HYBRID DEVNET · PUBLIC EVIDENCE LIVEVerifiable infrastructure for value, markets, identity, and operational dataInspect the network
Wallets & recovery

How does an MPC wallet work?

3 min read

MPC stands for multi-party computation: participants jointly perform a calculation without revealing their private inputs to one another. In a threshold MPC wallet, signing material is held as separate secret shares, rather than giving one signer the complete private key. During a signing ceremony, a required number of eligible participants cooperate to produce a signature for the same transaction, without reconstructing the full key in one place. This threshold is often described as t-of-n: at least t of the n participants must contribute. Participants are signing systems, not necessarily people manually approving every transaction. Hybrid-Chain separates customer authorization from distributed signing participation; a signer’s availability is not permission to spend.

What the user needs to understand

You do not need to operate every signing participant yourself to understand the control model. Ask who authorizes the transaction, which participants must cooperate, and who can change that arrangement. A useful demonstration shows both an authorized signature and a request that cannot obtain the required authority. The strength comes from the actual separation and the supported protocol, not simply the number of boxes in a diagram.

Key benefits

  • Reduced single-key exposure: compromising one share does not, by itself, provide a valid signature when multiple shares are required. Signing does not require handing a complete private key to a single service.
  • Redundancy: when the threshold is smaller than the participant set, an authorized signing session can tolerate some unavailable participants, provided enough eligible signers and the other required services remain available.
  • Separation of control: independently operated participants can reduce dependence on one operator or infrastructure failure domain. Customer authorization and business approval rules remain separate requirements.
  • Chain-compatible signatures: supported threshold schemes can produce a signature the destination chain verifies normally, without requiring a separate on-chain signature for every participant. This does not automatically enable every chain or guarantee lower fees.

Illustrative example

In an illustrative 3-of-5 arrangement, three eligible participants must cooperate. One participant cannot sign alone; two unavailable participants need not stop signing if the remaining three and all authorization requirements are ready. This example explains the threshold principle, not the configuration of every Hybrid-Chain wallet.

Conditions & limitations

More signers do not automatically mean more security. Shared administrators, correlated outages, collusion reaching the threshold, implementation flaws, or bypassable recovery paths can undermine the benefits. Losing too many shares can prevent signing. MPC does not make an authorized malicious transaction safe, and it does not by itself establish self-custody. Enrollment, key generation, signing readiness, and chain-specific funding permission must each be verified.

What to do next

Confirm the exact threshold, participant operators, customer-authorization requirements, and recovery controls for your deployment. Test both a denied transaction and an authorized transaction with a participant unavailable in an agreed non-production evaluation.