Elliptic Curve Elliptic Curve
ECEC 05

Custody, MPC and multisig

Standfirst — one sentence stating the claim. To be written.

PUBLICATION GATE · SPEC §11, §12 This page does not go live with the rest of the site. It is blocked on the employment disclosure being raised at onboarding, and on a separate counsel review. Both are open. The prose slots below can be drafted; none of them can ship until those two clear.

What threshold signing protects against

PROSE · SPEC §3.5 Stated fairly and at full strength: against key theft, the claim is true. Establishing that first is what makes the next section credible rather than contrarian. Source: —— · Dated: ————-——-—— · Review due: ————-——-——

Why it is irrelevant against quantum

CLAIM · SPEC §3.5, §12 Threshold ECDSA and threshold Schnorr both operate over the same curve. A quantum adversary attacks the curve, not the key shares; splitting a key n ways does not make the discrete log harder. Frame this as a property of the mathematics, cite the underlying result, and name no provider. Source: —— · Dated: ————-——-—— · Review due: ————-——-——
EQUATION · component-specs §6 EQ 1: the aggregate public key is a point on the same curve regardless of how the private key is shared.

Multisig

CLAIM · SPEC §3.5 The same reasoning: a 3-of-5 with five exposed public keys is five quantum-vulnerable keys, not one made harder. Source: —— · Dated: ————-——-—— · Review due: ————-——-——

What actually helps

PROSE · SPEC §3.5 Hash-based address types where the public key is never revealed until spend, avoiding reuse, and eventually post-quantum signature schemes. Source: —— · Dated: ————-——-—— · Review due: ————-——-——

What does not help

PROSE · SPEC §3.5 Threshold schemes, HSMs, geographic distribution of shares — the controls that dominate custody marketing. As a class, as properties of the mathematics, with no vendor named. Source: —— · Dated: ————-——-—— · Review due: ————-——-——

Practical output

The forwardable version of this page is the custodian's checklist: what to ask a provider, what "quantum-ready" should mean in a contract, and what to migrate first.

This section discusses the security properties of custody architectures as a class, not the implementations of any named provider. Statements about threshold signature schemes follow from the underlying cryptography and are not assessments of any specific product, vendor, or deployment. Providers should be evaluated on their own documentation and audits.