Chainvara
MPC wallets

A key that no one holds, not even us

MPC wallets are generated jointly by the Chainvara vault and your own co-signer with 2-of-2 FROST threshold signatures. The full private key is never assembled: every signature needs both sides, and your side checks the exact transaction first.

Share 1

Chainvara vault

Share 2

Your co-signer

Valid signature

bc1p… · Schnorr (BIP-340)

Full private key: never assembled

What makes it safe

Core

Threshold signatures (FROST)

Built on the Zcash Foundation's audited FROST implementation (RFC 9591), compiled to WebAssembly and run on both sides.

Solana and Bitcoin

Ed25519 for Solana; secp256k1 with BIP-340 Schnorr signatures for Bitcoin Taproot (bc1p…) addresses.

Your side verifies

Before adding its share, the co-signer rebuilds the transaction: destination, amount, change, fee and every signature hash must match what was approved.

Single-use rounds

Signing nonces are used exactly once and destroyed, even when a request is refused.

Same controls as any wallet

Policies, approvals, screening and the audit trail apply unchanged before the signing rounds start.

No single point of compromise

A breach of the vault alone, or of your server alone, cannot produce a signature.

How it works

  1. 1

    Run the co-signer

    Install the co-signer on a machine you control and connect it in Developers.

  2. 2

    Generate the key together

    Choose MPC 2-of-2 when creating a wallet: three rounds of key generation give each side a share.

  3. 3

    Sign together

    After approvals, the vault and your co-signer each add their share; the result is a standard signature.

Create an MPC wallet

await fos.wallets.create({
  network: "bitcoin",
  label: "Cold treasury",
  key_mode: "mpc",
});
// → address bc1p… generated with your co-signer

Works best with

Ready to see Chainvara in action?

Start free on test networks. Move to production when your controls are in place.