Blocsafe
A multi-chain wallet secured by MPC/TSS threshold signatures. Keys are generated and used as distributed shares, so no single party ever holds the full private key.
Tech Stack
Overview
Blocsafe is a multi-chain wallet that Mithium built for a client, secured by multi-party computation (MPC) and threshold signature schemes (TSS). Instead of a single private key stored in one place, the key exists only as distributed shares. Signing happens as a joint computation between share holders, so the full key is never assembled, not at generation time and not at signing time.
Why MPC/TSS
Custodial wallets traditionally protect a single private key with encryption, HSMs, or multi-signature contracts. Each approach has a weak point: the key still exists in full somewhere, or the on-chain multisig costs gas and is chain-specific.
Threshold signatures move that protection into the cryptography itself:
- Distributed key generation: the key is created as shares from the start; no party ever sees the whole key.
- Threshold signing: a quorum of share holders cooperates to produce a standard signature, and any smaller set learns nothing.
- Chain-agnostic: the output is an ordinary ECDSA signature, so it works on EVM chains without special contracts or extra gas.
Architecture
┌────────────────────────────────────────────────┐
│ TypeScript wallet & API layer │
│ accounts · policies · transaction flow │
├────────────────────────────────────────────────┤
│ Go MPC/TSS signing core │
│ distributed keygen · threshold signing │
├──────────────┬──────────────┬──────────────────┤
│ Share node │ Share node │ Share node │
└──────────────┴──────────────┴──────────────────┘
│
EVM networks (multi-chain)Signing Core
The MPC/TSS protocol runs in Go, chosen for its performance and its mature cryptography libraries. It handles distributed key generation, share storage, and the threshold signing rounds.
Wallet Services
Account management, transaction construction, and the client-facing API are written in TypeScript. They assemble unsigned EVM transactions, request a threshold signature from the signing core, and broadcast the signed result.
Multi-Chain
Because threshold signing produces standard signatures, one key setup serves multiple EVM networks. Adding a chain means adding an RPC integration, not a new key ceremony.
My Role
I led the architecture and data model for Blocsafe as Founder & Lead Engineer at Mithium, and set the engineering standards the team delivered against.
Technologies Used
- Cryptography: MPC/TSS threshold signatures
- Signing Core: Go
- Services: TypeScript
- Chains: EVM networks