Summary of the October 2025 enhancements to key share management and security in MPC Wallets.
To enhance the usability and security of MPC Wallets, the configuration, interface, and security mechanisms for key shares were optimized in October 2025. The updates are described below.Across all modes, Cobo does not control or use client key shares. Any key share stored within Coboโs multi-cloud infrastructure is encrypted and stored on the clientโs behalf, and remains under the clientโs control.
The concept of key share holder groups has been simplified to keys, and all groups have been renamed as follows:
Original Name
New Name
Main Group
Main Key
Signing Group
Signing Key
Recovery Group
Recovery Key
The structure and meaning of the keys remain unchanged. For example, the process of creating a Main Key is the same as the previous process of creating a Main Group: the client generates one key share, and the other key share is generated within and stored encrypted in Coboโs multi-cloud infrastructure on the clientโs behalf. Together, the two key shares form a complete private key.
Previous interface:
Required viewing each holder group under different tabs.New interface:
All key shares are displayed together, with labels indicating Main Key holders. Recovery Keys can be managed through the upper-right entry.
Users can choose between Self Recovery and Third-Party Recovery. In both modes, the key share stored within Coboโs multi-cloud infrastructure participates in recovery. Recovery without this stored key share is no longer available.
For advanced MPC vaults, users can customize the signing threshold (m/n). This feature requires activation and is designed for clients who need custom signing structures.
For advanced vaults, keys are referred to as MPC Keys, categorized as Signing Keys and Standby Keys, with no longer separate designations for Main, Signing, or Recovery Keys.Key share holders (signers) are categorized as Regular Signers and Standby Signers. Transactions are sent to Regular Signers.
Critical operations related to keys (such as creating Signing Keys and Recovery Keys, or re-creating a Main Key) are now integrated with Governance Policies. These operations trigger security verifications to ensure that all critical steps are secure and controllable.
The system now prohibits the same node from acting as a key share holder for multiple keys within the same vault, to prevent cross-use risks and strengthen overall security.
This optimization does not affect existing keys. Keys created before the optimization will retain their original structure and functions, and remain fully usable. The interface will present the existing key information in the new format.
Was this page helpful?
Assistant
Responses are generated using AI and may contain mistakes.