A New Approach to MPC Wallet Management: Reflections and Improvements After the Multichain Incident

robot
Abstract generation in progress

The Correct Management Method of MPC Wallets: Learning from the Multichain Incident

Recently, the Multichain project has encountered significant setbacks, with its CEO going missing, leading to the revocation of access keys for the MPC node servers. This incident has exposed many issues in the management of MPC Wallets and provided us with valuable lessons.

Reflection on Multichain Events

Although Multichain uses MPC technology to manage the treasury, its management method is essentially equivalent to a single entity controlling all assets. All node servers operate under the CEO's personal cloud service account, and this highly centralized management approach contradicts the decentralized intention of MPC technology.

This event reveals a key issue: simply adopting decentralized technology is not sufficient to ensure true decentralization. To fully leverage the advantages of MPC technology, a unified decentralization of both technical applications and management models is required.

The Correct Management Method of MPC Wallets from the Multichain Incident

Key Points for Effectively Utilizing MPC Technology Characteristics

  1. Enhance transparency and prevent conflicts of interest

The MPC solution of Multichain is essentially a "black box", lacking transparency and verifiability. To address this issue, it is crucial to introduce credible third-party MPC service providers. This can eliminate the "black box" effect and provide necessary information verification for stakeholders.

  1. Strictly adhere to the principles of decentralized custody

Ensuring the decentralization of servers, access permissions, and geographical locations is key. One viable solution is to adopt a multi-signature mechanism, such as a 3-3 multi-signature, supplemented by high-strength encryption and a trusted execution environment. At the same time, implement a multi-level private key derivation design to meet the business needs at different levels. In addition, adopting measures such as online remote multi-active distributed storage and multi-level offline cold storage backups can minimize single-point risks.

The Correct Management Method of MPC Wallet from the Multichain Incident

  1. Develop contingency plans for extreme situations

Considering the irresistible factors of the physical world, it is essential to design the "SOS mode" as a last line of defense. This mode can be activated under specific conditions to achieve emergency asset transfer or disposal. To prevent abuse, restrictions such as a delay in effectiveness and an asset lock-up period can be set.

The Correct Management of MPC Wallets from the Multichain Event

Conclusion

The Multichain incident has sounded the alarm for the entire industry. It reminds us that merely adopting advanced technologies is not enough; what is more important is how to properly manage and apply these technologies. By enhancing transparency, strictly enforcing decentralization principles, and being prepared for extreme situations, we can better leverage the advantages of MPC technology to provide users with safer and more reliable asset management services.

MULTI-1.52%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 5
  • Share
Comment
0/400
GateUser-a5fa8bd0vip
· 16h ago
Who would dare to use mpc in the future?
View OriginalReply0
TokenVelocityTraumavip
· 16h ago
Spot long order trapped for three years.
View OriginalReply0
TokenTaxonomistvip
· 16h ago
*sigh* yet another predictable evolutionary failure in the cryptosphere...statistically inevitable tbh
Reply0
BearEatsAllvip
· 16h ago
So much nonsense? Wouldn't it have been better to have a plan in place earlier?
View OriginalReply0
TokenTherapistvip
· 16h ago
MPC is a good thing, but it's difficult to maintain.
View OriginalReply0
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate app
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)