Back to Trust Center

Exchanges & Custodians Primary

Cryptographic Primitives

Regulated institutions run on cryptographic trust. Banks, asset managers, payment processors, market infrastructure operators and critical infrastructure providers depend on cryptography for every authenticated transaction.

Industry Context

Regulated crypto exchanges and custodians sit at the trust centre of digital-asset markets. They hold client assets, settle transactions, produce proof-of-reserves attestations, and generate the audit records that regulators, counterparties, and institutional clients rely on. Trust is not a feature of the business — it is the business. A custodian that cannot demonstrate the integrity of its holdings and its records has nothing to sell.

That trust rests almost entirely on public-key cryptography. Wallet infrastructure, transaction signing, settlement rails, and the supporting enterprise stack depend on elliptic-curve and RSA signature schemes. The same schemes secure the compliance artefacts a venue must keep — signed attestations, audit exports, registers — for years after they are created. The exposure extends to the assets themselves: the ECDSA keys securing custodied funds are quantum-vulnerable in exactly the same way as the records they sit alongside. That chain-level exposure is real and partly outside any single venue’s control — which is why readiness starts with the surface a venue does control: its records, its signing infrastructure, and its attestations.

The operating environment is tightening on every axis. Institutional capital is entering the asset class through regulated venues, not unregulated ones. Licensing regimes are maturing, and with them the expectation that an exchange or custodian can evidence not only that it is secure today, but that the records it produces will remain verifiable into the future. Auditors increasingly ask not just “is this signed?” but “will this signature still mean something in ten years?”

This is where long-term cryptographic integrity stops being a technical detail and becomes a governance question. A custody record or a proof-of-reserves attestation is only as durable as the cryptography underneath it. If that cryptography has a known expiry, so does the trust it underwrites — unless the venue has prepared for the transition before the expiry arrives.

Business Risk & Exposure

Doing nothing is not a neutral position. It is an accumulating, unquantified liability. That holds even for those who judge a cryptographically relevant quantum computer to be decades away: the exposures below accrue from data captured and records signed today, and the regulatory deadlines are already dated. Neither waits for the hardware.

The most immediate exposure is harvest-now-decrypt-later. State-level actors are already capturing encrypted data at scale on the assumption that it can be decrypted once cryptographically relevant quantum capability exists. For an exchange or custodian, the sensitive material — client records, historical transaction flows, and internal communications — has a long shelf life. The decryption deadline is, on any prudent planning horizon, a question of when, not if, and data captured today is exposed against that future date regardless of what the venue does next year. History also says the migration itself takes years: the SHA-1 and 3DES deprecations each took five to ten years or more to work through the industry, so the work has to start well before the threat is imminent — not once it arrives.

The second exposure is long-term record integrity. A proof-of-reserves attestation, a compliance export, or a custody confirmation signed today must remain verifiable years later. If the signature scheme behind it is broken or deprecated in the interim, the record’s evidentiary value degrades — quietly, and usually unnoticed until it is needed in an audit or a dispute.

The third is cryptographic dependency risk. ECC and RSA are buried throughout the stack: in signing services, wallet infrastructure, internal PKI, and vendor platforms a venue does not control. Most exchanges and custodians cannot produce a complete inventory of where they rely on these schemes — which means they cannot scope their own exposure, let alone govern it. This is the governance blind spot: you cannot manage, prioritise, or defend what you have not mapped.

The cumulative effect is future scrutiny risk. As deadlines approach, regulators, auditors, and institutional clients will ask for migration plans. The venues that can produce a credible, evidenced roadmap will clear those conversations. The venues that cannot will face the migration as an emergency — under time pressure, with weaker negotiating position and higher cost.

The point a board should take from this is simple: post-quantum readiness is a business-risk and governance issue first, and a technical project second.

The Infrastructure Challenge

The reason this is hard is not a shortage of post-quantum algorithms. The standards exist. The challenge is that the infrastructure most venues run today was never built to answer the questions readiness now requires.

There is a visibility gap: no authoritative inventory of where cryptographic schemes are relied upon across owned systems and inherited dependencies. There is a governance gap: no clear owner of cryptographic risk, no roadmap, no defined triggers for action. There is a trust gap: attestations and records depend both on classical signature schemes and on the issuer remaining the single, continuous point of trust — if the issuer’s keys are compromised or the issuer ceases to exist, the record’s integrity is no longer independently provable.

Underlying all of these is a capability that is genuinely difficult to maintain over long horizons: the ability to prove that a specific record existed at a known point in time and has not changed since — independently of the issuer, and durably enough to survive the deprecation of whatever cryptography secured it originally. Conventional infrastructure ties that proof to the issuer and to a single signature scheme. Neither assumption holds across a ten- or fifteen-year retention window that crosses a cryptographic transition.

The reader should take away that existing infrastructure is not wrong — it is simply not designed for the readiness requirements now arriving, and closing that gap is an infrastructure question, not a patch.

Future-State Architecture

A prepared exchange or custodian looks materially different from today’s default. It holds a complete, maintained inventory of its cryptographic dependencies and a named owner for them. It runs a NIST-aligned roadmap with crypto-agile signing patterns, so a change of primitive is a configuration decision rather than a re-architecture. Its proof-of-reserves attestations and audit records carry integrity proofs that are independently verifiable against a public post-quantum blockchain — provable without relying on the venue’s continued existence or key hygiene. And it can answer a regulator’s migration question with evidence rather than intention.

The operational improvement is that readiness stops being a looming, undated risk and becomes a governed, business-as-usual posture. The trust improvement is that the venue’s most important records — the ones clients and regulators depend on — are durable across the transition that is coming for everyone else.