Skip to content

Invest1 publisher3 min readPublished

Coinbase's quantum fallback puts a whole bitcoin key back inside one box

Head of cryptography Yehuda Lindell says hash-based post-quantum signatures may not split across parties. So Coinbase is researching threshold decryption plus a programmable HSM for the $250 billion it custodies.

The Investor · Invest desk

Illustration accompanying Coinbase's quantum fallback puts a whole bitcoin key back inside one box

What happened

  • Coinbase's head of cryptography, Yehuda Lindell, said the exchange is building post-quantum custody safeguards meant to support a wide range of signature schemes, whichever one each blockchain adopts.
  • Coinbase safeguards roughly $250 billion in assets on behalf of institutions such as BlackRock, the book this custody architecture would eventually have to carry.
  • Cryptographers including Dan Boneh are researching MPC-like schemes for hash-based signatures in a paper called PRAWNS, work Decrypt describes as highly experimental.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • constraint Should Bitcoin adopt a hash-based scheme, the selling point of MPC custody, that no single device ever holds the key, stops being available for that chain. The best remaining answer is a physically hardened room.
  • decision Institutional clients would have to accept an architecture in which a complete private key exists, briefly, on one device, and decide what audit and indemnity they need around it.
  • exposure Custodians that market split-key MPC as their differentiator are exposed to a technical choice made by protocol developers.
  • precedent If no single signing scheme wins across chains, multi-scheme support becomes a procurement question for anyone buying custody.

In the architecture Coinbase is researching, the shares survive and what they unlock changes. Several parties hold the pieces needed for post-quantum threshold decryption, and the key they decrypt is assembled inside a programmable hardware security module sitting in a private data centre [3][10]. Signing happens there, on one device, with the complete key present.

According to Decrypt's account of the interview, holding a complete key in one place even momentarily is theoretically less secure than traditional multi-party computation, where the whole key is never assembled anywhere [11][4]. Lindell pointed to rigorous physical side-channel protections and strict controls on what code can be uploaded to the module [11].

The reason to contemplate any of this is a property of hash-based signatures. They may lack the underlying arithmetic structure that key-splitting depends on, and that same absence of structure is why they are presumed to resist quantum attack [5]. "MPC-friendliness or non-MPC-friendliness makes a very big difference," Lindell said [6].

Bitcoin has not settled on a scheme [16]. "It's unlikely that there will be a single signing scheme that everybody will use," Lindell said. "That means we have to be prepared and ready for the different outcomes on different blockchains" [7][8]. Until recently, doing MPC with hash-based signatures was presumed impossible. Dan Boneh and other cryptographers are now working on it, in a paper called PRAWNS, and Decrypt describes the research as highly experimental with no certainty that a viable scheme emerges [12]. Ledger's chief technology officer, Charles Guillemet, has raised the same worry about hash-based signatures [13].

Coinbase did not give a completion date for the work [14]. The book behind it is roughly $250 billion held for institutions including BlackRock [9], and the account of the programme is one executive's appearance on MARA Foundation TV, hosted by Isabel Foxen Duke [1].

A lattice-style winner that splits cleanly leaves the hardware path unused. A hash-based winner puts the module on the production path for the whole custody book. The property institutions were sold, that no single device ever holds the key [4], becomes something Coinbase has to argue for on physical grounds. If the PRAWNS line of work produces a practical threshold scheme, signing stays distributed and the fallback is dead code [12].

I'd expect the middle branch to be settled contractually well before it is settled cryptographically. Which document permits the key to be assembled, which auditor covers the module, who bears the loss if the data centre's physical controls are breached. The counter-case is straightforward, and Lindell makes it himself, that the physical and code-upload controls on a hardware security module are strong enough to live with [11]. He said that once the work is finished, "I will be able to say, 'I can support anything.'" [15]

What to watch

  • Which post-quantum signature family Bitcoin's upgrade proposals converge on, and whether it splits across parties.
  • Whether Coinbase names a completion date or publishes custody terms covering the hardware-module path.
  • Whether other MPC-based custodians state publicly how they would handle a non-MPC-friendly signature scheme.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories