Multichain Event Analysis: Risks and Countermeasures of MPC Wallet Management

Analyzing Multichain Events: Key Issues and Countermeasures in MPC Wallet Management

Recently, a cross-chain protocol company experienced operational anomalies, sparking widespread discussion in the industry about the management method of MPC( multi-party computation ) Wallet. The company's CEO and team went missing, resulting in the revocation of access keys to the MPC node servers. This incident reveals that merely adopting decentralized technology is not enough to ensure asset security; true decentralization must also be realized in management methods.

Similar situations are not uncommon. Although Bitcoin is decentralized, if a single miner monopolizes all the computing power, its advantage of decentralization will be lost. Ethereum, while decentralized, still sees Vitalik Buterin emphasizing the importance of distributed validation technology to prevent centralization trends.

In-depth analysis reveals that all node servers of the company are actually run by the CEO's personal cloud server account. This highly centralized management approach is essentially equivalent to using a single-signature Wallet to control all assets. Therefore, the root of the problem lies in the fact that the CEO should not control all MPC shards and has not provided a backup plan for extreme situations.

Correct Management of MPC Wallets from the Multichain Event

To fully leverage the advantages of MPC technology, it is essential to focus on the following three aspects:

  1. Increase transparency to prevent conflicts of interest
  2. Strictly adhere to the principles of decentralized custody to avoid excessive concentration of power.
  3. Develop contingency plans for extreme situations

First, preventing conflicts of interest requires rejecting the "black box". The company's MPC solution is essentially an opaque black box, as it serves both as the service builder and the user, which can lead to opacity and opportunities for wrongdoing. The solution is to introduce neutral third-party MPC service providers to enhance transparency and verifiability.

Correct Management of MPC Wallets from the Multichain Event

Secondly, decentralized custody must resolutely avoid single point risks. A multi-signature scheme can be adopted, ensuring security through high-strength encryption and trusted execution environments. At the same time, multi-level private key derivation should be implemented to balance global control and specific permission management. In addition, a multi-backup mechanism should be adopted, such as online geographically distributed active storage and offline cold storage, to minimize asset loss or service interruption risks.

Finally, in extreme cases, an "SOS mode" can be designed as an emergency response plan. When specific conditions are triggered, the SOS shard can replace the ordinary private key shard to facilitate emergency asset transfer or disposal. To prevent abuse, additional restrictions such as delayed effectiveness and lock-up periods can be implemented.

Correct Management of MPC Wallets from the Multichain Event

In summary, while MPC technology is advanced, its management approach is equally crucial. Only by achieving decentralization through the collaboration of technology application and management methods can the advantages of MPC truly be realized, ensuring asset security.

MULTI9.15%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 7
  • Share
Comment
0/400
AlphaBrainvip
· 3h ago
People are gone again, and the coin is gone too.
View OriginalReply0
AirdropHunterWangvip
· 3h ago
This CEO will inevitably do a Rug Pull.
View OriginalReply0
airdrop_huntressvip
· 3h ago
If you can't afford it, don't pretend to be decentralized.
View OriginalReply0
PoetryOnChainvip
· 3h ago
Another one has gone under~
View OriginalReply0
DYORMastervip
· 3h ago
Another fund scheme has Rug Pulled?
View OriginalReply0
WalletManagervip
· 4h ago
MPC cannot withstand human vulnerabilities; Private Key management is the key.
View OriginalReply0
BitcoinDaddyvip
· 4h ago
Mining is all that matters, why bother with so much?
View OriginalReply0
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate app
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)