public keys, representing roughly 57% of all identified exchange balances.
Interestingly, management practices vary widely depending on the exchange venue. According to Glassnode's analysis, Coinbase maintained only about 5% exposed balances across its identified wallets, whereas Binance showed roughly 85% exposure, and Bitfinex reached 100% exposure due to their respective wallet management and address sweeping protocols.
Why Is Key Exposure Generating Attention Now?
Under standard conditions today, knowing a public key does not allow anyone to steal funds. Elliptic Curve Digital Signature Algorithm (ECDSA) encryption remains secure against conventional computing power. Reversing a public key back into a private key would take standard supercomputers billions of years.
However, recent discussions among cryptography researchers have heightened interest in long-term key safety. EthereumETH-2.70% Foundation researcher Justin Drake recently suggested a potential worst-case scenario where advancements in AI-accelerated mathematical solver algorithms could theoretically compress decryption timelines much faster than previously assumed.
Additionally, international authorities such as Europol have issued advisories regarding long-term quantum computing risks, urging technological sectors to prepare for post-quantum cryptographic standards in the coming decades.
Should Bitcoin Holders Move Their Coins Immediately?
Despite the theoretical discussions surrounding public key visibility, industry leaders urge users not to panic or rush into hasty wallet maneuvers.
Ethereum co-founder Vitalik Buterin addressed the situation directly, advising crypto holders against making panicked token transfers without proper preparation.
"It is very easy to lose funds from a misconfigured rushed upgrade. I personally have lost more money in botched migrations than I have lost in all hacks."
Buterin emphasized that while research into advanced cryptography and AI risks should be taken seriously by protocol developers, self-custody users face far greater immediate risk from making user errors during rushed wallet transfers than from cryptographic attacks.
Similarly, BitMEX co-founder Arthur Hayes categorized the recent public key and AI decryption concerns as typical market anxiety, placing it alongside historical market events such as the 2017 block size debates, the 2020 economic uncertainties, and the 2023 FTX collapse.
US Government Wallet Activity Continues
In separate on-chain news highlighted alongside the Glassnode metrics, large-scale administrative transfers continue to occur across institutional and government wallets. Federal agency wallets recently initiated transfers involving over $1 billion in Bitcoin and $94 million in TetherUSDT-0.39%, following prior multi-day movements totaling $770 million in digital assets.
These routine institutional wallet consolidations demonstrate how ongoing blockchain activity constantly moves large volumes of coins across existing network addresses.
Practical Steps for Basic Crypto Security
For everyday cryptocurrency users, maintaining clean wallet habits remains the best defense against privacy leaks and potential future cryptographic risks. Simple best practices include:
- Avoid Reusing Addresses: Use modern wallet software (Hierarchical Deterministic or HD wallets) that automatically generates a new receiving address for every transaction.
- Avoid Spending Partial Balances from Storage Wallets: If you need to send funds from a cold wallet, transfer the entire balance or let your wallet automatically send the remaining change to a fresh, unexposed address.
- Double-Check Transfer Steps: Always verify destination addresses carefully and test small amounts before completing major wallet migrations.
- Stay Informed, Not Impulsive: Protocol updates and post-quantum security enhancements are active areas of development across major blockchain communities.
Digital asset investments involve inherent market volatility and risk. Understanding how your wallet manages public and private keys helps ensure your assets remain safe, private, and under your full control.
Latest blog posts

Bitcoin Below $81K Sparks $1.1B in Market Liquidations
Bitcoin slipped below $81,000, triggering $1.1B in liquidations as speculators transferred 55,000 BTC to exchanges at a loss.

XT Exchange at Eight: Raising Standards for Service
At XT Exchange's eighth anniversary event, Key Accounts head Lily explained how experienced traders are driving higher standards for customer service and platform transparency.

XRP Ledger Activates Major Security Upgrade for Institutions
The XRP Ledger has activated Permission Delegation V1_1, allowing large accounts to delegate daily wallet tasks while keeping master keys offline.