Coinbase Is Building Bitcoin Custody for a Quantum Upgrade That Does Not Exist Yet
• September 22, 2026 11:23 pm • CommentsBitcoin does not have a working quantum computer at its door today. It has something more immediate for the companies holding billions of dollars in customer assets: a migration problem with no settled destination.
Decrypt reports that Coinbase is designing its institutional custody systems to remain adaptable to whatever post-quantum signature scheme Bitcoin eventually adopts. That sounds abstract until you consider the scale.
Coinbase safeguards roughly $250 billion in assets, and custody architecture cannot be rebuilt casually after a cryptographic emergency arrives. Institutional clients also depend on approval rules, recovery procedures and audit trails built around today’s signing systems. A migration therefore has to protect more than a private key: it must preserve the operational controls that determine who can authorize a transaction, how access is restored and where sensitive material can exist.
Choosing a stronger signature is only the first hurdle. Modern institutional custody often relies on multi-party computation, or MPC, which splits signing authority so no single machine ever holds the complete private key.
Many leading post-quantum signature designs do not fit that model cleanly.
Coinbase Head of Cryptography Yehuda Lindell described a design meant to stay agnostic about the eventual winner. That matters because Bitcoin has not selected a post-quantum signature scheme, much less activated one across the network.
The architecture would keep the policy layer flexible while moving sensitive reconstruction and signing into hardened hardware. Coinbase could then adapt to a vetted scheme later without throwing away the controls institutions already use to separate authority, recover access and audit every operation.
Coinbase is studying a fallback that combines post-quantum threshold decryption with programmable hardware security modules. Encrypted signing material could be divided among multiple parties, reconstructed only inside hardened hardware and used under strict policy controls.
The goal is to preserve the security benefits institutions expect without betting the whole custody stack on one future algorithm.
⚛️ Bitcoin does not have a quantum computer problem today. It has a migration problem, and migrations could take years to get right.
SHRINCS is the first Bitcoin-specific post-quantum proposal I have seen that makes a serious end-to-end trade-off, and it deserves to be read…
— Charles Guillemet (@P3b7_) September 16, 2026
Ledger Chief Technology Officer Charles Guillemet put the issue cleanly: today’s risk is the time a safe migration could require. The distinction matters.
Panic would be premature. Waiting for a cryptographically relevant machine to appear would be reckless.
Bitcoin’s eventual choice is still open. Hash-based proposals such as SHRINCS trade compactness and familiar wallet behavior for security assumptions built around hashing rather than elliptic-curve mathematics.
Other approaches may offer different compromises in signature size, state management, backup recovery and hardware support. Any winner must survive public review, wallet integration and a difficult network-upgrade process.
StarkWare’s current quantum-security library shows how quickly the field is moving. Researchers have already demonstrated specialized quantum-safe Bitcoin transactions under existing rules, while separate teams continue working on signatures and migration paths.
Those experiments are useful proof points. A network-wide upgrade that ordinary holders can use safely remains unfinished.
There are 3 things you should look at when talking about the race to post-quantum security:
(1) Can a chain become PQS?
(2) How fast can it get there?
(3) Will users be able to migrate seamlessly?Starknet is at the front of this race on all three, thanks to ZK-STARKs and… https://t.co/5RgKxxMb5y pic.twitter.com/Sfrs3RULAJ
— Eli Ben-Sasson | Starknet.io (@EliBenSasson) August 25, 2026
Those three questions—whether a chain can upgrade, how quickly it can do it and whether users can migrate without losing access—are also the right test for Bitcoin custody. A mathematically sound signature scheme is not enough if exchanges, hardware wallets and recovery systems cannot deploy it at scale.
Coinbase’s work is therefore less a prediction about which algorithm will win than an acknowledgment that custody providers need optionality. The best outcome is a system that can swap in a vetted post-quantum signing method without forcing institutions to rebuild every access control, backup process and compliance layer around it.
The work is quiet infrastructure, not a flashy breakthrough. It is the kind of plumbing that matters most when the stakes are enormous—and when the migration window may be much shorter than the engineering project.
Join the conversation!
We have no tolerance for comments containing violence, racism, profanity, vulgarity, doxing, or discourteous behavior. If a comment is spam, instead of replying to it please click the icon below and to the right of that comment. Thank you for partnering with us to maintain fruitful conversation.
