MPC vs Multisig Wallet: Threshold Signatures vs Gnosis Safe
By Vultisig • • Updated October 9, 2026
Contents
- What Is a Multisig Wallet?
- 7 Problems With Multisig Wallets
- 1. Smart Contract Risk
- 2. Chain Limitations
- 3. High Gas Costs
- 4. On-Chain Visibility
- 5. Coordination Overhead
- 6. Key Management Complexity
- 7. Every Change Is a Public Transaction
- What Is an MPC Wallet?
- How Vultisig Works
- Teams, DAOs, and Families
- Team Treasuries
- DAO Operations
- Family Security
- Resharing: The Flexibility Advantage
- Direct Comparison
- When to Use Each
- Getting Started
- FAQ
- Is MPC safer than multisig?
- Does Vultisig support Bitcoin?
- What if I lose a device?
- Is Vultisig open source?
- How is this different from Gnosis Safe?
- Can teams and DAOs use Vultisig?
- Conclusion
Think of a bank vault that needs two of three managers to turn their keys. A multisig wallet builds that rule into a smart contract (like Safe) or a chain's script, and every manager holds a full key. An MPC wallet gets the same "several parties must agree" property differently: the key is generated in pieces with threshold signatures, so the full key never exists anywhere, and the chain sees an ordinary signature.
Both models have failed in public. Parity froze funds through a contract bug. Ronin and Harmony lost theirs when attackers collected enough signer keys.
This is the complete breakdown: how each model works, where multisig breaks, and which approach fits your situation.
What Is a Multisig Wallet?
A multisig wallet requires multiple private keys to move funds. Instead of one person holding all power, you split control across parties.
Common configurations:
- 2-of-3: two of three keyholders approve
- 3-of-5: three of five approve
- 5-of-7: large treasuries and DAOs
Implementation typically happens through smart contracts. Deploy a Gnosis Safe, set your signers, set your threshold. The contract enforces the rules on-chain.
Not all multisigs are smart contracts. Bitcoin has native multisig built into the protocol. But native multisig is chain-specific and static: it works only on that chain, and changing signers means moving to a new address.
So you get two flavors of multisig limitations: smart contract risk on EVM chains, or chain lock-in and inflexibility on native implementations.
Thousands of teams use these approaches. Billions secured.
But both create problems that threshold signatures avoid entirely.
7 Problems With Multisig Wallets
1. Smart Contract Risk
On EVM chains, a multisig is a smart contract, and smart contracts have bugs. The keys behind it are a second target.
Parity (2017): a vulnerability in the Parity multisig library let a user destroy the library contract. 513,774 ETH frozen forever. Not stolen, frozen. Still sitting there, inaccessible to anyone.
Ronin (2022): a 5-of-9 validator multisig protected the bridge. Attackers compromised 5 keys and drained $625 million. The contract worked exactly as designed; too many keys sat with too few parties.
Harmony (2022): a 2-of-5 multisig. Two keys compromised. $100 million gone.
Two failure modes keep repeating: contract bugs (Parity) and signer keys concentrated where one attack can collect enough of them (Ronin, Harmony). MPC removes the first entirely. For the second, Vultisig keeps every share on a separate device you control and publishes no signer list on-chain for attackers to work through.
2. Chain Limitations
Gnosis Safe works on Ethereum and EVM chains. That's it.
Bitcoin? Can't use Gnosis Safe. Solana? No. Cosmos? No.
If you hold assets across chains, and most serious users do, you need separate security solutions for each. Multiple wallets. Multiple setups. Multiple attack surfaces.
3. High Gas Costs
Every multisig transaction requires:
- Multiple signature submissions on-chain
- Smart contract execution
- State updates
Simple ETH transfer from a 2-of-3 multisig costs 3-5x a standard transfer. Gas spikes make it worse.
Teams with active treasuries feel this daily. Costs compound.
4. On-Chain Visibility
Multisig wallets are public. Anyone can see:
- Signing addresses
- Threshold requirements
- Transaction history
- Approval patterns
This creates attack surface. Knowing a wallet uses 2-of-3 with specific signers gives attackers a target list. Social engineering gets easier when you know exactly who to compromise.
5. Coordination Overhead
Getting three people to sign sounds simple.
Reality:
- Signer A traveling
- Signer B needs to review details
- Signer C's hardware wallet firmware outdated
- Gas price changed while waiting
Emergency transactions suffer most. The ones that matter get blocked by coordination friction.
6. Key Management Complexity
Each signer needs secure storage, backup procedures, recovery plans. Multiply across all signers.
One person loses their key? Recovery procedures. One hardware wallet fails? Delays.
Operational burden scales with security. More signers, more complexity.
7. Every Change Is a Public Transaction
On Safe, adding a signer or changing the threshold is an on-chain transaction that the existing signers approve and pay gas for, and the new signer list is public the moment it lands. On Bitcoin's native multisig it's worse: new signers mean a new script, a new address, and moving every coin.
Each change costs gas, needs a quorum, and tells the world exactly who now holds a key.
What Is an MPC Wallet?
MPC (Multi-Party Computation) achieves multi-party security without smart contracts.
Instead of multiple complete keys, MPC distributes key shares. No single device ever holds the full private key. Signing requires collaboration between shareholders. The signature itself looks identical to standard single-key signatures.
Technical term: Threshold Signature Scheme (TSS).
Result: multi-party security that works natively on any blockchain.
How Vultisig Works
Vultisig implements TSS with DKLS23, a modern threshold signature protocol, using Silence Laboratories' audited implementation.
Vault creation
- Your devices pair, over the same Wi-Fi or Vultisig's encrypted relay (in a Secure Vault, no server holds a share)
- Key generation distributes shares across devices
- Each device stores only its share
- Complete key never exists anywhere
Signing
- Transaction initiated on one device
- Required threshold of devices collaborate
- Combined computation produces valid signature
- Signature broadcasts to blockchain
The blockchain sees a normal transaction. No special contract. No on-chain footprint revealing your setup.
Configurations
- Fast Vault: one device plus VultiServer (2-of-2). Setup in about a minute. VultiServer co-signs and can never sign alone.
- Secure Vault 2-of-2: two devices, both required
- Secure Vault 2-of-3: two of three required. Recommended.
- Secure Vault 3-of-4: higher security with a spare
Larger setups are supported. Most users stick to 2-of-3 or 3-of-4, and teams and organizations can add more signers.
Teams, DAOs, and Families
Threshold signatures scale beyond personal security. Same architecture works for multi-party use cases.
Team Treasuries
Startup with three co-founders:
- Each founder holds a share on their device
- 2-of-3 threshold for transactions
- No smart contract deployment
- Works across all 30+ supported chains
A founder leaves on good terms? Reshare onto the remaining devices and keep the same vault address. If trust is broken, create a new vault and move the funds: a reshare doesn't revoke old shares.
DAO Operations
DAOs typically use Gnosis Safe. Vultisig offers an alternative:
- Committee members hold shares
- Threshold matches governance requirements
- Cross-chain without multiple wallets
- No public signer list for attackers
Family Security
Estate planning. Shared finances.
- Parents and adult children hold shares
- 2-of-3, so no one person can move funds alone
- A separate 3-of-3 vault for long-term savings everyone must approve
- Resharing adds a new family member's device
Multisig forces structure choices upfront. TSS adapts.
Resharing: The Flexibility Advantage
Traditional multisig is static. Change signers, change address.
Vultisig resharing lets you:
- Add participants: a new team member or family member
- Drop a device: reshare onto the devices that remain
- Grow the setup: go from 2-of-3 to 3-of-4 by adding a device
- Rotate shares: a periodic refresh
The vault address stays the same, so integrations keep working. No migration, and nothing appears on-chain.
One rule matters here: a reshare does not revoke old shares. Old and new shares can't be mixed, but an old set still works as a set. So:
- Device lost? Your other devices still meet the threshold. Reshare to add a replacement.
- Team grows? Add shares.
- Device stolen, or a participant you no longer trust? Create a new vault and move the funds.
Direct Comparison
Traditional multisig vs MPC (Vultisig), point by point:
- Implementation. Traditional Multisig: Smart contract. MPC (Vultisig): Native cryptography.
- Contract risk. Traditional Multisig: Yes. MPC (Vultisig): No.
- Chain support. Traditional Multisig: EVM only. MPC (Vultisig): 30+ chains.
- Gas costs. Traditional Multisig: 3-5x standard. MPC (Vultisig): Standard.
- On-chain visibility. Traditional Multisig: Public signers. MPC (Vultisig): No footprint.
- Signer changes. Traditional Multisig: an on-chain transaction that publishes the new signer list (a new address on Bitcoin). MPC (Vultisig): resharing, same address, nothing on-chain.
- Threshold changes. Traditional Multisig: an on-chain transaction. MPC (Vultisig): resharing.
- DeFi compatibility. Traditional Multisig: Contract limitations. MPC (Vultisig): Full.
When to Use Each
Multisig makes sense when
- EVM chains only
- On-chain governance records required
- Existing Gnosis tooling integration needed
- Gas costs irrelevant
MPC/Vultisig makes sense when
- Assets across multiple chains
- Privacy matters
- Flexibility to change participants needed
- Gas efficiency matters
- Smart contract risk unacceptable
- Individual wanting team-level security without complexity
Getting Started
Individuals
- Download on two+ devices (iOS, Android, Desktop)
- Create Secure Vault (2-of-3 recommended)
- Pair the devices (same Wi-Fi or the encrypted relay)
- Backup shares to separate secure locations
Teams
- Each member downloads Vultisig
- Coordinate vault creation (all devices present)
- Document resharing procedures
Learn more
FAQ
Is MPC safer than multisig?
MPC removes smart contract risk, the attack vector in Parity, because there is no contract. Ronin and Harmony were lost through compromised signer keys, which is why Vultisig keeps each share on a separate device and publishes no signer list on-chain.
Does Vultisig support Bitcoin?
Yes. 30+ chains including Bitcoin, Ethereum, Solana, Cosmos ecosystem. One vault covers everything.
What if I lose a device?
With 2-of-3, losing one device doesn't lock funds. Use remaining two devices, then reshare to add replacement.
Is Vultisig open source?
Fully. Code at github.com/vultisig. Audits published.
How is this different from Gnosis Safe?
Gnosis Safe (now Safe) is a smart contract multisig limited to EVM chains. Vultisig uses native threshold signatures: no contract, any chain, standard gas, private signers.
Can teams and DAOs use Vultisig?
Yes. Secure Vaults support multi-party setups. Threshold matches governance needs. Resharing adds members without an address migration. When someone leaves on bad terms, move to a new vault.
Conclusion
Multisig solved real problems. Single points of failure eliminated. Distributed control achieved.
Smart contract implementation created new problems. Bugs. Chain limits. Gas bloat. Public exposure. Every change on-chain.
MPC keeps multi-party security and removes smart contract risk entirely. Native signatures work everywhere, cost nothing extra, reveal nothing on-chain, and adapt through resharing.
For anyone wanting multisig-level security without the baggage, threshold signatures are the answer.
Open source and audited. Get started.
Related Articles
MPC Wallets for AI Agents, Compared (2026)
Coinbase, Cobo, MetaMask and Vultisig all ship agent wallets. The difference that matters is where the signing key lives. A five-point comparison.
Best MPC Wallets 2026: Vultisig vs Zengo, Fireblocks & More
The best MPC wallets of 2026 compared: who holds the key shares, whether a company co-signs, open source, recovery, chains and price.
Wallet Swap Fees 2026: MetaMask vs Phantom vs Trust Wallet vs Rabby
MetaMask 0.875%, Phantom 0.85%, Coinbase Wallet up to 1%, Rabby 0.25%, Uniswap 0%. Every major wallet's swap fee, sourced, checked October 2026.