HYBRID DEVNET · PUBLIC EVIDENCE LIVEVerifiable infrastructure for value, markets, identity, and operational dataInspect the network
Wallets & recovery

How does MPC differ from giving a custodian control of our assets?

3 min read

MPC describes how signing participants cooperate; custody describes who has effective authority over assets. Distributed signing can support a customer-controlled arrangement, but the technology name alone does not tell you who controls approvals, recovery, or enough participants to sign.

One term is about technology; the other is about control

MPC, or multi-party computation, lets participants cooperate in a cryptographic task. A threshold wallet requires an agreed number of participants to contribute to signing. Custody asks a different question: who can effectively decide to move the assets? A service can use sophisticated distributed signing while still having practical control over all the relevant authority. Conversely, distributed signing can be part of a design in which the customer retains essential authorization.

Counting participants is not enough

Five servers do not necessarily mean five independent decision makers. They may share one administrator, organization, or recovery route. Ask who operates the participants, who can change the threshold, and whether customer approval can be bypassed. Include exceptional procedures in that review. A well-presented architecture diagram should make those responsibilities easier to understand, rather than using the number of components as a substitute for explaining who can act.

Compare the experience during a problem

Consider an unavailable provider, a compromised administrator, and an employee leaving the business. Ask what each arrangement allows in those situations, what stops an unauthorized transfer, and what a legitimate customer must do to continue. The aim is not to assume that one technology label settles every risk. It is to choose a supported arrangement whose authority and recovery rules match your needs, and to confirm those rules through documentation and agreed tests before relying on it.

Illustrative example

Compare two deployments with the same threshold but different organizations controlling the participants.

Conditions & limitations

Do not assume that multiple servers mean independent control or that every MPC service is self-custodial.

What to do next

Compare operators and administrative boundaries, not only the number of shares.