Home   News   Features   Interviews   Magazine Archive   Industry Awards  
Subscribe
Securites Lending Times logo
Leading the Way

Global Asset Servicing News and Commentary
≔ Menu
Securites Lending Times logo
Leading the Way

Global Asset Servicing News and Commentary
News by section
Subscribe
⨂ Close
  1. Home
  2. Industry news
  3. The Vault launches in-house MPC cryptography for institutional custody
Industry news

The Vault launches in-house MPC cryptography for institutional custody


18 September 2026 Spain
Reporter: Zarah Choudhary

Generic business image for news article
Image: Who is Danny/stock.adobe.com
The Vault has launched an in-house multi-party computation (MPC) library for its institutional digital asset custody platform, following an independent security audit by blockchain security firm Halborn.

The Switzerland and EU-regulated custody provider says the library underpins its co-signing model, in which no single party, including The Vault, can authorise an asset transfer independently.

MPC enables separate parties to hold shares of a signing key, meaning a complete private key does not exist on any individual device or server.

The Vault says its decision to develop the cryptographic technology internally gives it control over the code, signing protocol, and release schedule, rather than relying on an external vendor for security updates and supported protocols.

The library implements distributed key generation, resharing, refresh, and recovery, alongside threshold Elliptic Curve Digital Signature Algorithm (ECDSA) and Edwards-curve Digital Signature Algorithm (EdDSA) signing.

It also includes commitment, oblivious transfer, and zero-knowledge proof primitives, as well as the transport layer used to carry protocol messages between signers.

Written in Rust, the implementation runs across The Vault's servers and its mobile signer applications on iOS and Android, allowing the same codebase to be subject to security review.

Halborn's audit covered 91 files across the cryptographic core, test suite, and mobile applications.

The Vault said all findings identified during the review were remediated, with Halborn verifying the fixes against the relevant code commits.

The final items were confirmed in August 2026.

Artem Stopnevich, CEO of The Vault, says: “For an institution, custody is a risk decision that has to be signed off internally, and it comes down to a single question: who is able to move an asset, and under what controls.”

Yurii Derbasov, chief technology officer at The Vault, adds: “The properties we need at the signing layer are the ones the compiler can enforce for us: no use-after-free, no data races across the concurrent rounds of a protocol, and explicit control over how key material is held in memory and erased once it is no longer needed. The language does not make a protocol correct, which is why the design itself needed an external review of this depth.

The co-signing model allows a client to hold a key share on its own device through The Vault's mobile signer.

The functionality is available as an add-on to the company's SaaS custody product.
NO FEE, NO RISK
100% ON RETURNS If you invest in only one asset servicing news source this year, make sure it is your free subscription to Asset Servicing Times
Advertisement
Subscribe today
Knowledge base

Explore our extensive directory to find all the essential contacts you need

Visit our directory →

Discover definitions, explanations and related news articles in our glossary

Visit our glossary →