BitGo has announced four new features for institutional Bitcoin wallets, focusing not on responding to existing attacks, but on proactively managing the risks of public key exposure that quantum computing may bring. The company states that these tools are applicable to its supported Bitcoin multisignature wallets and are used to identify, organize, and migrate wallet balances that have been exposed to risk.
Most Bitcoin addresses do not reveal their public keys before their first expenditure, but once a expenditure occurs, the public key required to verify the transaction appears on the blockchain. If the same address is reused, or if a balance remains in the original address after a transaction, the funds may theoretically face higher risks in the future when quantum computing power is sufficient. Taproot addresses are different; their outputs expose public key information at creation time.
Added risk scoring and address repair
BitGo's newly launched features include a quantum risk score, an exposed address remediation process, a new UTXO selection method, and updates to default address control. The quantum risk score is used within the platform to measure the degree of public key exposure of supported wallets.
However, BitGo has not disclosed the calculation formula, weighting, or thresholds for this score. This suggests that it is more of an internal risk management metric rather than a unified security standard at the Bitcoin network level.
UTXO processing methods will be adjusted accordingly.
The new UTXO selection method aggregates funds by address. When a wallet is about to spend a UTXO from a specific address, the system will try to select other UTXOs associated with that address and transfer them out simultaneously. This is to prevent remaining funds from being held in publicly accessible addresses after a single expenditure.
BitGo has also introduced a "fix exposed addresses" process to migrate related funds to newly generated addresses. The public keys for these new addresses have not yet appeared on-chain. At the same time, default settings have been adjusted to reduce the use of address types and transaction patterns that prematurely expose public keys.
BitGo stated that funds such as Taproot and Pay-to-Public-Key, which expose public key information from creation, require separate handling. However, the company did not specify whether this product update covers these remediation paths.
This is still a forward-looking preparation at this stage.
In its statement, BitGo cited Blockstream co-founder Adam Back as saying that there are currently no quantum computers capable of threatening Bitcoin. This also means that these tools target future risks, rather than currently feasible methods of stealing cryptocurrency.
Meanwhile, Bitcoin developers are also discussing the BIP 360 draft. This proposal plans to introduce a new output design through a soft fork to reduce the risks associated with long-term public key exposure. However, this proposal is still in the draft stage and has not yet been activated on the Bitcoin network.
On-chain research firm Glassnode previously estimated that as of May this year, approximately 6.04 million BTC had their public keys exposed, representing 30.2% of the issued supply. Of these, about 1.92 million BTC were exposed due to output structures, while another 4.12 million BTC were related to address reuse, partial spending, or escrow operations. The study did not suggest that these Bitcoins could currently be stolen, but rather pointed out which balances had exposed public keys and which risks could be mitigated through better wallet management.
BitGo has not yet disclosed how many customers can use these features, nor has it stated whether there will be a separate charge, or when support will be expanded in the future.










