Inside Coinbase’s $250 Billion Playbook for Post-Quantum Bitcoin Custody

Coinbase is building post-quantum custody safeguards meant to support a wide range of potential signature schemes Bitcoin and other blockchains might adopt, Head of Cryptography Yehuda Lindell said on MARA Foundation TV. Because some post-quantum signatures—particularly hash-based schemes—may not work with traditional Multi-Party Computation (MPC), Coinbase is also exploring a fallback that uses programmable Hardware Security Modules (HSMs) and post-quantum encryption.

By AI Newsroom· Reviewed by Pranav, Founder & Editor-in-ChiefPublished 1 minute agoUpdated 1 minute ago0 views
Inside Coinbase’s $250 Billion Playbook for Post-Quantum Bitcoin Custody

Why It Matters

Coinbase custodies roughly $250 billion for institutional clients, so its approach to post-quantum security could influence how large custodians and their customers manage cryptographic migration risks. Designing custody to be agnostic to different post-quantum signing schemes addresses uncertainty about which standards blockchains will adopt.

Key Facts

  • Company: Coinbase
  • Spokesperson: Yehuda Lindell, Head of Cryptography
  • Assets under custody (approx.): $250 billion
  • Primary current custody technique: Multi-Party Computation (MPC)
  • Post-quantum concern: Some signature schemes (e.g., hash-based) may be non-MPC-friendly

Coinbase is preparing its custody systems for a transition to post-quantum cryptography by designing safeguards that can accommodate a variety of signature schemes, Head of Cryptography Yehuda Lindell said in an interview on MARA Foundation TV. The exchange said it aims for an architecture that remains usable regardless of which post-quantum signing standards different blockchains eventually adopt. Today Coinbase relies heavily on Multi-Party Computation (MPC) for institutional custody. MPC splits a private key into multiple shares held by separate parties so transactions can be signed without ever assembling a full key in one place. That off-chain approach reduces single points of failure and mirrors the quorum logic available in on-chain multisignature setups. However, Lindell and other experts warn that not all post-quantum signature families will be compatible with MPC. Hash-based signatures, in particular, lack the algebraic structure that traditional key-splitting techniques exploit, making them difficult to integrate with MPC workflows. While recent academic work—such as research referenced by Lindell—has begun to explore MPC-like constructions for such schemes, these efforts remain experimental and uncertain. To address that uncertainty, Coinbase is investigating a fallback architecture that would use programmable Hardware Security Modules (HSMs). In this model, private keys would be encrypted under post-quantum algorithms and only ever assembled inside physically secure HSMs within Coinbase data centers. Lindell acknowledged that assembling a complete key even briefly is theoretically less secure than MPC, but said HSMs provide strong physical and side-channel protections and strict controls on code uploads. He said Coinbase is building its systems to be agnostic so it can support whatever post-quantum signing approaches Bitcoin or other networks ultimately adopt.

Keep Reading