Midterms 2026See who we think should earn your vote, based on our standardsThe guide →
WRITTEN IN PLAIN AMERICAN ENGLISH.
CLAY TRIBUNE.
Advertisement

Inside Coinbase’s $250 Billion Plan to Keep Bitcoin Safe From Quantum Computers

Coinbase is building a $250B post-quantum Bitcoin custody plan, splitting keys across HSMs to stay ready for quantum attacks.

By mitch·6 min read
A glowing quantum computer with encrypted keys floating above it in a vault-style illustration.

The exchange is getting ready for the moment a real quantum computer arrives and starts breaking the math that protects Bitcoin. Yehuda Lindell, who leads Coinbase’s cryptography team, said on MARA Foundation TV that the company is planning ahead for a time when the signature schemes guarding its assets no longer work. The goal is simple: ensure that Coinbase can keep holding its $250 billion in institutional assets even after those protection systems fail.

The problem is that quantum computers could one day crack the cryptography behind Bitcoin’s private keys. Coinbase custodies roughly $250 billion on behalf of institutions including BlackRock. Its current protection, called Multi-Party Computation or MPC, splits private keys across many devices so no single one holds the whole key. That works against classical attacks. It is not clear it will work against quantum ones.

Lindell said the company is designing its post-quantum security measures to be agnostic and adaptable to whatever signing scheme Bitcoin adopts in the coming years. “It’s unlikely that there will be a single signing scheme that everybody will use,” he said. “That means we have to be prepared and ready for the different outcomes on different blockchains.”

Advertisement

How MPC Works Today

MPC is similar in function to Bitcoin multi-signature setups. Different parties hold distinct “shares” of a private key, so multiple signers can execute transactions without making whole private keys vulnerable on a single device. Bitcoin’s native scripting language lets users enforce quorum rules directly on-chain.

A particular set of cryptographic functions power MPC’s operation away from the blockchain, which means no single location ever holds the whole key. Instead, a specific quorum of key shares must come together to sign a single transaction, removing a single point of failure entirely.

The shared arithmetic structure within the keys is what MPC depends upon. Certain post-quantum signature schemes do not possess that structure. Hash-based signatures, for instance, are assumed to hold up against quantum threats due to their absence of the underlying mathematical foundation that enables traditional cryptographic key-splitting. It is that very absence of mathematical structure that makes them hard to use when constructing infrastructure for MPC.

“MPC-friendliness or non-MPC-friendliness makes a very big difference,” Lindell explained. While executing MPC with hash-based signatures was presumed impossible up until recently, leading cryptographers like Dan Boneh are actively researching potential solutions, as detailed in the recent “PRAWNS” paper. However, because this research is in a highly experimental phase, it is still unclear if a viable MPC-like scheme can be developed for hash-based signatures.

The Fallback Architecture

Coinbase is investigating a fallback design built around programmable Hardware Security Modules, or HSMs. The proposal calls for private keys to be encrypted with post-quantum cryptography, then reassembled solely inside a physically secure HSM. The idea holds that holding a full key in one spot—albeit briefly—is considered more vulnerable than traditional MPC.

The physical side-channel protections and strict code-upload controls are what give Lindell comfort with the setup, he said. He described the architecture as combining post-quantum threshold decryption with programmable HSMs.

The Research Race

Until recently, executing MPC with hash-based signatures was considered an impossibility, according to Lindell. Cryptographers such as Dan Boneh are now investigating possible answers, as described in the latest “PRAWNS” paper. Since this work remains in its early stages, however, there is no certainty yet about whether a practical MPC-like approach can ever be built for hash-based signatures.

Coinbase has expressed doubt about the quantum-resistant signature scheme Bitcoin might use for its upgrade. That doubt has come from wallet developers, including Ledger CTO Charles Guillemet. The fear is that the method chosen for Bitcoin could end up being incompatible with the MPC infrastructure Coinbase has already put together.

Lindell’s Comfort Level

Although the timeline to complete Coinbase’s post-quantum security measures is still uncertain, Lindell added that once it is complete, “I will be able to say, ‘I can support anything.’ We don’t have the fear that some blockchain [is going to] decide to use something that we just won’t be able to support.”

Coinbase is building its custody design to match any signature scheme Bitcoin chooses, regardless of whether that scheme plays well with MPC systems or not. The fallback HSM method acts as a smart way to handle the unknown path Bitcoin’s final signature scheme will take.

What This Means for Bitcoin

A quantum computer capable of breaking Bitcoin’s private keys could devastate institutions with substantial holdings. The danger is real: Coinbase safeguards about $250 billion on behalf of such organizations, including BlackRock.

The irony is that the architecture protecting Coinbase’s money today—the MPC key-splitting system—may be the first thing a quantum computer breaks. If Bitcoin switches to a hash-based signature scheme, the MPC infrastructure that currently guards the exchange’s assets becomes useless. The fallback HSM approach is meant to fill that gap, but it remains experimental.

The HSM design is already built, according to Lindell, along with its controls and its fallback path for when Bitcoin’s chosen signature scheme breaks MPC. What he is not doing is declaring the research complete; rather, he is pointing to what is already accomplished.

Key Facts Box

  • $250 billion: value of assets custodied for institutions including BlackRock
  • Yehuda Lindell: Coinbase head of cryptography
  • Dan Boneh: cryptographer researching MPC-like schemes for hash-based signatures
  • “PRAWNS”: recent paper detailing Boneh’s work
  • Isabel Foxen Duke: MARA Foundation TV host
  • Charles Guillemet: Ledger CTO

Comparison Table

Scheme MPC-Friendly Current Status
Traditional cryptography Yes In use now
Hash-based signatures No Secure against quantum threats but not yet compatible with MPC
MPC with hash-based signatures Unknown Research in progress (PRAWNS)
Coinbase fallback HSM Unknown Experimental architecture

The contrast reveals the core challenge facing Coinbase. The signature method most protected against quantum computers is also the one that joins least easily with the MPC system now guarding Bitcoin. The firm is counting on the backup HSM path to succeed, though the study remains at an early stage.

The fact that Coinbase is even thinking about this is a sign of how seriously the exchange takes quantum risk. It is one thing to theorize about quantum attacks. It is another to design a $250 billion backup plan for the day they arrive.

The market reads Lindell’s self-assurance as a sign that Coinbase can handle any scheme, which takes away one excuse for institutional investors to hold back. The HSM backup plan works as the safety net. It remains experimental, yet it is there for consideration.

The fact that Coinbase has taken action shows that quantum computers pose an actual danger. They are not something that exists only in theory.

Source material: “Inside Coinbase’s $250 Billion Playbook for Post-Quantum Bitcoin Custody,” Decrypt.

The Notebook

Get the Notebook.

The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

We send one note to confirm. Every issue has a one-click way out.

Advertisement

Leave a Reply

Your email address will not be published. Required fields are marked *

As an Amazon Associate, Clay Tribune earns from qualifying purchases.