The principle
Zero trust is a security posture, not a product: assume any single component can be compromised, and design so that one compromise does not cause loss. For a network it means authenticating every request. For crypto keys it means no single key, device or person can move funds alone.
Two technologies implement that for private keys.
Multisig vs MPC
| Multisig | MPC (threshold signatures) | |
|---|---|---|
| What it is | An on-chain rule: M of N separate keys must sign (2-of-3, 3-of-5) | One key mathematically split into N shares; M shares jointly produce a single ordinary signature without ever reconstructing the key |
| Where the logic lives | In the blockchain (Bitcoin script, Ethereum smart contract such as Safe) | Off-chain, in the signing software |
| Visible on-chain? | Yes — anyone can see it is a multisig and the threshold | No — looks like a normal single-key address |
| Chain support | Per chain; needs native support or a contract | Any chain, since the output is a standard signature |
| Cost | Larger transactions (Bitcoin) or contract gas (Ethereum) | Normal transaction size |
| Key rotation | Requires an on-chain change of signers | Shares can be refreshed without changing the address |
| Typical users | Bitcoin treasuries, DAOs (Safe), individuals with 2-of-3 hardware setups | Custodians (Fireblocks, Coinbase), exchanges' hot wallets, consumer wallets (Zengo and similar) |
| Main risk | The interface that builds the transaction can lie about what is being signed | The software implementing the protocol; a bug or a compromised co-signer service |
Both achieve the zero-trust goal — no single key moves funds — by different routes. Multisig is transparent and auditable; MPC is flexible and private. Both can be undone by the same thing: a compromised interface.
What the Bybit theft taught
In February 2025 an exchange lost roughly $1.5 billion from a cold wallet secured by a Safe multisig. The keys were not stolen and the contract was not broken. Attackers compromised the web interface the signers used, so that what the signers saw on screen — a routine transfer — differed from what they actually signed — a change to the wallet's logic that handed control to the attacker. Every signer approved; every signature was valid.
The lesson generalises: a threshold of keys protects against key theft, not against all signers being shown the same lie. Zero trust must extend to the display. Concretely: verify the transaction on a hardware device screen that renders the real calldata, use more than one independent interface for high-value signing, and treat the front-end as untrusted even when the keys are safe.
Zero trust for an individual
You do not need institutional tooling to apply the principle. A practical setup:
- No single point of failure for savings. A 2-of-3 multisig for Bitcoin (two hardware devices from different vendors plus a backup key stored separately) means a lost device, a stolen device or a single compromised vendor does not lose funds. Sparrow Wallet and similar tools make this accessible. For chains without cheap multisig, a hardware wallet with a passphrase is the single-device approximation.
- Separate roles. Savings on hardware (or multisig); daily spending and DeFi in a hot wallet with limited balance. A drained hot wallet is bounded.
- Verify on an independent screen. Every address and amount confirmed on a hardware device, not only in the browser. This is the personal version of the Bybit lesson.
- Assume every service is compromised at some point. Hold minimal balances on exchanges; use account-free swaps for conversion so there is no standing balance and no login to steal. A service you never log into cannot leak your credentials.
- Assume every device is compromised at some point. Seed stored offline; never typed; passphrase separate.
- Assume every message is hostile. Support does not DM; links are not followed; software is installed only from vendors. The scam guide lists the scripts.
How exchanges and swap services apply it
Regulated custodians and large exchanges run MPC for hot wallets (fast signing, no on-chain footprint) and multisig or MPC with hardware modules for cold storage, with policy engines that enforce limits and approvals per transaction. That protects their keys. It does not protect a customer from the exchange's own failure modes — insolvency, freezes, account takeover through the customer's credentials.
An account-free swap has a different profile. It holds funds only for the minutes between a deposit confirming and a payout leaving; it has no customer balances to steal in bulk and no customer logins to take over. From the customer's side that removes two of the three largest exchange risks; the remaining one — the service's own operational security during the swap window — is bounded by the size of one swap. BTC → ETH, USDT (TRC-20) → BTC and every other pair run on the same model.
Frequently asked questions
Is MPC safer than multisig? Different. MPC is more flexible and private; multisig is auditable on-chain. For an individual, Bitcoin multisig with hardware devices is the most transparent option; MPC consumer wallets trade some of that for convenience and depend on the vendor's software.
Does a hardware wallet count as zero trust? It removes trust from the computer but not from the single device. Adding a second device (multisig) or a passphrase moves closer.
What about social recovery and "smart wallets"? Ethereum account-abstraction wallets can require guardians or multiple devices; they are multisig-like policies in a contract, with the same interface caveat.
Should I use MPC wallets that keep a share on their server? They are convenient and reasonably safe for everyday amounts; the vendor is a co-signer and a dependency. Not for the amount you cannot afford to lose.
How does this relate to no-KYC? Zero trust is about limiting what any one compromise yields. A KYC file is a compromise waiting to happen; a service that never builds one has nothing to lose there. The no-KYC explainer covers that side.
BTC → ETH
USDT (TRC-20) → BTC
ETH → USDT (TRC-20)