Intermediate · 9 min read

Multisig vs MPC vs Single Key: Choosing a Custody Model

One key is a single point of failure. Multisig and MPC remove it in different ways, and the differences matter more than the marketing suggests.

Selin AydinSelin AydinSecurity Editor · Crypto security, custody, exploits and smart-contract risk
Multisig vs MPC vs Single Key: Choosing a Custody Model
The short answer

A single key is simplest and fails completely if it is lost or stolen. Multisig requires several independent keys to approve a transaction and leaves an on-chain record of who signed. MPC splits one key into shares so the full key never exists, which is invisible on-chain and depends on the vendor's implementation. For personal holdings above what you would hate to lose, a 2-of-3 multisig across different hardware vendors is the strongest practical setup.

Every custody decision answers one question: what happens when something goes wrong. A single key answers it badly — lose it and the funds are gone, leak it and they are stolen. Multisig and MPC both remove that single point of failure, and they do it in ways that suit different situations.

Single key

One private key, one seed phrase, one point of failure. On a hardware wallet the key resists extraction and the risk narrows to the backup: if the phrase is lost the funds are unrecoverable, and if it is found the funds are someone else's.

This is the right model for spending balances and for anyone who will actually maintain one backup properly. It stops being the right model at the point where losing the whole amount would be a serious event in your life.

Multisig

A multisig is a contract or a script requiring M of N keys to approve each transaction — commonly 2 of 3. Losing one key costs nothing but a rotation. An attacker who compromises one key gets nothing. Every approval is recorded on-chain, so in a shared treasury you can see who signed what.

The cost is friction and gas: contract accounts are more expensive to operate, transactions need coordination, and a few applications still handle contract wallets awkwardly. Safe is the standard implementation and has secured very large balances since 2018 without a contract failure.

The failure mode worth internalising is not cryptographic. In February 2025, attackers manipulated what Bybit's signers saw before approving, and multiple signers authorised a malicious transaction that drained roughly $1.5bn. A multisig where everyone signs the same manipulated screen is a single point of failure with extra steps. The mitigation is procedural: verify the destination and hash on each signer's own hardware screen, and use different devices and interfaces across signers.

MPC

Multi-party computation splits a single key into shares held by different parties, which jointly produce a signature without the complete key ever existing anywhere. On-chain it looks like an ordinary address — no contract, no visible signer set, standard gas costs, and compatibility with everything.

That invisibility is the advantage and the drawback. There is no on-chain record of the signing policy, so you cannot verify from the chain who can move funds; you are trusting the vendor's implementation and its share-management. MPC is the default for institutional custodians and for consumer wallets that offer account recovery without a seed phrase, and the quality varies enormously between implementations.

Smart accounts and social recovery

A fourth option now exists on several chains: a smart contract account with guardians who can restore access without being able to spend. Argent is the clearest consumer implementation — guardians approve recovery only, enforced by the contract, alongside daily transfer limits and address whitelists.

This addresses the failure that actually loses people crypto, which is not attackers but lost backups. The trade is higher gas, narrower chain coverage, and dependence on a specific account implementation.

Choosing

**Spending balance:** single key on a hardware wallet, paired with a wallet that shows you what you are signing. **Long-term personal holdings that matter:** 2-of-3 multisig with keys from different vendors in different physical locations — vendor diversity means one manufacturer's flaw cannot reach the quorum. **Shared or company funds:** multisig, always, with named signers and a written procedure for verification. **Institutional operations with frequent movement:** MPC through a custodian whose controls are examined, accepting that you are trusting an implementation you cannot inspect on-chain.

The part everyone postpones

Whatever model you choose, write down what happens if you are unavailable. A 2-of-3 whose recovery instructions exist only in your head is a single point of failure wearing a quorum's clothes. Document which keys exist, where they are, and what a trusted person would need to do — and test the recovery once, with a small amount, before you rely on it.

FAQ

Is multisig safer than MPC?
Multisig is verifiable on-chain: anyone can see the signer set and threshold. MPC hides the policy inside the vendor's implementation but works with every application and costs normal gas. For self-custody, multisig's verifiability is usually worth the friction.
What is a good multisig setup for personal holdings?
2-of-3 with keys on hardware wallets from different manufacturers, stored in different locations, coordinated through Safe or a Bitcoin coordinator like Sparrow. Vendor diversity means one firmware flaw cannot reach the quorum.
Did the Bybit hack break multisig?
No. The contracts worked correctly. Attackers manipulated what the signers were shown, so valid signatures approved a malicious transaction — which is why verifying details on each signer's own hardware screen matters.
Do I need multisig for a small balance?
No. For amounts you could absorb losing, a single hardware wallet key with a well-stored backup is proportionate. Multisig earns its friction when losing the balance would be a serious event.