If a cryptographically relevant quantum computer eventually becomes an active threat to Bitcoin's security, Coinbase wants to have protections in place that are prepared for whatever direction Bitcoin and other digital assets take, according to Yehuda Lindell.
In a recent appearance on MARA Foundation TV, the crypto exchange’s head of cryptography told host Isabel Foxen Duke that the company’s post-quantum safeguards are being designed to support any potential forms of technical retooling. At the moment, it is unclear what kind of post-quantum signature scheme Bitcoin will use in practice.
Myriad: How high will Bitcoin go? Click to make your prediction.
“It’s unlikely that there will be a single signing scheme that everybody will use,” Lindell said in reference to the standards that various networks will ultimately adopt. “That means we have to be prepared and ready for the different outcomes on different blockchains.”
Safeguarding roughly $250 billion in assets on behalf of institutions such as BlackRock, Coinbase has spent years refining associated procedures. Now it is preparing for a world where a cornerstone of that arrangement becomes more challenging—or even unfeasible in Bitcoin's case: Multi-Party Computation (MPC).
Similar in function to Bitcoin multi-signature setups, MPC allows different parties to hold distinct “shares” of a private key, enabling multiple signers to execute transactions without making whole private keys vulnerable on a single device.
While Bitcoin's native scripting language allows users to create multi-signature setups by enforcing quorum rules directly on-chain, MPC operates off-chain using specific cryptographic functions. Because a certain quorum of key shares is required to sign a single transaction, the complete key is never assembled in one location, effectively eliminating a single point of failure.
But as Bitcoin prepares for the post-quantum era, there is growing concern among experts that not all post-quantum signature schemes will be “MPC-friendly.” Specifically, hash-based signatures may lack the underlying arithmetic structure that makes traditional cryptographic key-splitting possible. While this lack of mathematical structure is why hash-based signatures are presumed to be secure against quantum threats, it also makes them difficult to work with when building infrastructure for MPC.
“MPC-friendliness or non-MPC-friendliness makes a very big difference,” Lindell explained. While executing MPC with hash-based signatures was presumed impossible up until recently, leading cryptographers like Dan Boneh are actively researching potential solutions, as detailed in the recent "PRAWNS" paper. However, because this research is in a highly experimental phase, it is still unclear if a viable MPC-like scheme can be developed for hash-based signatures.
Concerns about hash-based signatures have also been raised by wallet developers including Ledger CTO Charles Guillemet.
The hardware fallback
In the event that Bitcoin adopts a post-quantum scheme incompatible with MPC, Coinbase is researching a fallback architecture centered on programmable Hardware Security Modules (HSMs)—digital vaults for encrypted keys inside private data centers.
Under this arrangement, private keys would be encrypted with post-quantum cryptography and only assembled within the confines of a physically secure HSM.
Although keeping a complete key in one place—even momentarily—is theoretically less secure than traditional MPC, an HSM provides strong protection within these constraints. Lindell noted that the rigorous physical side-channel protections and strict code-upload controls support his comfort with the setup.
Given the uncertainty around a potential post-quantum upgrade for Bitcoin, Coinbase is designing its custody architecture to be agnostic and adaptable to whatever signing scheme Bitcoin adopts in the coming years, Lindell said.
Although the timeline to complete Coinbase’s post-quantum security measures is still uncertain, Lindell added that, once it is complete, “I will be able to say, ‘I can support anything.’ We don't have the fear that some blockchain [is going to] decide to use something that we just won't be able to support.”
André Beganski is a Senior Content Manager at MARA Foundation, producing content on topics including the intersection of quantum computing and cryptography. He has previously worked for Decrypt.
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。