In a recent post, Justin Drake, an Ethereum Foundation researcher, asks holders to move Bitcoin to addresses whose public keys are still hidden behind a hash.
Drake writes that it is now reasonable to brace for ECDSA breaking through classical means before a quantum attack becomes practical, in the worst case within months. By a break he means recovering a private key in about a week on available hardware. No such attack exists today, and whether one is plausible at all is disputed. Yehuda Lindell, Head of Cryptography at Coinbase and a professor at Bar-Ilan University, makes the counter-case: AI proving open theorems is no evidence that problems believed inherently hard are about to fall, and a break of elliptic curves would reach far past crypto, to the certificates and code signing the rest of the digital world runs on. Drake’s recommendation is a calm, controlled move of funds to addresses that have never signed, with any remaining funds moved to a new address after each spend. He asks holders not to rush. Whoever is right, the step he recommends is already part of sensible post-quantum preparation. That is how the Fireblocks research team views this.
Why Unused Addresses Buy Protection
A Bitcoin P2PKH or P2WPKH address commits to a hash of the public key. The key itself appears onchain only when the address spends. Until then an attacker has only the hash to work with. Once the key is public it stays public, and any attack on the curve, found now or years from now, can target it. Fireblocks Bitcoin wallets use only these address types.
How Fireblocks Can Help Reduce Exposure Today
Fireblocks already provides several ways to reduce public-key exposure, with additional capabilities in development.
- Deposit addresses. A fresh deposit address can be created under the same Bitcoin wallet for each deposit rather than reusing an existing address. Bitcoin wallets can hold multiple deposit addresses within the same vault account, so this does not require creating a new wallet for every deposit. See the Fireblocks Developer Portal for guidance on creating deposit addresses.
- Moving exposed funds. Funds at an address that has already spent can move to a fresh address in the same wallet by selecting the inputs explicitly through the API, with policies and approvals applying as usual. For deposits that keep arriving at a spent address, an Automation rule can sweep them as they land into a vault account that never spends, keeping addresses that have already spent as close to empty as possible.
- Fireblocks Network. Address rotation is already supported on Network transfers, where each incoming payment lands on a fresh address.
- Change-address rotation. By default, change from every spend returns to the permanent address, so once that address has spent it stays exposed. Change-address rotation sends change to a fresh address instead. Because some operator-side validation, reconciliation, and reporting flows rely on the permanent address, they may need to be adjusted. Therefore, it is enabled on request today, with a self-serve option planned.
Where This Ends
Funds held at addresses whose public keys have not yet been revealed are not directly exposed to an attack on the signature curve. Spending is different. The transaction must carry the public key so the network can check the signature, and it sits in the mempool for anyone to read until it confirms. An attacker who recovers the private key inside that window can broadcast a competing transaction with a higher fee for the same coins. Against the attack Drake describes, a week per key, that window is irrelevant. Against an attack that recovers a key in minutes, from a large quantum computer or a classical shortcut, hashing no longer helps and new signature schemes are needed. If such a migration became necessary, how it happens would depend on the mechanisms each network supports, and those paths are still evolving across the industry.
What Else We Are Working On
We are also working on making this type of exposure reduction more seamless. Recently, Fireblocks enhanced its UTXO offering with a new adaptive selection algorithm. This enhancement provides the foundation for capabilities such as exposure-aware input selection, visibility into funds held at exposed addresses, and simpler change-address rotation.
The larger problem is not Bitcoin-specific. Our post-quantum program starts from the assumption that the set of signature schemes we need to support will evolve over time, and we are building the next generation of our signing infrastructure with that flexibility in mind.
Alongside that work we are researching threshold signing for the new signature schemes, and hash-based signatures for Bitcoin. Another strand is verifying post-quantum signatures on existing chains, without requiring a fork, and our post-quantum verifier on Ethereum is a published result. On the custody side, we laid out the custody considerations of rotating a live account in place to a post-quantum key, demonstrated on NEAR with the address unchanged. Across all of it, security comes first: new schemes get the same scrutiny as old ones, and our team found a signature forgery in Shipovnik, a post-quantum candidate.
There is no need to rush. For customers who want to reduce this exposure today, a straightforward step is to confirm that their deposit flows do not reuse addresses. We will share more on change rotation and exposure-aware selection as those capabilities become available.