Threshold signing · engineering partner
MPC crypto wallet development,
custody where no single actor signs alone.
TrustChange is an MPC crypto wallet development company for EU-facing crypto startups, licensed VASPs, PSPs, EMIs, neobanks and banks. We engineer bespoke multi-party-computation wallets under your brand — the threshold-signing protocol, the share topology, the policy engine, the ceremonies and the audit trail — as client-owned code, not a SaaS licence with a per-signing fee. Custody your regulator can read; keys no single operator can move.
- EU-based engineers
- MiCA-ready architecture
- AML & Travel Rule aware
- GDPR-aware storage
What "MPC" means here
MPC versus HSM versus seed — the honest comparison
Most searches for an MPC crypto wallet development company are made by regulated operators that need custody with no single-holder guarantee, share rotation without a chain move and evidence a supervisor can read. Below is how MPC differs from a single-HSM model or seed-based custody in the parts that shape the build. We build all three and are candid about which fits.
Prefer a self-custody or DeFi wallet? See Web3 wallet development services. Custodial venue wallet? See crypto wallet app development and the pillar on wallet and custody engineering. Company-level view: crypto wallet development company.
| Dimension | MPC | HSM | Seed |
|---|---|---|---|
| Key material | Shares split across separate trust zones | Single hardware-backed key inside an HSM | Seed / mnemonic held by the user or ops |
| Single-actor signing | Impossible under the threshold | Possible with HSM operator access | Anyone with the seed can sign |
| Rotation | Rotate shares without changing the address | Rotate keys via HSM procedures | New seed = new address; funds move |
| Recovery | Share recovery + policy replay | HSM backup + attestation | Seed backup, phishing-vulnerable |
| Fit | Regulated operators, custody at scale, no single-holder | Regulated custody with HSM investment already in place | Self-custody, DeFi, personal wallets |
Subsystems
Three subsystems inside every MPC crypto wallet development engagement
MPC is not one library. It is a protocol and share topology, a policy engine that decides whether signing is even allowed, and a ceremonies-and-evidence layer that a reviewer can follow. We build the three together, on one plan, with one team accountable end to end.
-
01
MPC protocol & shares
Threshold signing across shares held in separate trust zones — no single actor can sign alone. Share generation, storage, rotation and disaster recovery engineered from day one.
- Threshold signing (TSS)
- Share separation
- Rotation & recovery
-
02
Policy engine
The rules that decide whether a signing request is even allowed: per-asset velocity caps, allow-lists, quorum thresholds, spending limits and time-of-day windows.
- Velocity + allow-lists
- Quorum & thresholds
- Time & role controls
-
03
Ceremonies & evidence
Written key ceremonies, tamper-evident logs of every signing and policy decision, exports formatted for auditors and supervisors when they ask.
- Written ceremonies
- Tamper-evident log
- Reviewer-shaped exports
Stack
What sits behind an MPC crypto wallet
Eight layers, one system. Every layer names an owner, a control and a piece of audit evidence — nothing is left implied under the "MPC" label.
Related specialised builds: crypto key management system development, white label crypto wallet development, crypto wallet development company and, for the whole platform, crypto software development company.
| Layer | What we build |
|---|---|
| Product surface | Web, mobile and admin apps under your brand for the operator, ops and (optionally) end-user side of the MPC wallet One product surface, no shared multi-tenant backend behind it. |
| MPC signing protocol | Threshold signing across shares held in separate trust zones (cloud enclave, HSM-backed and mobile / secure-enclave devices) No single actor holds a signing key on their own. |
| Chain coverage | Bitcoin, EVM chains, Solana and other UTXO / account networks — plus emerging protocols as plug-ins on one core New chains add adapters, not a fork of the wallet. |
| Policy engine | Per-asset velocity caps, allow-lists, quorum thresholds, spending limits and time-of-day windows — versioned in your admin console Policy is configuration, not code — reviewable, editable, audited. |
| Compliance controls | KYC/KYB where the model requires it, sanctions and wallet-risk screening, Travel Rule on transfers Rules run inside the flow; every decision writes to the audit log. |
| Key ceremonies & recovery | Written key ceremonies, share rotation, disaster recovery drills and social-recovery options where relevant Recovery is rehearsed with your staff before launch, not assumed. |
| Ledger & reporting | Double-entry ledger with daily reconciliation and reviewer-shaped export bundles Finance, ops and the auditor read the same source of truth. |
| Runtime & delivery | EU-hosted, CI/CD pipelines, observability, 24/7 on-call cover Your identity provider, your key custody, your data regions. |
Signing path
How an MPC signature crosses the wallet
Every signing request in the MPC wallet goes through the same gates before shares cooperate. Speed comes from tuning the protocol path, not from skipping a step or trusting the caller.
- 01
Request
Real time
A signing request arrives from the app, API, treasury console or automated flow, stamped with source id and requester.
- 02
Policy
Sub-second
Velocity caps, allow-lists, quorum thresholds and role checks run before any share is touched.
- 03
Screening
Sub-second
Sanctions and wallet-risk vendors return a verdict where regulated flows apply; the reason is stored.
- 04
MPC sign
Sub-second
The threshold protocol runs across shares in separate trust zones; no single actor sees the full key.
- 05
Broadcast
Chain-bound
The signed transaction goes on chain; the wallet watches inclusion, revert or replacement.
- 06
Log & reconcile
Immediate
A tamper-evident audit entry is written; the ledger reconciles against chain state daily.
Delivery
How we deliver an MPC crypto wallet development project
Five steps, in this order. MPC wallet work runs inside the product backlog — no separate cryptography-consulting phase billed for months, no big-bang launch of an unrehearsed key ceremony.
- 01
Scoping
Weeks 1–2
We map custody model, share topology, policy expectations, chains, licence context and the risk you must stand behind. Output: a scope, a control map and a costed plan.
- 02
Architecture
Weeks 3–4
Protocol choice, share zones, policy engine, screening flow and ceremony design written down first. Regulatory constraints shape the design.
- 03
Build
Two-week sprints
MPC signing, policy engine, chain adapters, ceremonies and admin ship in slices. Each merge runs tests, static checks and a dependency scan.
- 04
Hardening
Before launch
Independent third-party security review of the MPC integration, load work, failure drills, recovery rehearsal and a pen-test window.
- 05
Launch and run
Cutover + ongoing
Named engineers on 24/7 cover. Runbooks, dashboards, ceremony playbooks and the audit log are handed to your team on day one.
Engagement
Four ways to buy your MPC wallet build
Same engineers, same standard. Only the commercial shape changes.
-
Fixed-scope build
A defined MPC wallet at a fixed price and date. Best when custody model and chains are settled.
-
Dedicated team
A standing squad with a lead. Best for long roadmaps and new chains or protocols each quarter.
-
Staff augmentation
Senior engineers inside your team. Best when you already own the plan and need MPC depth.
-
CTO advisory
Architecture and buy-vs-build review before you commit. Best at the design stage.
Questions
FAQ: MPC crypto wallet development
Six answers up front on scope, packaged trade-offs, MPC vs HSM vs seed, ceremonies & recovery, MiCA / AML / GDPR and support. Bring the rest to the call.
What does an MPC crypto wallet development company like TrustChange actually deliver?
We engineer a bespoke, client-owned MPC wallet end to end: the threshold-signing protocol, the share topology across separate trust zones, the policy engine, key ceremonies and recovery drills, the operator and treasury surfaces, the compliance controls and the tamper-evident audit log. It ships as source code in your repositories, with the IP assigned to you. There is no per-signing fee, no shared multi-tenant backend and no vendor gate between you and your custody evidence.
How is your MPC crypto wallet development different from a packaged provider?
Packaged MPC providers bundle a fixed protocol, a fixed share topology and a licence fee, and the policy engine lives inside the vendor's platform. TrustChange shapes the protocol choice, the share zones, the policy rules, the ceremonies and the recovery drills against your actual custody model, licence context and audit expectations. A bespoke build takes longer up front, but you keep every share generation, every policy version and every signing decision — and you avoid the roadmap lock-in that comes with a rented custody stack.
How does MPC compare to HSM and to seed-based custody?
MPC splits signing across shares held in separate trust zones, so no single actor can sign alone. HSM holds a single hardware-backed key that the venue operates under written procedures — proven, but the HSM operator is a single point of trust. Seed-based custody is fit for self-custody and DeFi, but a single seed compromise is total. The MPC vs HSM vs seed table on this page shows where each is the right choice; we build all three and are candid about which fits your model.
What does key-ceremony, rotation and recovery look like in practice?
Ceremonies are written procedures rehearsed with your staff before launch — share generation, quorum approval, share rotation, disaster recovery. Rotation happens without changing the deposit address, so operations do not pause. Recovery drills replay realistic scenarios (share loss, trust-zone compromise, quorum unavailability) against your policy, with an independent observer and a signed record. Nothing about a specific attestation or supervisor sign-off is claimed — those depend on your programme.
How are MiCA, AML/Travel Rule and GDPR engineered into the MPC wallet?
TrustChange is an engineering partner, not a law firm — your legal advisers and MLRO set the policy, we ship the controls and the evidence. That means KYC/KYB where a regulated flow needs it, sanctions and wallet-risk screening before signing, Travel Rule data on crypto transfers, MiCA-ready records where relevant, and GDPR-aware storage with data mapping and retention rules. Nothing about licences, opinions or supervisor approvals is claimed on your behalf.
Do you also run the MPC wallet after launch, or hand it over?
Both are on the table. Most clients start with named TrustChange engineers on 24/7 cover during the first months while their own team ramps up, then take the platform in-house with runbooks, dashboards, key-ceremony playbooks and the audit bundle. Some keep us on as a dedicated development team or on staff augmentation for new-chain, new-protocol and roadmap work, or as CTO advisory on architectural calls.
Book a discovery call with an MPC crypto wallet development company
Bring the custody model, the chains, the policy needs, the licence context and the launch date. We come back with a control map, an architecture view and a costed plan for an MPC wallet you own end to end. No demo theatre.