skip to content

Bitcoin’s Largest Institutions Launch $15m Security Initiative

Bitcoin-1 Orange-2

This article originally appeared in Galaxy Research's weekly newsletter. Subscribe to get it in your inbox every Friday.

Nine of the largest institutional participants in Bitcoin have put a number on what it costs to keep the network secure. BlackRock, Fidelity Digital Assets, Coinbase, Strategy, Block, Galaxy, Anchorage, ARK Invest, and Blockstream announced the formation of the Bitcoin Security Consortium this week, pledging $15 million over the next three years for Bitcoin security research and open-source development.

This is not a development organization, nor is it a governance body. The consortium doesn’t write code, and it doesn’t vote on what Bitcoin becomes next. As per the announcement, members “don’t direct its development, and don’t speak for Bitcoin.” Robert Mitchnick, BlackRock’s global head of digital assets, framed the commitment as making “significant additional funding available to support Bitcoin’s long-term security needs.” Mike Schmidt, executive director of Brink (the nonprofit that’s funded Bitcoin Core contributors since 2020) is coordinating the day-to-day effort as a volunteer, independent of any member organization.

The timing tracks with where institutional BTC ownership sits. Spot exchange-traded funds (ETFs), publicly traded treasury companies, custodians, and exchanges now collectively secure hundreds of billions of dollars of BTC. This is a scale of institutional exposure that didn’t exist three years ago. And quantum computing has become one of the most discussed long-term risks to that pile of capital. This consortium is landing the week Galaxy Digital launched our own Bitcoin Quantum Readiness Initiative, committing up to $5 million toward developer grants and a Quantum Advisory Council focused on post-quantum migration (note that Galaxy also joined the Bitcoin Security Consortium). Meanwhile, custody giant BitGo has rolled out quantum risk scoring for institutional wallets, Blockstream has named post-quantum cryptography a top engineering priority for 2026, and Strategy has initiated a Bitcoin security program. The consortium reads as the coordination layer sitting on top of individual company-level activity.

Its mandate is broader than quantum risk. Funding is intended to support protocol security research generally.

OUR TAKE

Bitcoin security funding has historically come from a small group of nonprofits, often operating on budgets that wouldn’t register on any of these nine companies’ balance sheets. That model worked fine when BTC was mostly held by people who’d opted into the risk themselves. It doesn’t hold up as well with hundreds of billions of institutional dollars now sitting on top of the protocol.

Strategy CEO Phong Le put the incentive plainly: long-term holders have every reason to want Bitcoin secure for generations, and funding the people doing that unglamorous maintenance work is a natural extension of holding it. Unlike many other blockchains, Bitcoin has no foundation. (It used to, but that organization ran out of money more than a decade ago, when cryptocurrency was still a fringe interest.) It was never built to have one, but it’s accumulated enough economic value that its security has effectively become a public good with a funding problem. Someone still has to pay the people maintaining the code on which trillions of dollars depend. The consortium is best understood as an attempt to solve that coordination problem in a way akin to how Linux and other critical open-source infrastructure get funded, without introducing centralized governance.

It also invites an obvious knee-jerk reaction: these big companies funding Bitcoin security sounds, to some ears, like “institutions taking over Bitcoin.” The announcement goes out of its way to head that off. Funding developers is not the same thing as directing them. Consensus on Bitcoin still lives exactly where it always has, with users, node operators, miners, and developers in that same slow, occasionally frustrating rough-consensus process that’s kept the protocol credibly neutral for 17 years. The fact that Schmidt is running this as a volunteer keeps nine of the most powerful companies in the industry from having a hand on the wheel. Whether this earns trust in Bitcoin-native circles or gets read as a Trojan horse comes down entirely to whether that line holds.

A year ago, quantum risk to Bitcoin was conference-panel material. It was interesting, distant, and mostly theoretical. No more. None of these announcements mean that a cryptographically relevant quantum computer is imminent, but it signals that the ecosystem has started treating quantum readiness as an engineering problem worth solving on its own timeline.

The most notable part of this consortium is what committing that capital says about where Bitcoin now sits. The standing commitment to collectively fund developer work without asking for control in return is a milestone. Bitcoin’s governance hasn’t changed. The balance sheet of who’s willing to pay for its upkeep just did. - Will Owens

You are leaving Galaxy.com

You are leaving the Galaxy website and being directed to an external third-party website that we think might be of interest to you. Third-party websites are not under the control of Galaxy, and Galaxy is not responsible for the accuracy or completeness of the contents or the proper operation of any linked site. Please note the security and privacy policies on third-party websites differ from Galaxy policies, please read third-party privacy and security policies closely. If you do not wish to continue to the third-party site, click “Cancel”. The inclusion of any linked website does not imply Galaxy’s endorsement or adoption of the statements therein and is only provided for your convenience.