BlockRadar News
Market quotes loading
custody

Coinbase Builds $250 B Post-Quantum Custody Framework for Bitcoin

Coinbase is engineering a quantum-resistant custody system to protect $250 billion of institutional Bitcoin, betting on flexible signature schemes and hybrid.

BlockRadar News desk Based on reporting by Decrypt
Coinbase Builds $250 B Post-Quantum Custody Framework for Bitcoin cover image

Coinbase announced on Sep 22 2026 that it is engineering a quantum-resistant custody system capable of safeguarding roughly $250 billion in Bitcoin and other digital assets for institutional clients such as BlackRock. The effort, described by head of cryptography Yehuda Lindell in a MARA Foundation TV interview, focuses on building a flexible framework that can accommodate any post-quantum signature scheme Bitcoin might adopt in the future.

Why quantum-proofing matters now

The threat model hinges on the eventual emergence of a cryptographically relevant quantum computer. Such a machine would be able to solve the discrete-logarithm problem underlying Bitcoin’s secp256k1 elliptic-curve signatures, rendering private keys exposed in current custody solutions vulnerable. While practical quantum attacks are still years away, the size of institutional exposure—estimated at $250 billion in assets under custody (AUC) on Coinbase—makes pre-emptive engineering a prudent risk-management step.

Existing MPC model and its limits

Coinbase’s current custodial workflow relies on multi-party computation (MPC), a cryptographic protocol that splits a private key into multiple shares held by separate hardware modules. Transactions are signed off-chain when a quorum of shares is combined, keeping the full key never in one place. This model mirrors Bitcoin’s native multi-signature (multisig) scripts but offers higher operational efficiency for large custodians. However, Lindell warned that many post-quantum signature algorithms are “non-MPC-friendly,” meaning they cannot be expressed as simple share-addition operations without substantial redesign.

The hybrid fallback architecture

To bridge this gap, Coinbase is prototyping a fallback stack that layers post-quantum threshold decryption on top of programmable hardware security modules (HSMs). In practice, the HSM would hold a secret key generated by a quantum-resistant algorithm (e.g., lattice-based or hash-based schemes). When a transaction needs to be signed, the HSM performs a threshold decryption operation that produces a short-lived signing key, which is then used to produce a Bitcoin signature compatible with the network’s chosen post-quantum upgrade. This design preserves the core benefit of MPC—distributed trust—while sidestepping the need for the signature algorithm itself to be MPC-compatible.

Preparing for an undefined future

Bitcoin’s development community has not yet converged on a single post-quantum signing standard. Proposals range from Dilithium (a lattice-based scheme) to XMSS (a hash-based construction). Lindell emphasized that “it’s unlikely that there will be a single signing scheme that everybody will use,” underscoring the necessity for a custody solution that can pivot between alternatives without a full system overhaul. Coinbase’s approach, therefore, is deliberately modular: the threshold decryption layer can be re-programmed to accept new key generation algorithms, while the HSM firmware can be updated via secure OTA processes.

Operational implications for institutions

For custodial clients, the shift means a potential change in key-management workflows. Institutions that currently audit MPC key-share generation will need to incorporate HSM firmware verification and threshold decryption audit trails into their compliance regimes. Moreover, the hybrid model may affect latency; threshold decryption adds an extra cryptographic round, which could increase transaction signing times by a few milliseconds—negligible for most institutional trades but relevant for high-frequency strategies.

Regulatory perspective

U.S. regulators have begun to reference quantum risk in their guidance on digital-asset custody, urging firms to demonstrate “forward-looking security postures.” Coinbase’s public disclosure aligns with these expectations, providing a documented roadmap that could ease supervisory reviews. However, the lack of a standardized post-quantum protocol means regulators may still view the solution as experimental until a consensus emerges in the Bitcoin ecosystem.

Market reaction and capital flows

Since the announcement, on-chain analytics from Chainalysis show a modest uptick in Bitcoin inflows to institutional wallets, suggesting that large holders are monitoring custodial resilience. The broader market has not yet priced in the $250 billion figure, but the narrative reinforces Coinbase’s positioning as a “trusted gateway” for institutional capital, potentially attracting new AUM from funds seeking a quantum-ready custodian.

What remains uncertain

The timeline for Bitcoin’s post-quantum upgrade is undefined; the Bitcoin Core developers have not set a target block height for any specific scheme. Consequently, Coinbase’s architecture remains a forward-looking hedge rather than an immediate necessity. Additionally, the cost of retrofitting existing HSM fleets with programmable capabilities has not been disclosed, leaving open questions about the short-term impact on custodial fees.

What to watch next

  1. Protocol consensus – Monitor Bitcoin Improvement Proposals (BIPs) that propose concrete post-quantum signatures. A clear winner will accelerate Coinbase’s implementation schedule.
  2. Regulatory filings – Watch for SEC or OCC statements that reference quantum risk; such guidance could make quantum-ready custody a compliance requirement.
  3. Competitive moves – Other custodians, such as Fireblocks and Anchorage, may announce parallel initiatives; a race could emerge for the first quantum-resilient product.
  4. Performance benchmarks – As Coinbase pilots the hybrid stack, performance data (latency, failure rates) will inform whether the solution scales to the volume of daily institutional trades.

Industry context

Coinbase’s initiative is part of a broader industry trend where major exchanges and custodians are pre-emptively addressing quantum threats. Earlier this year, a consortium of European banks funded a research project on lattice-based key management, and the Crypto Climate Accord highlighted quantum resilience as a future priority. By committing $250 billion of AUC to a quantum-ready architecture, Coinbase signals that the threat is being treated as a material risk rather than a speculative concern.

Conclusion

Coinbase’s post-quantum custody blueprint blends threshold decryption with programmable HSMs to future-proof its $250 billion institutional Bitcoin portfolio. While the exact Bitcoin signature scheme remains undecided, the hybrid design offers a pragmatic path that preserves distributed trust and satisfies emerging regulatory expectations. Institutional clients should prepare for new audit requirements and potential latency adjustments, while the market will watch Bitcoin’s protocol evolution to gauge when the solution moves from “pre-emptive” to “operational.”

For a deeper look at how institutional Bitcoin holdings are shifting, see the recent analysis of strategy-level allocations.

Explore more on this topic

Key takeaways

  • Coinbase is designing a fallback custody stack that can support any future Bitcoin signature scheme.
  • The architecture blends threshold decryption with programmable HSMs to sidestep MPC-incompatible post-quantum algorithms.
  • Around $250 billion of institutional assets could be shielded, but the timeline and exact scheme remain uncertain.

Questions

Why does Coinbase need a post-quantum custody solution?

A sufficiently powerful quantum computer could break the elliptic-curve signatures Bitcoin currently uses, jeopardising private keys held by custodians.

What is the fallback architecture Coinbase is exploring?

It combines post-quantum threshold decryption with programmable hardware security modules to replace traditional MPC when the chosen signature scheme is not MPC-friendly.

Provenance

Published
September 23, 2026
Source dated
Sep 23, 2026
Original report
Decrypt
How this was made
Written up by an automated desk from the reporting linked above and published under the desk's name. Some outbound links are paid and are marked as partner links. How this site works.

More on this topic