Meta Force Space
BTC $84,493.00 -2.19% ETH $2,686.82 -2.86% SOL $115.04 -3.33% XRP $1.50 -4.94% BNB $765.60 -3.17% DOGE $0.0928 -8.05%
← Back to the news

Coinbase plans post-quantum Bitcoin custody for any scheme

Coinbase has begun designing a post-quantum custody system intended to protect about $250 billion in institutional assets while supporting any new signature scheme adopted by Bitcoin or another blockchain.

Summary
  • Coinbase is preparing custody infrastructure for several possible post-quantum signature schemes.
  • Hash-based signatures may not work with the MPC systems used by many crypto custodians.
  • Programmable hardware security modules could provide Coinbase with an alternative key-protection method.
  • Bitcoin developers have not selected or activated a post-quantum signature standard.

Coinbase prepares custody for several signature schemes

MARA Foundation TV hosted Coinbase Chief Cryptographer Yehuda Lindell, who said the exchange wants its custody platform to remain usable regardless of which post-quantum signature schemes blockchains eventually select.

Bitcoin has not chosen a signature scheme for practical post-quantum use, leaving custodians without a single technical standard around which to rebuild their systems. Lindell said different blockchain communities may also reach different decisions instead of adopting one common scheme.

Coinbase is therefore preparing for several possible outcomes rather than building its system around one candidate. Lindell said the company wants to avoid a situation in which a blockchain approves a signature scheme that its custody infrastructure cannot handle.

The work carries added weight because Coinbase holds about $250 billion in assets for institutional customers, according to the figure Lindell gave during the program. Its clients include BlackRock, which uses Coinbase Custody for digital assets connected to its investment products.

An August U.S. custody review placed Coinbase’s institutional assets at approximately $376 billion and said the company safeguards more than 80% of assets held by U.S. spot Bitcoin and Ethereum exchange-traded funds. Differences between the two totals may depend on their reporting dates and the services or assets included in each estimate.

Custody systems protect the private keys needed to authorize transactions. Any future change to Bitcoin’s signature method would therefore require large custodians to update the technology used to create, store and operate those keys.

Post-quantum signatures challenge existing MPC custody

Many institutional custody platforms use Multi-Party Computation, or MPC, to divide control of a private key among several parties. Under such an arrangement, no participant needs to hold or assemble the full private key while approving a transaction.

Lindell said many post-quantum signature schemes may be “not friendly to MPC” because their mathematical design differs from the signatures now used by major blockchains. Hash-based signatures present a particular problem because they lack the arithmetic structure on which traditional cryptographic key splitting depends.

Researchers, including Stanford University cryptographer Dan Boneh, are studying possible ways to apply MPC-style controls to such signatures, Lindell said. The research remains highly experimental, however, and it is not yet clear whether a practical MPC-equivalent system can be created for hash-based signatures.

Coinbase’s existing interest in the field predates the latest custody design. In January, the company established an independent quantum computing and blockchain advisory board that includes Boneh, Lindell, Ethereum Foundation researcher Justin Drake, University of Texas professor Scott Aaronson, EigenLayer founder Sreeram Kannan and distributed-systems specialist Dahlia Malkhi.

According to Coinbase, its post-quantum roadmap includes changes to Bitcoin address handling, updates to internal key-management systems and research into supporting schemes such as ML-DSA within MPC infrastructure. The company tasked the advisory board with assessing quantum developments, publishing recommendations and responding to major technical advances.

Other custodians have started testing one possible route. In June, BitGo tested quantum-safe MPC with Silence Laboratories using an ML-DSA-based protocol integrated into BitGo’s custody platform. The simulation retained distributed key control, policy checks, and separation of duties, according to the companies.

ML-DSA is included in FIPS 204, a post-quantum digital signature standard published by the U.S. National Institute of Standards and Technology. Lindell’s comments indicate that Coinbase wants an architecture capable of handling schemes beyond ML-DSA if Bitcoin or another network chooses a different design.

Hardware modules could provide a custody fallback

To reduce its dependence on MPC compatibility, Coinbase is exploring a backup design built around programmable Hardware Security Modules, according to Lindell.

HSMs are physically protected devices used to store cryptographic material and perform sensitive operations. Under the architecture being considered by Coinbase, private keys would remain encrypted using post-quantum cryptography and would be assembled only inside secure HSMs.

Containing the complete key within the protected device would allow the custodian to work with signature schemes that cannot be divided through conventional MPC. Programmable modules could also give Coinbase room to add support as blockchain developers settle on new standards.

Lindell did not provide a completion date, saying the technical work could take time. Once the system is finished, however, he expects Coinbase to operate without having to predict which post-quantum scheme each network will choose.

“I will be able to say, I can support any scheme,” Lindell said.

Physical security becomes more important under the proposed model because the full key would temporarily exist inside an HSM. Coinbase would therefore need the modules to perform signing without exposing the key to outside software or operators.

The approach would not require Coinbase to abandon MPC for signature schemes that support it. Instead, the HSM architecture would serve as another custody method when a network’s chosen cryptography cannot work with distributed key generation and signing.

Bitcoin has not approved a quantum migration plan

Bitcoin currently uses elliptic-curve cryptography, and no publicly demonstrated quantum computer can derive its private keys from exposed public keys. Researchers and industry groups have still called for early preparation because changing Bitcoin’s security model would require software development, testing, wallet upgrades, and network consensus.

Crypto.news reported in June that Coinbase’s advisory board urged Bitcoin developers to begin creating migration tools before a cryptographically relevant quantum computer exists. The board estimated that about 1.7 million BTC sit in older pay-to-public-key addresses with exposed public keys, while address reuse could place as many as 5 million BTC within a future risk category.

The advisory board did not recommend freezing, burning, or leaving vulnerable coins available to a future attacker. It said Bitcoin’s community should decide through its consensus process how to treat coins that remain in older address formats after a migration deadline.

Draft proposals are examining separate parts of the problem. BIP 360, known as Pay-to-Merkle-Root, would remove Taproot’s quantum-vulnerable key-path spending option, while BIP 361 describes a phased retirement of legacy ECDSA and Schnorr signatures after Bitcoin gains a post-quantum output method.

Neither proposal has been activated. A recent migration assessment also found that SHRINCS, an experimental hash-based signature design under discussion, remains an unnumbered draft requiring further review and a completed security proof.

For U.S. investors, Coinbase’s preparations concern assets held through regulated investment products as well as coins stored by direct institutional clients. Spot Bitcoin and Ethereum ETF investors do not control the private keys behind fund holdings; those keys are managed by custodians selected by the issuers.

Coinbase’s ability to support multiple signature schemes could become relevant if Bitcoin, Ethereum, or another network used by a U.S.-listed fund adopts new cryptography. Any blockchain migration would still depend on network rules and action by users, wallet providers, exchanges, custodians and fund operators rather than a decision by Coinbase alone.

Originally published by crypto.news on

Read the original on crypto.news ↗

Text and images are the property of crypto.news and are reproduced here with attribution and a link to the original publication.

More stories

All the latest news