MPC wallet: a key that never exists in one place
An MPC wallet replaces a single private key with several mathematical shares held on different devices or by different parties, and those shares produce a signature together without the complete key ever being assembled. There is no moment, and no machine, where the whole key exists, so there is nothing for an attacker to steal in one place.
That property is why institutional custody moved toward this technology. For a custodian holding client assets, the question an auditor and a supervisor ask is where the key is and who could use it alone, and the honest answer with MPC is that nobody can.
Threshold signing: what the shares do
The shares are not pieces of a key that get glued back together. Each one is an independent secret, and the signing protocol has the holders exchange messages so that the mathematics of a valid signature is completed jointly, while each party learns nothing about the others' secrets. This is a threshold signature scheme, often written TSS.
The scheme is configured as a threshold of a total, such as two of three or three of five. Below the threshold, no combination of shares can sign or can reconstruct the key, which means a stolen laptop with one share is worthless. Ledger's glossary entry describes the same split into shares held by separate parties. What appears on the blockchain is an ordinary single signature, indistinguishable from a normal wallet's.
MPC against multisig
Multisig achieves a related goal on the chain instead of off it. A multisig address requires several complete, separate private keys, each producing its own signature, and the smart contract or the protocol checks that enough of them are present. Each key exists in full somewhere.
Four differences decide which one a firm uses. Multisig needs protocol support, and implementations differ by chain, while MPC works with any chain that accepts a standard signature, which matters for a custodian supporting many assets. Multisig writes its structure on chain, so the policy is public and each signature costs fees; MPC shows one signature and keeps the policy private. Multisig's quorum is fixed in the address, so changing signers means moving the funds, while MPC can change its share configuration without a transaction. And multisig's security is publicly auditable in the contract, which some holders prefer precisely because nothing is hidden. Kaleido sets out the same comparison across chain support, fees and failure modes.
HSMs, and when a custodian uses both
A hardware security module is a certified tamper-resistant device that generates and stores key material and performs signing inside its own boundary, with the key never leaving it in readable form. It solves a different problem from MPC: an HSM protects one key very well, and MPC removes the single key.
Serious custody setups combine them, holding each MPC share inside its own HSM in a separate location. An attacker then has to defeat the hardware protection and reach enough locations to meet the threshold. The HSM also brings something MPC does not: certification against a recognized standard such as FIPS 140, which is evidence a supervisor can read. Crypto custody covers the wider arrangement, and Tangany is one of the German licensed custodians in this field.
Key ceremony, share rotation and recovery
Three operational processes carry the real risk, and the technology does not perform any of them for you.
The ceremony generates the shares under controlled conditions, scripted, with named participants, dual control and a witnessed record, after which the shares are distributed so that no person or site holds enough to sign.
Rotation, also called key refresh, is the property that makes MPC genuinely strong over time. The parties can recompute new shares of the same key, so the old shares become useless while the wallet address stays unchanged. An attacker who stole one share last quarter holds nothing after a refresh, and a departing employee's share can be retired without moving a single coin.
Recovery answers the case where shares are lost. A threshold scheme survives the loss of shares up to its tolerance, and beyond that the assets are unrecoverable, so the backup arrangement, usually encrypted share backups split across locations, has to exist and be tested. An untested recovery plan is the most common serious defect in these setups.
What a supervisor asks a licensed custodian to evidence
In Germany crypto custody is a regulated activity, and the custodian has to show its arrangements, not describe them. The documents a review asks for are the ceremony records, the threshold configuration and where each share lives, the authorization rules for a transfer with evidence that dual control is enforced technically and not by convention, the segregation of client assets, the rotation schedule with evidence it has run, and the tested recovery procedure.
A third-party assurance report over the control environment is what makes these claims usable by someone else's auditor, which is the point covered under crypto audit. Crypto custody in Germany sets out the licensing itself.
What failure modes remain?
Four, and none of them is the cryptography. The first is the policy engine: the software deciding which transfers are allowed before signing starts is a normal piece of software, and an attacker who controls it can have the shares sign a legitimate-looking transfer to the wrong address.
The second is insider collusion at the threshold. A scheme of two of three is defeated by two cooperating holders, which is why share holders are separated across teams, locations and sometimes organizations. The third is the implementation: MPC protocols are hard to implement correctly, and the published attacks against this technology have been against implementation bugs, not the underlying mathematics. The fourth is the operational one above, losing shares beyond the recovery tolerance. Digital asset risk management places these in a limit framework.
Is an MPC wallet right for an individual holder?
Usually not, and the reason is that its advantages are organizational. MPC earns its complexity where several people must be prevented from acting alone, where shares can be separated across locations and where a rotation schedule can be operated. A single holder has none of those conditions and ends up depending on one provider's software for the thing a hardware wallet does with less machinery, described under hardware wallets.
Consumer wallets marketed as MPC usually mean something narrower: the provider holds one share and the user's device holds another, which removes the seed phrase and introduces a dependency on the provider. That is a reasonable trade for some people and it is a different proposition from institutional MPC, as crypto wallets explains.
MPC wallets and Finance Loop
Finance Loop is the meeting place for the custody engineers, security officers and supervisors in Germany who have to decide whether a key arrangement is good enough for client assets. Finance Loop members build these systems at licensed custodians and review them from the risk and audit side.
Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, tokenization, stablecoins, and DeFi. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, Digital Infrastructure & Sovereignty, and Risk & Compliance.