Finrock Wallet Types: MPC, Legacy KMS, and HSM Cold Storage
Choose between MPC wallets, legacy KMS wallets, and HSM cold storage based on your security requirements and operational workflow.
Finrock supports three distinct wallet architectures — MPC wallets, Legacy KMS wallets, and HSM cold storage — each designed for different security postures and operational requirements. Understanding the trade-offs between them helps you select the right approach for your custody strategy, whether you prioritize automation, self-custody of key material, or the highest possible physical security.
MPC wallets are Finrock’s default and recommended wallet type for most operational use cases. They use threshold cryptography to split key material across independent signing nodes, so the full private key is never assembled at any point — not during creation, signing, or storage.How it works:
Key shares are distributed across Node A (your application server), Node B (Finrock Mobile App, user-controlled), and Node C (backup/DR node).
A signing threshold (e.g., 2-of-3) determines how many nodes must participate to produce a valid signature.
Nodes communicate over encrypted P2P channels. No key material is ever transmitted between them — only partial signatures.
Distributed Key Generation (DKG) ensures the full private key never exists, even during wallet creation.
Best for:
High-volume operational workflows
Automated transaction processing
Businesses requiring institutional-grade security without air-gapped hardware
MPC wallets support ECDSA (secp256k1) for Bitcoin, Ethereum, and EVM chains, and EdDSA (Ed25519) for Solana. See How MPC Wallets Work for a full architectural overview.
Legacy KMS wallets give you complete ownership and control of your private keys by hosting a Key Management Server (KMS) on your own infrastructure. Finrock’s backend servers never access your private keys, mnemonic phrases, or wallet seeds at any time — by design.How it works:
You deploy the finrock/ng-signer Docker image on your own VM (AWS or Azure recommended).
Your KMS polls Finrock at regular intervals to pick up pending signing jobs — Finrock never pushes tasks to your KMS.
The KMS signs transactions locally and encrypts them before dispatching to the blockchain.
All communication is one-way, end-to-end SHA-512 encrypted. All inbound (ingress) traffic to the KMS must be blocked; only outbound (egress) traffic is allowed.
Passphrase to encrypt the MPC keystore (MPC mode only)
FINROCK_MNEMONIC_PHRASE
String
12-word seed phrase
FINROCK_SECRET
String
Encrypted mnemonic phrase
FINROCK_API_HOST
String
Defaults to https://sapi.finrock.io
Key operational features:
Kill switch: Instantly take the KMS offline to halt all transaction signing.
Recovery option: Generate new private keys for specific addresses or address groups if needed.
Your KMS host must block all inbound network traffic. Only outbound (egress) connections to Finrock’s API are required. Exposing the KMS to inbound traffic defeats its security model.
HSM (Hardware Security Module) cold storage provides the highest level of physical key security available in Finrock. Private keys are stored inside tamper-resistant hardware devices that are never connected to the internet, making remote extraction or exploitation impossible.Hardware specification:
Physical tamper protection against unauthorized access or key exfiltration
Air-Gapped QR Code Signing Workflow:
1
Initiate the Transaction
Create a transaction from the Finrock platform. The platform converts it into a PSBT (Partially Signed Bitcoin Transaction) or equivalent unsigned payload.
2
Display the QR Code
The unsigned payload is rendered as a QR code on your Finrock workspace. No network transfer occurs at this stage.
3
Scan with Offline Device
Take your air-gapped device running the Finrock Mobile App — with Wi-Fi disabled, mobile data off, and in airplane mode — and scan the QR code. The app has no network access.
4
Sign Offline
The Finrock Mobile App signs the transaction entirely offline using private keys stored in the device’s secure enclave or connected HSM. The signed transaction is displayed as a return QR code.
5
Broadcast the Transaction
Scan the return QR code back into the Finrock platform. The platform broadcasts the signed transaction to the blockchain network.
Key benefits:
Zero Network Exposure
The signing device never requires a network connection. Remote exploits and malware are impossible by design.
FIPS 140-2 Level 3
Industry-standard certification for tamper-resistant hardware used in government and regulated financial environments.
Physical Protection
Keys are stored inside hardware designed to destroy itself if tampered with, preventing physical extraction.
Operational Usability
Designed for real-world treasury operations — not just security theory. The QR workflow makes air-gapped signing practical at scale.
Best for:
High-value treasury reserves and cold storage
Environments with strict physical security requirements
Institutions that cannot accept any online key exposure under any circumstances
Many institutions combine wallet types: MPC wallets for operational liquidity and hot wallets, with HSM cold storage for long-term treasury reserves. You can use both within the same Finrock workspace.
⌘I
Assistant
Responses are generated using AI and may contain mistakes.