Coinbase is building a post-quantum version of CoreKMS, mapping cryptographic dependencies across the company, and joining industry efforts to help Bitcoin prepare for a future quantum threat.
Coinbase said it is building a post-quantum version of its CoreKMS key management system, which protects about 99.9% of the assets it custodies, as part of a broader plan to prepare for the eventual arrival of fault-tolerant quantum computing. The exchange said it aims within the next year to deliver an automated signing pipeline using secure enclaves, secret-sharing and threshold cryptography that can support any post-quantum signature algorithm, followed by a two- to three-year research effort to develop full multi-party computation capabilities for post-quantum signing schemes. The company is also inventorying cryptographic dependencies across authentication, customer data protection and internal systems, ranking them by migration priority and defining technical milestones in quantum computing progress that would trigger migration. For Base, Coinbase said Ethereum has published its own post-quantum roadmap and the Layer 2 inherits much of that protection through its relationship with the base layer. Coinbase said stronger custody alone would not protect Bitcoin if its underlying signature scheme remains vulnerable. To address that, it will co-host a working session with Stanford in August for Bitcoin core developers, cryptographers and researchers, and is a founding member of the Bitcoin Security Consortium launched Thursday alongside BlackRock, Fidelity Digital Assets, Block, Blockstream, Strategy, Anchorage Digital, ARK Invest and Galaxy. The Crypto Times reported the nine members pledged a combined $15 million over three years, while disclaiming any governance role. Coinbase said it is supporting open-source work including proposals such as BIP-360. Coinbase's research estimates 20% to 50% of Bitcoin's supply could face exposure to a long-range quantum attack, particularly in older wallet formats. The company argued the timing debate is less important than the years required to coordinate migration across users, custodians and decentralized protocols.