Designing 2-of-2 MPC Key Generation for Self-Custody
By Security Engineering · June 28, 2026 · 6 min read
The security dilemma
In Web3, users historically faced a harsh choice: trust a centralized exchange with their keys (custodial) or write down a 12-word seed phrase on paper (self-custodial). The former exposes users to exchange insolvency; the latter places the entire burden of key security on the user, leading to millions lost to misplaced papers and phishing attacks. Furlpay solves this by implementing 2-of-2 Multi-Party Computation (MPC).
Under the hood: key splitting
With MPC, a single private key is never generated in one place. Instead, during account setup, our backend runs a cryptographic protocol (distributed key generation) to produce two distinct key shares:
- Share A (client-side): stored on the user's device, encrypted and accessible only via WebAuthn / passkey biometrics.
- Share B (server-side): managed inside Furlpay's Hardware Security Module (HSM) cluster, gated by policy rules.
[ Client Device ] ─────> Share A (biometric-gated)
│
(co-signing engine)
│
[ Furlpay HSM ] ─────> Share B (policy rules)To sign a transaction, the client app and the Furlpay HSM compute a signature cooperatively. Neither party ever reveals its share, and the complete private key is never assembled in memory. If our server is breached, the attacker cannot steal your funds because they lack Share A. If you lose your device, Furlpay assists recovery through a secure social/email verification protocol to regenerate your key shares.
Compromising one share yields nothing usable — an attacker must defeat both the device and the HSM policy at the same time.
Furlpay
Written by the Furlpay team — engineers and compliance specialists building an on-chain financial operating system for stablecoin payments, travel, and investing on Arbitrum.
Don't miss the next one
Stay ahead of the curve
Get product updates, engineering deep-dives, and security bulletins. No spam — just the signal.
More in Engineering
Solana Is Being Rebuilt Around Latency, Not Throughput
In August 2026 Solana cut its slot time below 400ms for the first time since genesis, and block capacity had already risen 66% to 100M compute units. But finality still takes 12.8 seconds — the upgrade that changes that is scheduled, not shipped. What is actually live, what is not, and why the roadmap is a latency story rather than a TPS one.
September 7, 2026 · 15 min read
JPMorgan 13F Q2 2026: What the SEC Filing Actually Shows
JPMorgan reported $1,807,041,234,839 across 34,064 information-table rows for the quarter ended 30 June 2026. We parsed the original SEC XML twice and reconciled it to the dollar. Here is what the filing shows on the iShares Ethereum and Bitcoin trusts, Strategy, the bitcoin miners and the semiconductor names — and why the same filing produces different position counts, share totals and rankings depending on how the rows are read.
September 2, 2026 · 18 min read
Bypassing the 3% Card Tax: How I Built an x402 Settlement Layer for AI Agents and Travelers on Arbitrum
A $340 resort checkout loses $11.90 to five intermediaries before it reaches the hotel — three days later. Here is how I built Furlpay's x402 settlement layer on Arbitrum instead: the actual contract code, measured gas benchmarks from the 34-test suite, the paymaster math behind zero-gas UX, and a direct answer to 'why not just use Stripe?'
July 8, 2026 · 11 min read