Mastodon Skip to content Breaking Bitget Confirms $351.6M Wallet Breach•Bitget Confirms $351.6M Wallet Breach•Bitget Confirms $351.6M Wallet Breach•Bitget Confirms $351.6M Wallet Breach•Bitget Confirms $351.6M Wallet Breach•
LIVE - NYSE/-/- CRYPTO/OPEN/24/7
BTC$84,567▲ 0.29%ETH$2,689▲ 0.09%SOL$117.29▲ 1.77%TOTAL CRYPTO$2.9T▼ 2.08%S&P 5007,704.13▲ 0.67%NASDAQ26,939.37▲ 3.69%DOW51,349.98▼ 3.87%GOLD4,304.60▼ 8.37%WTI93.84▲ 10.39%BRENT105.97▲ 14.97%EUR/USD1.1375▼ 2.51%USD/JPY158.71▼ 0.27%DXY101.30▲ 2.32%
Crypto

Coinbase Designs Post-Quantum Custody for $250B in Assets

Coinbase is building quantum-resistant custody safeguards for roughly $250 billion in institutional assets, designed to work with any future Bitcoin signature scheme.

Pexels – Bastian Riccardi

Coinbase has started designing a post-quantum custody system meant to protect about $250 billion in institutional assets, including bitcoin tied to US spot ETFs, against the distant but consequential threat of quantum computers. The exchange’s head of cryptography, Yehuda Lindell, said the architecture is being built to adapt to whatever signing scheme Bitcoin eventually adopts.

Lindell laid out the thinking in a September 22 interview with Decrypt. The problem is not that quantum computers can break Bitcoin today. They cannot, and most researchers put a cryptographically relevant quantum machine years or decades away. The problem is that custody infrastructure takes years to build, audit and deploy, and the assets sitting in it are expected to still be there when the threat becomes real.

Why current custody is exposed

Most institutional bitcoin custody relies on multi-party computation, or MPC, which splits a private key into shares held by separate parties so no single person or machine can move funds alone. MPC is the backbone of custody for ETF issuers and large funds. Lindell’s concern, which he has raised publicly before, is that many post-quantum signature schemes are not MPC-friendly, meaning the key-splitting tricks that make today’s custody safe do not carry over cleanly.

Bitcoin’s own constraints make it harder. The network’s scripting language supports a limited set of signature types, and migrating a quantum-vulnerable output to a new address requires the owner to move the coins, which is not possible for lost or dormant holdings. An estimated several million bitcoin, including coins attributed to Satoshi Nakamoto, sit at addresses whose public keys are exposed and would be vulnerable first.

Coinbase’s answer is a fallback architecture that combines post-quantum threshold decryption with programmable hardware security modules. The design goal, Lindell said, is scheme-agnostic custody: whatever post-quantum signing scheme Bitcoin and other assets settle on, the infrastructure should support it without a rebuild.

The scale involved

The $250 billion figure covers Coinbase’s institutional custody business, which holds a large share of the bitcoin behind US spot ETFs. BlackRock’s iShares Bitcoin Trust alone uses Coinbase Prime as a custodian, and the ETF complex has grown into one of the largest pools of institutional bitcoin in the world. Any cryptographic weakness in that layer would be a systemic event, which is why the exchange is treating the timeline seriously even though the threat is not imminent.

The work also has a practical near-term angle. Standards bodies, including the US National Institute of Standards and Technology, have already finalized post-quantum encryption and signature standards for conventional systems, and financial institutions across traditional markets have begun migration planning. Crypto custody is a latecomer to that process, partly because Bitcoin has no governance mechanism to schedule a protocol upgrade.

The Bitcoin upgrade problem

Coinbase can prepare its own systems, but the harder dependency is Bitcoin itself. A post-quantum transition would almost certainly require a soft fork introducing new output types based on quantum-resistant signatures, and Bitcoin’s history of contentious upgrades makes any such change slow. Developers have floated quantum-safe proposals in technical discussions, but none has an activation path, and consensus for one would need to be built years before a quantum threat materializes.

Lindell acknowledged the uncertainty. Coinbase wants protections in place for whatever direction Bitcoin and other digital assets take, rather than betting on one outcome. That agnostic approach costs more up front but avoids the trap of building for a specific scheme that the ecosystem later rejects.

Regulators are watching too

The engineering effort is not happening in a vacuum. European watchdogs warned this month that quantum computing poses a real risk to blockchain systems, adding supervisory weight to what was previously an academic debate. In the United States, federal agencies have published migration guidance for critical infrastructure, and custodians serving regulated ETFs can expect examiners to ask about quantum readiness in coming years.

The competitive angle matters as well. Coinbase is the custodian of record for the largest US bitcoin ETFs, and rivals including Fidelity run their own custody operations. Demonstrating a credible post-quantum roadmap is a way to defend that franchise. It also speaks to corporate treasuries holding bitcoin on long horizons, a group that has grown steadily and has the most to lose from a cryptographic transition handled badly.

There are limits to what any custodian can do alone. If a quantum computer broke elliptic curve signatures tomorrow, the exposed coins include not just custody clients but every address whose public key has been revealed by spending, which is most of them. Exchanges could freeze withdrawals and move assets to quantum-safe addresses, but the network itself would need the upgrade. That is why the industry consensus, such as it is, treats post-quantum custody as preparation for a transition rather than a shield against one.

The research community remains split on timelines. Some estimates for a machine capable of running Shor’s algorithm against elliptic curve cryptography run to the 2030s, others consider the engineering obstacles severe enough to push it beyond any predictable horizon. What almost no researcher disputes is that the transition itself, once triggered, would be messy, since quantum-safe addresses would coexist with legacy outputs for years and markets would price the difference.

For now, the practical effect on customers is none. The system is in design, not production, and no quantum computer capable of breaking elliptic curve signatures exists. The significance is institutional: the largest listed crypto exchange is formally budgeting for a post-quantum future, which gives ETF issuers and corporate treasuries a counterparty that has started the migration clock. Whether Bitcoin’s own upgrade politics can move on a comparable schedule is the open question the engineering cannot answer.

SourcesDecrypt, September 22, 2026; crypto.news; Unchained Crypto; KuCoin News.
Share: X