A key that no one holds, not even us
MPC wallets are generated jointly by the Chainvara vault and your own co-signer with 2-of-2 FROST threshold signatures. The full private key is never assembled: every signature needs both sides, and your side checks the exact transaction first.
Share 1
Chainvara vault
Share 2
Your co-signer
Valid signature
bc1p… · Schnorr (BIP-340)
Full private key: never assembled
What makes it safe
Threshold signatures (FROST)
Built on the Zcash Foundation's audited FROST implementation (RFC 9591), compiled to WebAssembly and run on both sides.
Solana and Bitcoin
Ed25519 for Solana; secp256k1 with BIP-340 Schnorr signatures for Bitcoin Taproot (bc1p…) addresses.
Your side verifies
Before adding its share, the co-signer rebuilds the transaction: destination, amount, change, fee and every signature hash must match what was approved.
Single-use rounds
Signing nonces are used exactly once and destroyed, even when a request is refused.
Same controls as any wallet
Policies, approvals, screening and the audit trail apply unchanged before the signing rounds start.
No single point of compromise
A breach of the vault alone, or of your server alone, cannot produce a signature.
How it works
- 1
Run the co-signer
Install the co-signer on a machine you control and connect it in Developers.
- 2
Generate the key together
Choose MPC 2-of-2 when creating a wallet: three rounds of key generation give each side a share.
- 3
Sign together
After approvals, the vault and your co-signer each add their share; the result is a standard signature.
Create an MPC wallet
await fos.wallets.create({
network: "bitcoin",
label: "Cold treasury",
key_mode: "mpc",
});
// → address bc1p… generated with your co-signerWorks best with
Ready to see Chainvara in action?
Start free on test networks. Move to production when your controls are in place.