Coinbase plans post-quantum Bitcoin custody for any scheme
Coinbase has begun designing a post-quantum custody system intended to protect about $250 billion in institutional assets while supporting any new signature scheme adopted by Bitcoin or another blockchain.
- Coinbase is preparing custody infrastructure for several possible post-quantum signature schemes.
- Hash-based signatures may not work with the MPC systems used by many crypto custodians.
- Programmable hardware security modules could provide Coinbase with an alternative key-protection method.
- Bitcoin developers have not selected or activated a post-quantum signature standard.
Coinbase prepares custody for several signature schemes
MARA Foundation TV hosted Coinbase Chief Cryptographer Yehuda Lindell, who said the exchange wants its custody platform to remain usable regardless of which post-quantum signature schemes blockchains eventually select.
Bitcoin has not chosen a signature scheme for practical post-quantum use, leaving custodians without a single technical standard around which to rebuild their systems. Lindell said different blockchain communities may also reach different decisions instead of adopting one common scheme.
Coinbase is therefore preparing for several possible outcomes rather than building its system around one candidate. Lindell said the company wants to avoid a situation in which a blockchain approves a signature scheme that its custody infrastructure cannot handle.
The work carries added weight because Coinbase holds about $250 billion in assets for institutional customers, according to the figure Lindell gave during the program. Its clients include BlackRock, which uses Coinbase Custody for digital assets connected to its investment products.
An August U.S. custody review placed Coinbase's institutional assets at approximately $376 billion and said the company safeguards more than 80% of assets held by U.S. spot Bitcoin and Ethereum exchange-traded funds. Differences between the two totals may depend on their reporting dates and the services or assets included in each estimate.
Custody systems protect the private keys needed to authorize transactions. Any future change to Bitcoin's signature method would therefore require large custodians to update the technology used to create, store and operate those keys.
Post-quantum signatures challenge existing MPC custody
Many institutional custody platforms use Multi-Party Computation, or MPC, to divide control of a private key among several parties. Under such an arrangement, no participant needs to hold or assemble the full private key while approving a transaction.
Lindell said many post-quantum signature schemes may be "not friendly to MPC" because their mathematical design differs from the signatures now used by major blockchains. Hash-based signatures present a particular problem because they lack the arithmetic structure on which traditional cryptographic key splitting depends.
Researchers, including Stanford University cryptographer Dan Boneh, are studying possible ways to apply MPC-style controls to such signatures, Lindell said. The research remains highly experimental, however, and it is not yet clear whether a practical MPC-equivalent system can be created for hash-based signatures.
Coinbase's existing interest in the field predates the latest custody design. In January, the company established an independent quantum computing and blockchain advisory board that includes Boneh, Lindell, Ethereum Foundation researcher Justin Drake, University of Texas professor Scott Aaronson, EigenLayer founder Sreeram Kannan and distributed-systems specialist Dahlia Malkhi.
According to Coinbase, its post-quantum roadmap includes changes to Bitcoin address handling, updates to internal key-management systems and research into supporting schemes such as ML-DSA within MPC infrastructure. The company tasked the advisory board with assessing quantum developments, publishing recommendations and responding to major technical advances.
Other custodians have started testing one possible route. In June, BitGo tested quantum-safe MPC with Silence Laboratories using an ML-DSA-based protocol integrated into BitGo's custody platform. The simulation retained distributed key control, policy checks, and separation of duties, according to the companies.
ML-DSA is included in FIPS 204, a post-quantum digital signature standard published by the U.S. National Institute of Standards and Technology. Lindell's comments indicate that Coinbase wants an architecture capable of handling schemes beyond ML-DSA if Bitcoin or another network chooses a different design.
Hardware modules could provide a custody fallback
To reduce its dependence on MPC compatibility, Coinbase is exploring a backup design built around programmable Hardware Security Modules, according to Lindell.
HSMs are physically protected devices used to store cryptographic material and perform sensitive operations. Under the architecture being considered by Coinbase, private keys would remain encrypted using post-quantum cryptography and would be assembled only inside secure HSMs.
Containing the complete key within the protected device would allow the custodian to work with signature schemes that cannot be divided through conventional MPC. Programmable modules could also give Coinbase room to add support as blockchain developers settle on new standards.
Lindell did not provide a completion date, saying the technical work could take time. Once the system is finished, however, he expects Coinbase to operate without having to predict which post-quantum scheme each network will choose.
"I will be able to say, I can support any scheme," Lindell said.
Physical security becomes more important under the proposed model because the full key would temporarily exist inside an HSM. Coinbase would therefore need the modules to perform signing without exposing the key to outside software or operators.
The approach would not require Coinbase to abandon MPC for signature schemes that support it. Instead, the HSM architecture would serve as another custody method when a network's chosen cryptography cannot work with distributed key generation and signing.
-- Price
Bitcoin has not approved a quantum migration plan
Bitcoin currently uses elliptic-curve cryptography, and no publicly demonstrated quantum computer can derive its private keys from exposed public keys. Researchers and industry groups have still called for early preparation because changing Bitcoin's security model would require software development, testing, wallet upgrades, and network consensus.
Crypto.news reported in June that Coinbase's advisory board urged Bitcoin developers to begin creating migration tools before a cryptographically relevant quantum computer exists. The board estimated that about 1.7 million BTC sit in older pay-to-public-key addresses with exposed public keys, while address reuse could place as many as 5 million BTC within a future risk category.
The advisory board did not recommend freezing, burning, or leaving vulnerable coins available to a future attacker. It said Bitcoin's community should decide through its consensus process how to treat coins that remain in older address formats after a migration deadline.
Draft proposals are examining separate parts of the problem. BIP 360, known as Pay-to-Merkle-Root, would remove Taproot's quantum-vulnerable key-path spending option, while BIP 361 describes a phased retirement of legacy ECDSA and Schnorr signatures after Bitcoin gains a post-quantum output method.
Neither proposal has been activated. A recent migration assessment also found that SHRINCS, an experimental hash-based signature design under discussion, remains an unnumbered draft requiring further review and a completed security proof.
For U.S. investors, Coinbase's preparations concern assets held through regulated investment products as well as coins stored by direct institutional clients. Spot Bitcoin and Ethereum ETF investors do not control the private keys behind fund holdings; those keys are managed by custodians selected by the issuers.
Coinbase's ability to support multiple signature schemes could become relevant if Bitcoin, Ethereum, or another network used by a U.S.-listed fund adopts new cryptography. Any blockchain migration would still depend on network rules and action by users, wallet providers, exchanges, custodians and fund operators rather than a decision by Coinbase alone.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Why Bitcoin Could Drop Below $80,000 After Another Failed Bounce

Crypto firms turn to Anthropic AI to find security flaws

Kruidvat sells Bitcoin gift cards with high fees

President Trump unveils $215M quantum computing plan amid crypto fears

Tiger Research: Five Key Changes in Crypto VC for Q3 2026

Midterm Elections in the United States, Bitcoin Could Benefit from a Historic Rise

Core Lightning v26.06.9 released with security fixes and payment bug repair

Long-Bond Highs Pressure Tech| WEEX TradFi Daily Brief (October 9, 2026)
Indexes were mixed on October 8 ET. The long-bond yield touched about 5.35% intraday, near levels last seen in 2002. OpenAI’s annualized revenue of about $50 billion came in below higher figures that had circulated, pressuring tech and chip names. Nasdaq fell clearly, while Dow edged higher. Energy led, with WTI up about 3.2% to about $91. Bitcoin pulled back from about $86,000 and traded near $81,000, down about 5%. September PPI is the focus on October 9.

WEEX Exclusive:Long-Bond Highs Pressure Tech| WEEX TradFi Daily Brief (October 9, 2026)
Indexes were mixed on October 8 ET. The long-bond yield touched about 5.35% intraday, near levels last seen in 2002. OpenAI’s annualized revenue of about $50 billion came in below higher figures that had circulated, pressuring tech and chip names. Nasdaq fell clearly, while Dow edged higher. Energy led, with WTI up about 3.2% to about $91. Bitcoin pulled back from about $86,000 and traded near $81,000, down about 5%. September PPI is the focus on October 9.

Ansem: Quantum Risks Will Drive ZEC Closer to BTC, Pure Meme Surpassing Bitcoin Is Highly Unlikely

Thailand SEC Allows Bitcoin and Ethereum ETFs to Trade

Q3 Crypto Investment Review: Strategic Capital Rises, Seed Rounds Cool Off

AI may be keeping Bitcoin’s biggest macro headwind alive after the Fed stops hiking

Why Are AI Stocks Still Rising Despite Soaring US Treasury Yields?

Arthur Hayes Predicts a Super Bull Market for Digital Assets

Robin Linus Releases Bitcoin Poker Protocol with 56,000 Transaction Tree Nodes

Meanwhile Completes $37.5 Million Financing, Total Funding Exceeds $180 Million

OSL Launches USDGO Market-Neutral Fund On-Chain for Hong Kong Investors

Bitcoin Core merges privacy fix into v32, v31 patch remains open

PowerCompute Mines 8.1 Bitcoin In September, Reduces Debt By 22.45 Million

Strategy Schedules October 29 Bitcoin Treasury Update

BNY Expands Regulated Crypto Custody Across The European Union Under MiCA

Citrini Research predicts tokenization could surpass BTC and ETH

Bitcoin ETFs See $484.9 Million Outflows Led By BlackRock

TD Cowen Raises Bitcoin Year-End Price Prediction to $109,000

Economist Who Called Bitcoin 'Revolutionary' Among Favorites for 2026 Nobel Prize in Economics

Breez Reports 14-Fold Increase in Bitcoin Integration Demand

ACAMS and Chainalysis expand crypto crime training as scam losses hit $17B

Report Estimates $50 Billion Inflow into Crypto Market in 2023, Momentum Improves in Q4









