Free exchange diagnostic

Evidence reviewed 2026-09-03

One of six sampled exchanges publishes post-quantum custody work.

For exchange custody, security, and risk teams, exchange.fail checks four migration gates: risk recognition, cryptography inventory, custody signer upgrades, and customer asset migration.

Exchanges sampled
6
Custody programs published
1
Customer migration dates
0

This is a limited public-disclosure sample, not a penetration test. A missing item means it was not present in the cited official source. It does not prove that internal work is absent or that an exchange is insecure today.

Public readiness sample

Every exchange below acknowledges quantum risk in an official source. The gap is operational evidence. Coinbase is the only company in this sample that describes both an internal inventory and custody signer work.

Coinbase

Exchange and institutional custody

Program published
Crypto inventory
Inventory in progress
Custody signer
PQ-CoreKMS in progress
Customer migration
No date published

Coinbase describes a company-wide cryptography inventory and a post-quantum custody signing pipeline. Its article does not publish a customer asset migration date.

Open official source

Binance

Exchange and custody

Risk acknowledged
Crypto inventory
Not in reviewed source
Custody signer
Not in reviewed source
Customer migration
Not in reviewed source

Binance Academy explains how quantum computing could affect wallet signatures and summarizes NIST standards. The reviewed article does not describe an exchange-operated migration program.

Open official source

OKX

Exchange and custody

Risk acknowledged
Crypto inventory
Not in reviewed source
Custody signer
Not in reviewed source
Customer migration
Not in reviewed source

OKX Learn describes the structural quantum risk to Bitcoin and Ethereum. The reviewed article does not document internal inventory, custody signer work, or a customer migration plan.

Open official source

Gemini

Exchange and qualified custody

Risk acknowledged
Crypto inventory
Not in reviewed source
Custody signer
Not in reviewed source
Customer migration
Not in reviewed source

Gemini's educational material recognizes the threat to Bitcoin public-key cryptography and the availability of post-quantum alternatives. It does not publish a Gemini custody migration program.

Open official source

Kraken

Exchange and institutional custody

Risk acknowledged
Crypto inventory
Not in reviewed source
Custody signer
Not in reviewed source
Customer migration
Not in reviewed source

Kraken's Bitcoin risk statement acknowledges that sufficiently advanced quantum computers could weaken current elliptic-curve cryptography. The reviewed disclosure does not include an operating plan.

Open official source

Crypto.com

Exchange app and custody services

Risk acknowledged
Crypto inventory
Not in reviewed source
Custody signer
Not in reviewed source
Customer migration
Not in reviewed source

Crypto.com's Canadian risk statement identifies quantum computing as a possible security risk to cryptography-based systems. The reviewed disclosure does not describe implementation or migration milestones.

Open official source

What a complete answer looks like

A useful exchange plan links protocol migration to custody operations and customer communication. Awareness by itself is not a runbook.

  1. 1

    Inventory

    Map every signing, identity, transport, and asset dependency.

  2. 2

    Triggers

    Define measurable events that start staged migration.

  3. 3

    Custody path

    Test signer, HSM, MPC, recovery, and withdrawal changes.

  4. 4

    Customer migration

    Publish supported assets, deadlines, fallback states, and communications.

Make the migration plan public.

Submit stronger official evidence for this index, or bring your security and custody team to QDay in Singapore.