Coinbase is in the process of developing a post-quantum custody framework aimed at securing approximately $250 billion in institutional investments. This system is designed to accommodate any new signature methodologies adopted by Bitcoin or other blockchain technologies.

Coinbase Enhances Custody for Various Signature Options

During an appearance on MARA Foundation TV, Coinbase’s Chief Cryptographer, Yehuda Lindell, discussed the company’s goal of ensuring its custody infrastructure remains adaptable, irrespective of the post-quantum signature protocols that blockchain platforms may eventually adopt.

As of now, Bitcoin has not officially selected a signature method for practical post-quantum applications, leaving custodians without a unified technical standard to guide system upgrades. Lindell remarked that different blockchain developers might select various options, rather than converging on a single standard.

To address this uncertainty, Coinbase is preparing for multiple potential scenarios instead of centering its system around one specific choice. Lindell emphasized the need to avoid situations where a blockchain endorses a signature method that cannot be accommodated by their custody infrastructure.

This initiative is particularly crucial as Coinbase manages about $250 billion in assets belonging to institutional clients, including prominent firms like BlackRock, which utilizes Coinbase Custody for its digital investment products.

A custody review conducted in August estimated Coinbase’s institutional assets to be approximately $376 billion, stating that the company secures over 80% of the holdings in U.S. spot Bitcoin and Ethereum exchange-traded funds. The differing figures might arise from variations in reporting periods and the types of services or assets included in those assessments.

Custody systems are responsible for safeguarding the private keys essential for transaction authorization. Consequently, any alterations to Bitcoin’s signature procedures would necessitate significant updates to the technology used for creating, storing, and executing these keys.

Post-Quantum Signatures Challenge Current MPC Custody Models

Many institutional custody platforms utilize Multi-Party Computation (MPC) to split control of a private key across multiple entities. This mechanism ensures that no single participant requires the full private key to authorize a transaction.

Lindell noted that numerous post-quantum signature methodologies may not be compatible with MPC due to their distinct mathematical frameworks when compared to the signatures currently employed in major blockchains. For instance, hash-based signatures present challenges as they do not possess the arithmetic structure that traditional cryptographic key division relies on.

Researchers, including Stanford’s Dan Boneh, are investigating potential methods for integrating MPC-like controls with these signatures. However, Lindell cautioned that this research is still in experimental stages, and it remains uncertain whether a functional MPC-equivalent system for hash-based signatures can be developed.

Coinbase’s exploration into this domain began even before the latest custody system design. In January, the company established a separate advisory board focused on quantum computing and blockchain, featuring experts like Boneh, Lindell, Ethereum researcher Justin Drake, University of Texas professor Scott Aaronson, EigenLayer’s Sreeram Kannan, and distributed-systems authority Dahlia Malkhi.

Coinbase’s roadmap for post-quantum advancements encompasses updates to Bitcoin address processing, enhancements to internal key-management utilities, and research into employing schemes such as ML-DSA within the MPC framework. This advisory group is tasked with evaluating quantum developments, making recommendations, and reacting to significant technical breakthroughs.

Other custodians have also begun exploring feasible options. In June, BitGo collaborated with Silence Laboratories to test quantum-safe MPC by implementing an ML-DSA-based protocol into its custody system. This simulation maintained distributed key management, policy compliance, and responsibility segregation as reported by the involved companies.

ML-DSA is part of FIPS 204, a post-quantum digital signature standard released by the U.S. National Institute of Standards and Technology. Lindell’s comments suggest that Coinbase is aiming for an architecture that can manage schemes beyond ML-DSA should Bitcoin or other networks adopt alternative designs.

Hardware Security Modules Offer Custody Backup

To lessen reliance on MPC compatibility, Coinbase is considering a backup system centered around programmable Hardware Security Modules (HSMs), as per Lindell.

HSMs are safeguarded devices designed to store cryptographic materials and perform secure operations. Under the proposed architecture, private keys would remain encrypted with post-quantum cryptography and would only be assembled within secure HSMs.

Storing the entire key inside a protected module would enable the custodian to engage with signature methods that cannot be split using traditional MPC. These programmable modules would also provide Coinbase with the flexibility to adapt as blockchain developers implement new standards.

Lindell did not specify a timeline for completion, acknowledging that the technical development may take considerable time. However, once finalized, he anticipates Coinbase will function effectively without needing to predict the post-quantum methods chosen by different networks.

“I will be able to say, I can support any scheme,” Lindell stated.

As this proposed model necessitates enhanced physical security, the full key would briefly reside within an HSM. Therefore, Coinbase must ensure that these modules can carry out signing operations without exposing the key to external software or personnel.

This method would not force Coinbase to abandon MPC for compatible signature protocols, rather, the HSM framework would act as an alternative custody option when a network’s selected cryptography cannot integrate with distributed key generation and signing processes.

Bitcoin Lacks a Quantum Migration Strategy

Currently, Bitcoin employs elliptic-curve cryptography, and no publicly demonstrated quantum computer can derive private keys from accessible public keys. Nevertheless, researchers and industry stakeholders have advocated for proactive measures because altering Bitcoin’s security framework will necessitate software development, testing, wallet enhancements, and achieving network consensus.

According to a report from Crypto.news in June, Coinbase’s advisory board urged Bitcoin developers to start formulating migration tools ahead of the advent of a cryptographically relevant quantum computer. The board highlighted that nearly 1.7 million $BTC are held in older pay-to-public-key formats with vulnerable public keys, while address reuse could place around 5 million $BTC at future risk.

The advisory board did not recommend actions such as freezing, burning, or keeping susceptible coins available for potential future attackers. It emphasized that the Bitcoin community should collectively decide via its consensus process how to handle coins that remain in outdated address formats beyond any migration cutoff.

Various draft proposals are currently examining different aspects of the migration challenge. BIP 360, also known as Pay-to-Merkle-Root, aims to remove the Taproot option that is vulnerable to quantum attacks, while BIP 361 outlines a gradual phase-out of legacy ECDSA and Schnorr signatures once Bitcoin implements a post-quantum output method.

Neither of these proposals has been enacted yet. Furthermore, a recent review found that SHRINCS, an experimental hash-based signature model under discussion, remains an unnumbered draft that requires further evaluation and a confirmed security proof.

For U.S. investors, Coinbase’s initiatives pertain to assets held through regulated investment vehicles as well as coins retained by direct institutional clients. Investors in spot Bitcoin and Ethereum ETFs do not manage the private keys associated with their holdings; those keys are overseen by custodians appointed by the fund issuers.

Coinbase’s capacity to support various signature methodologies could prove significant if Bitcoin, Ethereum, or any other networks utilized by U.S.-listed funds elect to adopt new cryptographic techniques. Nonetheless, any blockchain transition will depend on network regulations and the actions of users, wallet providers, exchanges, custodians, and fund operators, rather than solely on Coinbase’s decisions.

Share.