Crypto News Dispatch

Crypto news, five minutes a day

corporate wallet

Multi-Signature or Computation Based Custody: Where Adoption Landed

Two approaches to removing single key control. What each does, and which kinds of organisation chose which.

ELENA VOSS · · 2 min read

Both approaches solve the same problem: no single person or device should be able to move funds. They solve it differently and the adoption split follows organisational shape. The sector-level shift described here is observable in the published terms of a business crypto wallet with enforced approvals.

Multi-signature

Several independent keys, a threshold required to authorise. Enforced by the blockchain itself.

Advantages. Verifiable from outside: anyone can inspect the arrangement on-chain. No dependence on a vendor’s software for the security property. Well understood and long established.

Constraints. Not supported identically across networks. Transaction costs are higher, because more data is involved. Key management is entirely your responsibility, including rotation when holders change.

Who chose it. Organisations with technical capability, holding assets on networks with good support, and a preference for verifiable arrangements over convenience.

Computation based approaches

The key is never assembled. Shares held in separate environments jointly produce a signature.

Advantages. Works uniformly across networks, because the output is an ordinary signature. Lower transaction cost. Easier to change the participant set without moving funds. Richer policy control, because the rules live in software rather than in a threshold.

Constraints. The security property depends on the implementation, which you generally cannot inspect. Vendor dependence is real: the arrangement is only as good as the provider’s engineering.

Who chose it. Organisations wanting operational flexibility, holding across many networks, or preferring a vendor relationship to in-house key management.

What actually matters more than the choice

The operational controls around it: who can initiate, what approvals are required, whether a new destination has a delay, whether notifications reach several people, and whether the recovery procedure has been tested. Funds face an additional layer, and a platform built for institutional allocations is built around it.

An organisation with strong controls on either approach is in better shape than one with weak controls on the theoretically stronger approach.

The failure modes, which are shared

Untested recovery. Thresholds that stop working when someone leaves. Keys or shares concentrated in one location. Knowledge held by one person. Signers approving without verifying the destination independently.

None of these are addressed by the choice of technology.

The question for an organisation

Not which is more secure. Which will your organisation actually operate correctly every quarter for the next five years.

That is a staffing and process question, and the honest answer for most smaller organisations points toward a provider that carries the operational burden.

What to ask a provider

Which approach, and what is the threshold or policy configuration. Whether the arrangement can be verified independently. What happens if the provider ceases operating, and whether you can recover without them. The provision that only matters in a failure is the one worth checking first, and a crypto exchange with published fees states its position.

That last question is the important one and the answers vary considerably.

multisigcustodytechnology

Spotted an error? Corrections are published with a note at the foot of the article.Send the details.

More from the wire