Coinbase Prepares Post-Quantum Custody Defenses as Bitcoin Quantum Upgrade Remains Uncertain
Coinbase readies defenses for a quantum future in crypto custody
Coinbase is developing post-quantum custody protections designed to work with whatever signature scheme Bitcoin and other blockchains ultimately adopt, according to Yehuda Lindell, the crypto exchange's Head of Cryptography. Lindell shared details during an appearance on MARA Foundation TV, saying the company wants to be prepared for every possible outcome as the industry moves toward a post-quantum era.
The exchange safeguards roughly $250 billion in assets on behalf of institutions including BlackRock, and its preparations for quantum-resistant security are now a priority as experts weigh how Bitcoin might handle the emerging threat of cryptographically relevant quantum computers.
Key points
- Coinbase is designing custody safeguards that can support any post-quantum signature scheme, not just one predetermined approach.
- Traditional Multi-Party Computation (MPC) — a method where multiple parties hold separate "shares" of a private key — may not work with all post-quantum signature schemes.
- Coinbase is researching a hardware-based fallback using programmable Hardware Security Modules (HSMs) that could hold keys in physically secure digital vaults.
What Yehuda Lindell said
Lindell explained that it is unlikely any single signing scheme will be used across all blockchains. "That means we have to be prepared and ready for the different outcomes on different blockchains," he said. A major challenge is that some post-quantum approaches, particularly hash-based signatures, may lack the mathematical structure needed to support traditional MPC setups. While hash-based signatures are considered strong candidates against quantum attacks, that same lack of structure makes it difficult to split keys across multiple parties as MPC requires.
Lindell noted that leading cryptographers like Dan Boneh are actively researching potential solutions in a paper called "PRAWNS," but said the work remains highly experimental and it is unclear whether a viable MPC-like scheme for hash-based signatures can be built.
Charles Guillemet, CTO of hardware wallet maker Ledger, has also raised concerns about hash-based signatures in the post-quantum context.
The hardware fallback: HSMs as a secure alternative
If Bitcoin adopts a post-quantum scheme incompatible with MPC, Coinbase is researching a fallback centered on programmable Hardware Security Modules (HSMs) — encrypted key vaults housed inside secure data centers. Under this arrangement, private keys would be encrypted using post-quantum cryptography and assembled only within the physical boundaries of an HSM.
Lindell acknowledged that keeping a complete key in one location — even temporarily — is theoretically less secure than traditional MPC. However, he said the rigorous physical protections and strict code-upload controls of HSMs make him comfortable with the approach.
Why this matters for Bitcoin and institutional crypto
Bitcoin's security relies on cryptographic signatures that could theoretically be broken by a sufficiently powerful quantum computer. While no such computer currently exists, the crypto industry has been studying how networks might transition to post-quantum algorithms. Coinbase's work reflects a broader effort to ensure that large-scale institutional custody infrastructure can survive that transition without being caught off guard.
The concern is not just theoretical. Bitcoin's scripting language supports multi-signature setups on-chain, but MPC operates off-chain using different cryptographic functions. If the post-quantum signature Bitcoin eventually uses cannot support MPC, existing custody systems built around that technology may need significant redesign.
What is confirmed
Coinbase is actively researching post-quantum custody solutions, including both MPC-compatible approaches and HSM-based fallbacks. Lindell, as Head of Cryptography, presented these plans on MARA Foundation TV. The exchange manages approximately $250 billion in institutional assets. Research into MPC compatibility with hash-based signatures is ongoing but remains experimental.
What is still unclear
It is unknown what post-quantum signature scheme Bitcoin will ultimately adopt, when such an upgrade might occur, or whether a practical MPC-like scheme can be built for hash-based signatures. The timeline for Coinbase to complete its post-quantum security measures is also uncertain.
What happens next
Once Coinbase's post-quantum measures are complete, Lindell said the exchange will be positioned to support any blockchain's chosen signing scheme. "I will be able to say, 'I can support anything.' We don't have the fear that some blockchain [is going to] decide to use something that we just won't be able to support," he stated.