Back to Blog
PrivacyUpdated September 16, 2026·5 min read

Zero trust and MPC keys, explained for people who hold crypto: multisig vs threshold signatures, what exchanges use, and how to apply the principle to your own setup

Zero trust means no single component — a device, a person, a server — is trusted with everything. In key management that produces two tools: multisig, where several keys sign on-chain, and MPC threshold signatures, where one key is split into shares that sign together off-chain. How each works, where each is used (custodians, exchanges, consumer wallets), what the 2025 Bybit theft taught about the weakest link, and a practical zero-trust setup for an individual.

The principle

Zero trust is a security posture, not a product: assume any single component can be compromised, and design so that one compromise does not cause loss. For a network it means authenticating every request. For crypto keys it means no single key, device or person can move funds alone.

Two technologies implement that for private keys.

Multisig vs MPC

MultisigMPC (threshold signatures)
What it isAn on-chain rule: M of N separate keys must sign (2-of-3, 3-of-5)One key mathematically split into N shares; M shares jointly produce a single ordinary signature without ever reconstructing the key
Where the logic livesIn the blockchain (Bitcoin script, Ethereum smart contract such as Safe)Off-chain, in the signing software
Visible on-chain?Yes — anyone can see it is a multisig and the thresholdNo — looks like a normal single-key address
Chain supportPer chain; needs native support or a contractAny chain, since the output is a standard signature
CostLarger transactions (Bitcoin) or contract gas (Ethereum)Normal transaction size
Key rotationRequires an on-chain change of signersShares can be refreshed without changing the address
Typical usersBitcoin treasuries, DAOs (Safe), individuals with 2-of-3 hardware setupsCustodians (Fireblocks, Coinbase), exchanges' hot wallets, consumer wallets (Zengo and similar)
Main riskThe interface that builds the transaction can lie about what is being signedThe software implementing the protocol; a bug or a compromised co-signer service

Both achieve the zero-trust goal — no single key moves funds — by different routes. Multisig is transparent and auditable; MPC is flexible and private. Both can be undone by the same thing: a compromised interface.

What the Bybit theft taught

In February 2025 an exchange lost roughly $1.5 billion from a cold wallet secured by a Safe multisig. The keys were not stolen and the contract was not broken. Attackers compromised the web interface the signers used, so that what the signers saw on screen — a routine transfer — differed from what they actually signed — a change to the wallet's logic that handed control to the attacker. Every signer approved; every signature was valid.

The lesson generalises: a threshold of keys protects against key theft, not against all signers being shown the same lie. Zero trust must extend to the display. Concretely: verify the transaction on a hardware device screen that renders the real calldata, use more than one independent interface for high-value signing, and treat the front-end as untrusted even when the keys are safe.

Zero trust for an individual

You do not need institutional tooling to apply the principle. A practical setup:

  1. No single point of failure for savings. A 2-of-3 multisig for Bitcoin (two hardware devices from different vendors plus a backup key stored separately) means a lost device, a stolen device or a single compromised vendor does not lose funds. Sparrow Wallet and similar tools make this accessible. For chains without cheap multisig, a hardware wallet with a passphrase is the single-device approximation.
  2. Separate roles. Savings on hardware (or multisig); daily spending and DeFi in a hot wallet with limited balance. A drained hot wallet is bounded.
  3. Verify on an independent screen. Every address and amount confirmed on a hardware device, not only in the browser. This is the personal version of the Bybit lesson.
  4. Assume every service is compromised at some point. Hold minimal balances on exchanges; use account-free swaps for conversion so there is no standing balance and no login to steal. A service you never log into cannot leak your credentials.
  5. Assume every device is compromised at some point. Seed stored offline; never typed; passphrase separate.
  6. Assume every message is hostile. Support does not DM; links are not followed; software is installed only from vendors. The scam guide lists the scripts.

How exchanges and swap services apply it

Regulated custodians and large exchanges run MPC for hot wallets (fast signing, no on-chain footprint) and multisig or MPC with hardware modules for cold storage, with policy engines that enforce limits and approvals per transaction. That protects their keys. It does not protect a customer from the exchange's own failure modes — insolvency, freezes, account takeover through the customer's credentials.

An account-free swap has a different profile. It holds funds only for the minutes between a deposit confirming and a payout leaving; it has no customer balances to steal in bulk and no customer logins to take over. From the customer's side that removes two of the three largest exchange risks; the remaining one — the service's own operational security during the swap window — is bounded by the size of one swap. BTC → ETH, USDT (TRC-20) → BTC and every other pair run on the same model.

Frequently asked questions

Is MPC safer than multisig? Different. MPC is more flexible and private; multisig is auditable on-chain. For an individual, Bitcoin multisig with hardware devices is the most transparent option; MPC consumer wallets trade some of that for convenience and depend on the vendor's software.

Does a hardware wallet count as zero trust? It removes trust from the computer but not from the single device. Adding a second device (multisig) or a passphrase moves closer.

What about social recovery and "smart wallets"? Ethereum account-abstraction wallets can require guardians or multiple devices; they are multisig-like policies in a contract, with the same interface caveat.

Should I use MPC wallets that keep a share on their server? They are convenient and reasonably safe for everyday amounts; the vendor is a co-signer and a dependency. Not for the amount you cannot afford to lose.

How does this relate to no-KYC? Zero trust is about limiting what any one compromise yields. A KYC file is a compromise waiting to happen; a service that never builds one has nothing to lose there. The no-KYC explainer covers that side.

Ready to swap privately?

No account required. Start in seconds.

Start swapping →