|

The Vault Launches Its own MPC Library for Institutional Custody

Barcelona, 17 September 2026. The Vault, the institutional digital asset custody platform regulated in Switzerland and the EU, has launched its own multi-party computation (MPC) library, the cryptography that permits separate events to carry shares of a signing key so {that a} full non-public key by no means exists on any gadget or server. The launch follows an impartial safety audit by blockchain safety agency Halborn, which issued its remaining report earlier this week confirming that every one findings raised have been remediated and verified.

Artem Stopnevich, chief govt of The Vault, offered it on the European Blockchain Convention in Barcelona, describing it as the primary sovereign cryptographic library for institutional custody in Europe, following the completion of an impartial audit by Halborn. 

The library enforces The Vault’s co-signing mannequin, below which no single celebration, together with The Vault itself, can authorize a switch on its own. Most custody suppliers license this element from an exterior vendor, a call that ties them to the seller’s launch cycle for safety fixes, to the curves and protocols it helps, and to the extent of disclosure it permits throughout due diligence.

The Vault builds it in-house, which is what the corporate means by sovereign cryptography: the code, the signing protocol, and the discharge schedule sit with the platform, so fixes ship on The Vault’s own timetable, auditors see the entire codebase, and the protocol can transfer ahead as requirements evolve.

Artem Stopnevich, Chief Executive Officer of The Vault.

“For an establishment, custody is a threat resolution that needs to be signed off internally, and it comes all the way down to a single query: who is ready to transfer an asset, and below what controls,” mentioned Artem Stopnevich, Chief Executive Officer of The Vault, talking on the sidelines of the European Blockchain Convention in Barcelona, the place he joined a panel on the custody of tokenised funds. “We are the one EU-regulated custody supplier working institutional MPC cryptography of its own making, and we took the view that we might not put it in entrance of purchasers till any person exterior this firm had taken it aside on the protocol stage, which is what Halborn has now finished.”

The library implements distributed key technology, resharing, refresh and restoration, and threshold ECDSA and EdDSA signing, along with dedication, oblivious switch and zero-knowledge proof primitives, and the transport that carries protocol messages between signers. It is written in Rust, a methods language whose compiler enforces reminiscence security with no rubbish collector, and the identical implementation runs on The Vault’s servers and contained in the cellular signer on iOS and Android, so the audit covers a single codebase.

“The properties we’d like on the signing layer are those the compiler can implement for us: no use-after-free, no information races throughout the concurrent rounds of a protocol, and express management over how key materials is held in reminiscence and erased as soon as it’s not wanted,” mentioned Yurii Derbasov, Chief Technology Officer at The Vault. “The language doesn’t make a protocol right, which is why the design itself wanted an exterior overview of this depth.”

Halborn’s engagement coated 91 information throughout the cryptographic core, its check suite and the iOS and Android signer purposes. Findings raised throughout the overview have been addressed within the codebase because the engagement progressed, and Halborn verified every remediation in opposition to the commit that applied it, confirming the ultimate gadgets in August 2026.

“It was a pleasure to work along with The Vault on securing their MPC custody. Security was clearly a precedence for their staff, and all findings raised throughout the engagement have been remediated and verified. For institutional custody, proprietary cryptography offers suppliers direct management over safety fixes and protocol updates, and permits auditors to look at the entire implementation reasonably than stopping at a vendor boundary. That issues when purchasers are performing technical due diligence on who can transfer their belongings.” mentioned Gabi Urrutia, SVP Security & Field CISO at Halborn.

In the co-signing mannequin, the shopper holds a key share on their own gadget, and the cellular signer is the appliance via which that share is held and used. It is offered as an add-on to The Vault’s SaaS custody product.

Looking forward, The Vault intends to publish the Rust library as open supply, in order that the cryptography will be examined by anybody, and its cryptography staff is engaged on two new protocols.

The first is a threshold variant of ML-DSA, the post-quantum signature scheme that NIST standardized below FIPS 204 for a single signer; threshold signatures don’t have any NIST-standardised type at the moment, and candidate constructions, classical and post-quantum alike, are going via aggressive choice below the NIST First Call for Multi-Party Threshold Schemes, which opened in January 2026. The second is a brand new threshold post-quantum password-authenticated key alternate, or PAKE.

The full report is offered to institutional purchasers on request (media@thevault.inc). 

About The Vault

The Vault is a Swiss and EU-regulated institutional infrastructure platform for digital belongings, serving company treasuries, monetary establishments, household workplaces, and cost suppliers. It covers the total lifecycle, from safe custody and treasury operations to back-office administration and pockets infrastructure, and is constructed on proprietary threshold MPC cryptography developed by an in-house analysis staff. It is offered in SaaS and On-Premise, with a bespoke modular structure that may be custom-made to every firm’s wants and frameworks.

The submit The Vault Launches Its own MPC Library for Institutional Custody appeared first on BeInCrypto.

Similar Posts