Coinbase’s $250B Plan for Post‑Quantum Bitcoin Custody: MPC Limits, HSM Fallback, and a Scheme‑Agnostic Bet

Coinbase is engineering post‑quantum Bitcoin custody to stay signing‑scheme agnostic, weighing MPC limits and a programmable HSM + threshold decryption fallback for $250B in assets.

Bitcoin
Cryptocurrency
Regulations
Economy
Because Bitcoin
Because Bitcoin

Because Bitcoin

September 23, 2026

Coinbase is building for a Bitcoin future where no single post‑quantum (PQ) standard dominates—and where today’s Multi‑Party Computation (MPC) may no longer be the default. Head of Cryptography Yehuda Lindell said on MARA Foundation TV with Isabel Foxen Duke that the exchange’s architecture is being designed to slot in whatever signing scheme Bitcoin ultimately embraces. The interesting tension is not whether a quantum‑resilient migration is needed, but how to preserve institutional‑grade controls if the most practical PQ signatures refuse to play nicely with MPC.

Why the “MPC vs. PQ” collision matters - Institutional custody today leans heavily on MPC: key material is split into shares, thresholds enforce quorum, and the full private key never exists on a single device. Bitcoin’s on‑chain multisig offers a similar access policy, but MPC runs off‑chain with cryptographic protocols that simulate a single signer. - Many leading PQ candidates—especially hash‑based signatures—lack the algebraic structure that makes secret‑sharing and joint signing straightforward. That structural absence is precisely why they are considered resistant to quantum attacks, yet it also makes “MPC‑friendly” constructions harder to realize. - Until recently, MPC for hash‑based signatures was often assumed infeasible. New work, including Dan Boneh’s “PRAWNS,” explores MPC‑like approaches, but it remains early‑stage. Ledger CTO Charles Guillemet has voiced related concerns from the wallet side, underscoring that production‑grade paths are not settled.

Agnostic by design, with a hardware backstop Lindell expects fragmentation across networks: it’s unlikely a single PQ signing approach will win everywhere, and Bitcoin’s final choice is still unclear. To avoid being cornered by any one standard, Coinbase is developing safeguards that support a range of schemes and a fallback when MPC breaks down.

That fallback blends post‑quantum threshold decryption with programmable Hardware Security Modules (HSMs). In this model: - Private keys are encrypted using PQ cryptography. - Decryption shares are combined to reconstruct the key only inside a physically secure, programmable HSM. - Strict code‑upload controls and hardened side‑channel protections aim to contain risk while enabling policy enforcement, auditing, and automation.

This concedes a point MPC tries to avoid: the full key exists—briefly—in one place. Lindell argues the HSM’s physical and logical guarantees, combined with threshold gates and operational controls, can keep residual risk within acceptable bounds if MPC‑like signing is unavailable for a chosen PQ scheme.

Business reality: $250B demands continuity Coinbase safeguards roughly $250 billion for institutions including BlackRock. For clients of that scale, custody is not just cryptography—it is process assurance. An MPC‑unfriendly Bitcoin upgrade would challenge standard playbooks for quorum enforcement, disaster recovery, and incident response. A programmable HSM approach preserves determinism and policy checks, keeps workflows auditable, and reduces the chance that any given blockchain’s PQ choice strands assets operationally. It also mitigates psychological risk: institutions want to hear that their provider can maintain controls even if standards diverge.

Technically, a scheme‑agnostic stack provides optionality if: - Bitcoin favors hash‑based signatures that frustrate MPC. - Alternative L1s choose lattice‑ or code‑based schemes with different trust boundaries. - Academic breakthroughs like PRAWNS mature—or stall.

What to watch next - Standardization drift: If Bitcoin picks a non‑MPC‑friendly path, expect HSM‑centric custody to gain momentum across providers. - Research cadence: Progress on MPC‑like protocols for hash‑based signatures could re‑tilt the trade‑off back toward pure MPC. - Vendor ecosystem: Programmable HSM capabilities and certification pipelines will become strategic. - Migration clocks: Timelines are undefined. Lindell suggested that once Coinbase completes the buildout, they expect to “support anything,” reducing the risk that any blockchain’s PQ choice becomes a non‑starter for custody.

The core insight here is pragmatic: in a PQ world, control planes may need to shift from purely mathematical dispersal (MPC) to a hybrid that accepts carefully bounded hardware trust. For institutions, that blend often balances cryptographic rigor with operational reality—without betting the firm on a single, still‑evolving standard.