Summary

  • Coinbase is working on post-quantum custody measures that can accommodate various signature schemes, as explained by Yehuda Lindell, the Head of Cryptography.
  • Conventional Multi-Party Computation (MPC) relies on divided keys, but many post-quantum signature options may not be compatible with MPC.
  • The company is investigating a backup system that integrates post-quantum threshold decryption with programmable Hardware Security Modules (HSMs).

In anticipation of the potential threat posed by quantum computers to Bitcoin's security, Coinbase aims to establish protective measures that can adapt to the evolving landscape of digital assets, according to Yehuda Lindell.

During a recent segment on MARA Foundation TV, Lindell discussed how the firm is designing its post-quantum safeguards to be versatile enough to support various technical adaptations. Currently, the specific post-quantum signature scheme that Bitcoin will adopt remains uncertain.

Myriad: Predict Bitcoin's peak. Join the prediction.

Coinbase, which is responsible for safeguarding approximately $250 billion in assets for institutions like BlackRock, has spent years refining its custody processes. The company is now preparing for scenarios where a fundamental aspect of its operations, such as Multi-Party Computation (MPC), may become more difficult or even impossible for Bitcoin.

MPC functions similarly to Bitcoin's multi-signature arrangements, allowing multiple parties to hold separate “shares” of a private key. This method enables multiple signers to process transactions without exposing the entire private key on a single device.

Unlike Bitcoin's native scripting language, which supports multi-signature setups through on-chain quorum rules, MPC operates off-chain with particular cryptographic functions. In this setup, a requisite quorum of key shares is needed to authorize a transaction, preventing the complete key from being stored in one location and effectively removing a single point of failure.

However, as Bitcoin transitions into the post-quantum era, experts are increasingly concerned that some post-quantum signature schemes may not be conducive to MPC. In particular, hash-based signatures might not possess the necessary arithmetic structure for traditional key-splitting methods. Although this lack of mathematical structure contributes to their presumed security against quantum threats, it complicates the development of MPC-compatible infrastructure.

“The distinction between MPC-friendly and non-MPC-friendly has significant implications,” Lindell noted. While executing MPC with hash-based signatures was deemed impossible until recently, leading cryptographers like Dan Boneh are actively exploring potential solutions, as highlighted in the recent "PRAWNS" paper. However, since this research is still in its experimental stages, it's uncertain whether a workable MPC-like scheme can be realized for hash-based signatures.

Concerns regarding hash-based signatures have also been voiced by wallet developers, including Ledger's CTO Charles Guillemet.

Fallback Hardware Solutions

If Bitcoin adopts a post-quantum scheme that is incompatible with MPC, Coinbase is exploring a fallback framework that revolves around programmable Hardware Security Modules (HSMs), which serve as secure storage for encrypted keys in private data centers.

In this configuration, private keys would be encrypted using post-quantum cryptography and would only be assembled within the secure environment of an HSM. Although temporarily storing a complete key in one location is theoretically less secure than traditional MPC, an HSM offers robust protection within these limitations. Lindell expressed confidence in this setup, citing the stringent physical side-channel defenses and strict controls over code uploads.

With the uncertainty surrounding potential post-quantum upgrades for Bitcoin, Coinbase is crafting its custody framework to be adaptable to any signing scheme that Bitcoin may implement in the future, Lindell stated.

While the timeline for finalizing Coinbase’s post-quantum security measures remains unclear, Lindell mentioned that once completed, he will be able to affirm, "I can support anything. We won't be concerned that some blockchain will choose a method that we cannot accommodate."

André Beganski serves as a Senior Content Manager at MARA Foundation, focusing on topics at the intersection of quantum computing and cryptography. He has previously contributed to Decrypt.

Daily Debrief Newsletter

Stay informed with the latest news stories, original features, podcasts, videos, and more.