Thursday, July 30, 2026

BitGo adds quantum-risk controls and UTXO management for institutional BTC wallets

High-quality crypto dashboard for an institutional Bitcoin wallet, showing quantum risk score and UTXO paths with neon lighting.

BitGo has introduced four risk-management controls intended to help institutional clients identify and reduce potential quantum exposure across supported Bitcoin wallets. The release adds a Quantum Risk Score, exposed-address remediation, a new UTXO selection method and revised default address controls to the company’s multi-signature wallet infrastructure.

The tools address the visibility of Bitcoin public keys onchain. For address formats such as Pay-to-Public-Key-Hash, the blockchain initially records a hash of the public key, while the full key becomes visible when the corresponding output is spent. BitGo is treating previously revealed public keys as a distinct category of long-term cryptographic exposure, although some formats, including Taproot and Pay-to-Public-Key, expose a public key from the time an output is created.

New Controls Target Address-Level Exposure

BitGo’s Quantum Risk Score provides an internal measurement of potential exposure across supported wallets, allowing security and operations teams to identify balances associated with revealed public keys. The score turns address visibility into a trackable institutional risk indicator, but BitGo has not publicly disclosed its formula, weighting system or scoring thresholds. The measure should therefore be treated as a proprietary operational tool rather than an independently standardized assessment.

The Fix Exposed Addresses workflow gives clients a guided process for moving funds from addresses with elevated exposure into newly generated addresses. The remediation does not change the cryptography securing Bitcoin; it reorganizes wallet balances so fewer funds remain associated with public keys already visible onchain. Transactions used to complete that process remain subject to Bitcoin fees, confirmation times and the institution’s existing approval policies.

BitGo has also changed how its wallet software selects unspent transaction outputs. When one UTXO associated with an address is selected, the system attempts to include the address’s other UTXOs in the same transaction where possible. Emptying an address during its first spend reduces the chance that residual funds remain behind after the public key has been disclosed.

That selection method does not resolve every form of exposure. Funds held in output types that reveal public keys from creation, including Taproot and Pay-to-Public-Key, require separate treatment and fall outside the protection created by grouping UTXOs during a spend. Coin selection can improve key hygiene for future transactions without retroactively concealing information already published to the blockchain.

The fourth control updates BitGo’s default address behavior to reduce reliance on address types and transaction patterns carrying additional quantum-related considerations. Safer address handling becomes the standard wallet configuration rather than an optional setting that institutional operators must apply manually. BitGo has not published a complete technical matrix showing every supported wallet configuration or how defaults differ across legacy accounts.

Wallet Controls Do Not Make Bitcoin Quantum-Safe

Bitcoin uses secp256k1 elliptic-curve cryptography for its public and private key system. A sufficiently capable quantum computer could threaten current forms of public-key cryptography, although the technical timeline remains uncertain and practical quantum attacks against Bitcoin are not currently available. BitGo’s release is a preparatory custody measure, not evidence that an immediate quantum attack has become possible.

NIST finalized its first post-quantum cryptography standards in 2024 and has urged organizations to inventory vulnerable cryptographic systems and begin planning migrations. The agency notes that replacing widely embedded algorithms can require many years of engineering and operational coordination. BitGo’s approach follows that broader security principle by reducing measurable exposure before migration becomes urgent.

The wallet controls cannot replace a future Bitcoin protocol upgrade introducing quantum-resistant signatures. Such a transition would require technical proposals, software implementation, ecosystem testing and network consensus beyond the authority of any single custodian. BitGo can modify how institutional wallets manage current Bitcoin outputs, but it cannot independently change the signature rules enforced by the network.

The immediate significance is therefore operational. Institutions can now inventory public-key exposure, prioritize affected balances and adjust UTXO management without waiting for a network-wide cryptographic migration. The tools create a structured preparation layer for supported BitGo wallets, while their effectiveness will depend on scoring transparency, client adoption and disciplined remediation across large institutional balances.

Scroll to Top
Chain Report
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.