In brief

  • Coinbase is developing post-quantum custody safeguards to support a wide range of signature schemes, according to Head of Cryptography Yehuda Lindell.
  • Traditional Multi-Party Computation (MPC) relies on split keys, but many post-quantum signature schemes may be “non-MPC-friendly.”
  • Coinbase is exploring a fallback architecture that combines post-quantum threshold decryption with programmable Hardware Security Modules (HSMs).

If a cryptographically relevant quantum computer eventually becomes an active threat to Bitcoin's security, Coinbase wants to have protections in place that are prepared for whatever direction Bitcoin and other digital assets take, according to Yehuda Lindell.

In a recent appearance on MARA Foundation TV, the crypto exchange’s head of cryptography told host Isabel Foxen Duke that the company’s post-quantum safeguards are being designed to support any potential forms of technical retooling. At the moment, it is unclear what kind of post-quantum signature scheme Bitcoin will use in practice.

Myriad: How high will Bitcoin go? Click to make your prediction.
Myriad: How high will Bitcoin go? Click to make your prediction.

“It’s unlikely that there will be a single signing scheme that everybody will use,” Lindell said in reference to the standards that various networks will ultimately adopt. “That means we have to be prepared and ready for the different outcomes on different blockchains.”

Safeguarding roughly $250 billion in assets on behalf of institutions such as BlackRock, Coinbase has spent years refining associated procedures. Now it is preparing for a world where a cornerstone of that arrangement becomes more challenging—or even unfeasible in Bitcoin's case: Multi-Party Computation (MPC).

Similar in function to Bitcoin multi-signature setups, MPC allows different parties to hold distinct “shares” of a private key, enabling multiple signers to execute transactions without making whole private keys vulnerable on a single device.

While Bitcoin's native scripting language allows users to create multi-signature setups by enforcing quorum rules directly on-chain, MPC operates off-chain using specific cryptographic functions. Because a certain quorum of key shares is required to sign a single transaction, the complete key is never assembled in one location, effectively eliminating a single point of failure.

But as Bitcoin prepares for the post-quantum era, there is growing concern among experts that not all post-quantum signature schemes will be “MPC-friendly.” Specifically, hash-based signatures may lack the underlying arithmetic structure that makes traditional cryptographic key-splitting possible. While this lack of mathematical structure is why hash-based signatures are presumed to be secure against quantum threats, it also makes them difficult to work with when building infrastructure for MPC.

“MPC-friendliness or non-MPC-friendliness makes a very big difference,” Lindell explained. While executing MPC with hash-based signatures was presumed impossible up until recently, leading cryptographers like Dan Boneh are actively researching potential solutions, as detailed in the recent "PRAWNS" paper. However, because this research is in a highly experimental phase, it is still unclear if a viable MPC-like scheme can be developed for hash-based signatures.

Concerns about hash-based signatures have also been raised by wallet developers including Ledger CTO Charles Guillemet.

The hardware fallback 

In the event that Bitcoin adopts a post-quantum scheme incompatible with MPC, Coinbase is researching a fallback architecture centered on programmable Hardware Security Modules (HSMs)—digital vaults for encrypted keys inside private data centers.

Under this arrangement, private keys would be encrypted with post-quantum cryptography and only assembled within the confines of a physically secure HSM.

BitcoinBTC · USD
$86,038+13%
Sep 15Sep 17Sep 19Sep 21Sep 22
$87.0k$83.2k$79.3k$75.5k
24h HighHigh$86,722
24h LowLow$85,107
VolVol$1.9B
Buy Bitcoin with USDT
Powered by Jupiter
Price data by CoinGeckoCoinGeckoMore Bitcoin news and projections →

Although keeping a complete key in one place—even momentarily—is theoretically less secure than traditional MPC, an HSM provides strong protection within these constraints. Lindell noted that the rigorous physical side-channel protections and strict code-upload controls support his comfort with the setup.

Given the uncertainty around a potential post-quantum upgrade for Bitcoin, Coinbase is designing its custody architecture to be agnostic and adaptable to whatever signing scheme Bitcoin adopts in the coming years, Lindell said.

Although the timeline to complete Coinbase’s post-quantum security measures is still uncertain, Lindell added that, once it is complete, “I will be able to say, ‘I can support anything.’ We don't have the fear that some blockchain [is going to] decide to use something that we just won't be able to support.”

André Beganski is a Senior Content Manager at MARA Foundation, producing content on topics including the intersection of quantum computing and cryptography. He has previously worked for Decrypt.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.