Back to Projects
MPC/TSS Wallet

Blocsafe

A multi-chain wallet secured by MPC/TSS threshold signatures. Keys are generated and used as distributed shares, so no single party ever holds the full private key.

2 min read•MPC/TSS
MPC/TSS threshold signaturesDistributed key shares, no full key anywhereMulti-chain, EVM-firstGo signing core, TypeScript services

Tech Stack

MPC/TSSGoTypeScriptEVM

Overview

Blocsafe is a multi-chain wallet that Mithium built for a client, secured by multi-party computation (MPC) and threshold signature schemes (TSS). Instead of a single private key stored in one place, the key exists only as distributed shares. Signing happens as a joint computation between share holders, so the full key is never assembled, not at generation time and not at signing time.

Why MPC/TSS

Custodial wallets traditionally protect a single private key with encryption, HSMs, or multi-signature contracts. Each approach has a weak point: the key still exists in full somewhere, or the on-chain multisig costs gas and is chain-specific.

Threshold signatures move that protection into the cryptography itself:

  • Distributed key generation: the key is created as shares from the start; no party ever sees the whole key.
  • Threshold signing: a quorum of share holders cooperates to produce a standard signature, and any smaller set learns nothing.
  • Chain-agnostic: the output is an ordinary ECDSA signature, so it works on EVM chains without special contracts or extra gas.

Architecture

plaintext
┌────────────────────────────────────────────────┐
│           TypeScript wallet & API layer        │
│      accounts · policies · transaction flow    │
├────────────────────────────────────────────────┤
│              Go MPC/TSS signing core           │
│   distributed keygen · threshold signing       │
├──────────────┬──────────────┬──────────────────┤
│  Share node  │  Share node  │   Share node     │
└──────────────┴──────────────┴──────────────────┘
                       │
             EVM networks (multi-chain)

Signing Core

The MPC/TSS protocol runs in Go, chosen for its performance and its mature cryptography libraries. It handles distributed key generation, share storage, and the threshold signing rounds.

Wallet Services

Account management, transaction construction, and the client-facing API are written in TypeScript. They assemble unsigned EVM transactions, request a threshold signature from the signing core, and broadcast the signed result.

Multi-Chain

Because threshold signing produces standard signatures, one key setup serves multiple EVM networks. Adding a chain means adding an RPC integration, not a new key ceremony.

My Role

I led the architecture and data model for Blocsafe as Founder & Lead Engineer at Mithium, and set the engineering standards the team delivered against.

Technologies Used

  • Cryptography: MPC/TSS threshold signatures
  • Signing Core: Go
  • Services: TypeScript
  • Chains: EVM networks