Tools/Explorers

Seedless Wallet Comparison: MPC, Passkeys, and Social Recovery

Compare seedless Bitcoin and crypto wallet approaches including MPC, passkey authentication, and social recovery mechanisms.

Spark Team

Seedless Wallet Approaches Compared

A seedless wallet eliminates the 12- or 24-word seed phrase that has been the standard backup mechanism since BIP-39. Instead of writing down words on paper, seedless wallets distribute key material across devices, servers, or guardians so that no single point of failure can compromise or lose funds. The approaches differ significantly in how they split keys, who participates in signing, and what happens when a device is lost.

Four major architectural patterns have emerged: multi-party computation (MPC), passkey-based smart wallets, social recovery, and threshold signatures. Each makes different tradeoffs between security, usability, chain support, and custody classification.

WalletApproachKey DistributionCustody ModelChainsOpen Source
FireblocksMPC (MPC-CMP)Cloud + customer + DR shareConfigurable200+MPC lib only
ZenGoMPC (2-of-2)Device + ZenGo serverSelf-custodial (claimed)14+ chainsRecovery kit only
Lit ProtocolMPC (DKG)Distributed across node networkDecentralizedEVM, Solana, CosmosYes
Coinbase Smart WalletPasskeys (ERC-4337)Device secure enclave (P-256)Self-custodialEVM (Base, ETH, Arb)Yes
ArgentSocial recoveryDevice + guardian layerSelf-custodialEthereum, StarkNetContracts only
SafeMultisig + recovery modulesM-of-N owner keysSelf-custodial500+ EVM chainsYes
VultisigThreshold signatures (DKLS23/FROST)User devices only (2-of-3)Fully self-custodial36+ (BTC, ETH, SOL)Yes

For a focused breakdown of MPC versus traditional multisig, see our MPC wallet comparison tool.

MPC Wallets

MPC wallets split a private key into multiple shares using multi-party computation protocols. No single party ever holds the complete key, and shares are combined cryptographically during signing without reconstructing the original key. The three leading implementations take notably different approaches.

Fireblocks targets institutional users with its proprietary MPC-CMP protocol (derived from GG-18 and GG-20). Key shares are distributed across Fireblocks' cloud, the customer's infrastructure, and a disaster recovery share. Over 2,000 institutional clients use Fireblocks, and the platform supports 200+ blockchains. The MPC-CMP library is open source under GPL-3.0. The custody model is configurable: institutions can deploy it as co-custodial, fully custodial, or with customer-controlled recovery depending on how many shares the customer holds.

ZenGo uses a simpler 2-of-2 threshold MPC scheme for consumer users. One key share lives on the user's mobile device and the other on ZenGo's servers. Recovery relies on three factors: the encrypted server share, a recovery file in the user's cloud storage (iCloud or Google Drive), and a biometric FaceLock scan. If ZenGo ceases operations, master decryption keys held in escrow by an independent provider allow users to reconstruct their keys. ZenGo was acquired by eToro for approximately $70 million in April 2026.

Lit Protocol takes a decentralized approach by distributing key generation across a network of nodes running in AMD SEV secure enclaves. Users receive Programmable Key Pairs (PKPs) controlled by configurable auth methods such as OAuth logins or WebAuthn. Signing requires participation from more than two-thirds of the network nodes. Because no central server holds a majority of shares, Lit achieves decentralized custody, but it functions as a developer SDK rather than a consumer wallet.

In August 2023, Fireblocks disclosed the "BitForge" vulnerabilities (CVE-2023-33241, CVE-2023-33242): critical flaws in MPC implementations used by multiple vendors that could have allowed key extraction after as few as 16 signatures in some cases. All affected vendors patched before public disclosure, but the incident highlighted that MPC security depends heavily on implementation quality, not just the protocol design.

Passkey-Based Smart Wallets

Passkey wallets use the WebAuthn standard to generate cryptographic keys inside a device's secure enclave (or TPM). The passkey signs transactions directly, with no seed phrase, server-held shares, or guardian setup required. On EVM chains, passkeys pair with account abstraction (ERC-4337) to create smart contract wallets that accept passkey signatures.

Coinbase Smart Wallet, launched in June 2024, is the highest-profile implementation. It generates a P-256 key pair inside the device's secure enclave and uses the RIP-7212 precompile (falling back to a Solidity verifier) for on-chain signature verification. Users create a wallet with a single biometric prompt, and the passkey becomes the owner of an ERC-4337 smart contract account. Coinbase never holds the key. Recovery works by adding additional passkeys from other devices or enabling a Coinbase-managed recovery key as a backup owner. The smart wallet contracts are fully open source and have been audited by Cantina, Certora, and Code4rena.

The main limitation of passkey wallets today is chain support. Because they rely on smart contract accounts, they only work on chains with ERC-4337 infrastructure: Ethereum, Base, Arbitrum, Optimism, and other EVM chains. Native Bitcoin support is not available since Bitcoin does not have smart contract accounts. Passkey syncing across platforms (Apple, Google, Microsoft) has improved significantly through 2024 and 2025, reducing the risk of device lock-in that plagued earlier implementations.

For a deeper look at how passkeys intersect with Bitcoin, see our research on Bitcoin passkey wallet authentication.

Social Recovery Wallets

Social recovery wallets store the signing key on the user's device but add a smart contract layer that allows designated "guardians" to authorize key rotation if the device is lost. The user signs transactions normally without guardian involvement; guardians only participate during recovery.

Argent pioneered this model for consumer wallets. Users designate guardians: trusted contacts, hardware wallets, or Argent's own cloud service (Argent Guard). Recovery requires approval from a majority of guardians, and a 36-hour timelock on Ethereum (7 days on StarkNet) prevents attackers from rushing through a malicious recovery. Argent rebranded to "Ready" in June 2025, with its primary focus shifting to StarkNet, though the Ethereum L1 vault remains operational.

Safe (formerly Gnosis Safe) uses a multisig model where M-of-N owners must co-sign every transaction. While not a "seedless" wallet in the pure sense (each owner still manages their own key), Safe eliminates single-key risk and can be configured with recovery modules that function like social recovery. Safe secures over $35 billion in assets across 61 million accounts on 500+ EVM chains, making it the dominant treasury wallet for DAOs and institutions.

In February 2025, Safe's front-end infrastructure was compromised in a supply chain attack attributed to North Korea's Lazarus Group, enabling the approximately $1.5 billion theft from Bybit's Safe multisig. The attacker compromised a Safe developer's workstation and injected malicious JavaScript into the signing interface. Safe's smart contracts were not exploited: the attack targeted the environment in which owners reviewed and approved transactions.

Threshold Signature Wallets

Threshold signature wallets generate key shares across multiple devices controlled by the same user, with no server component at all. This approach achieves the seedless UX of MPC while maintaining fully self-custodial control.

Vultisig, built by THORChain developers, creates a 2-of-3 vault by default across the user's own devices (phone, laptop, tablet). Key generation uses a ceremony over the local network, and signing requires any two of the three devices. If one device is lost, the remaining two can reshare the vault to onboard a replacement. Vultisig uses DKLS23 (a threshold ECDSA scheme with 3 signing rounds) for Bitcoin and EVM chains, and FROST-Ed25519 for EdDSA chains like Solana. Both the DKLS23 implementation (by Silence Laboratories) and the wallet itself are fully open source and audited by Trail of Bits. It supports 36+ chains natively.

The tradeoff is usability: users must own and manage multiple devices, and the initial key ceremony requires all devices to be online simultaneously. Vultisig also offers a 2-of-2 "Fast Vault" with a server-held share for quicker signing, though this trades some self-custody guarantees for convenience.

Security Model Comparison

The attack surface for each approach differs based on where key material lives and what infrastructure must be trusted.

ApproachPrimary Attack SurfaceRecovery RiskServer DependencyUnilateral Exit
MPC (server-held share)Server compromise, MPC implementation bugsProvider shutdown riskHighVaries (some have recovery kits)
MPC (decentralized, Lit)Node collusion, enclave vulnerabilitiesAuth method lossNetwork-dependentNo (requires network liveness)
Passkeys (smart wallet)Device compromise, passkey sync vulnerabilitiesPasskey loss if no backup ownerLow (on-chain contract)Yes (user owns the passkey)
Social recoveryGuardian collusion, front-end attacksGuardian unavailabilityLow (on-chain contract)Yes (user holds signing key)
Threshold (user devices)Multi-device theft, key ceremony interceptionDevice loss below thresholdNoneYes (no server involved)

The July 2023 Multichain bridge exploit ($126 million lost) illustrated the worst case for server-dependent MPC: when the founding team was detained by authorities, the MPC key management system became a single point of failure because key control was concentrated rather than genuinely distributed. By contrast, threshold wallets like Vultisig and protocol-level FROST signing (as used by Spark) eliminate server dependency entirely.

Are Seedless Wallets Truly Self-Custodial?

The custody classification of seedless wallets is a genuine regulatory and practical question, not just marketing. The core test is whether the user can unilaterally move their funds without any third party's cooperation.

For self-custody purists, a wallet where a server holds a key share and can refuse to co-sign is not truly self-custodial, regardless of what the provider claims. If ZenGo's servers go offline and the user has not activated escrow recovery, funds are effectively frozen. Fireblocks deployments where the customer holds two of three shares pass the self-custody test; configurations that depend on Fireblocks infrastructure do not.

Regulatory bodies have taken different positions. FinCEN's framework focuses on whether the provider has "total independent control" over virtual currency transactions. Under this test, MPC wallets where the provider cannot unilaterally transact are not money transmitters. However, the Model Money Transmission Modernization Act expands the definition to include the power to "prevent indefinitely" a transaction, which could capture 2-of-2 MPC providers like ZenGo. The EU's MiCA regulation explicitly places self-custodial wallets outside its scope, though MPC wallets fall into ambiguity depending on the specific architecture.

The industry trend favors architectures with unilateral exit: the user can always force a withdrawal to an on-chain address without the provider's cooperation. Smart contract wallets (passkey and social recovery) achieve this inherently since the contract is on-chain. Spark's FROST-based architecture achieves this by design: the user's key share is sufficient to force-exit to on-chain Bitcoin, even if the Spark Service Operator stops cooperating. For more on how MPC and multisig compare for Bitcoin custody, see our MPC vs multisig custody analysis.

FROST Signatures and the Seedless Paradigm

FROST (Flexible Round-Optimized Schnorr Threshold signatures) is a threshold signature scheme standardized as RFC 9591 in June 2024. It enables t-of-n participants to collaboratively produce a valid Schnorr signature that is indistinguishable from a regular single-signer signature on-chain.

FROST is particularly significant for Bitcoin because Taproot (activated in 2021) uses Schnorr signatures natively. Unlike threshold ECDSA schemes (GG-18, GG-20) that require six or more rounds of communication, FROST completes signing in two rounds (one round with preprocessing). The resulting signature looks identical to any other Taproot key-path spend on-chain: a 57.5 vB input regardless of whether one person or one hundred signed. This compares to roughly 350 vB for a 3-of-5 script multisig, translating to roughly 80% fee savings.

Spark uses FROST as part of its statechains-inspired architecture. The user and the Spark operators (currently Lightspark, Flashnet, and Breez) each hold key shares. For off-chain operations (instant transfers, stablecoin payments), both parties co-sign using FROST. But the user can always unilaterally exit to on-chain Bitcoin using just their own share: this is the critical difference from custodial MPC setups. FROST also supports key refresh (proactive secret sharing), allowing operators to generate new shares for the same group public key without any on-chain transaction, invalidating previously compromised shares. For a technical deep dive into FROST, see our FROST threshold signatures explainer.

How to Choose a Seedless Wallet

The right seedless approach depends on your chain requirements, custody preferences, and technical comfort level.

If you need Bitcoin support with true self-custody: threshold wallets (Vultisig) or FROST-based protocols (Spark) are the strongest options. MPC wallets like ZenGo support Bitcoin but introduce server dependency. Passkey and social recovery wallets do not support native Bitcoin today.

If you want the simplest onboarding experience on EVM chains: passkey wallets (Coinbase Smart Wallet) provide one-tap setup with no seed phrase, no guardian configuration, and gasless transactions via paymasters.

If you manage a DAO treasury or institutional funds: Safe's multisig with recovery modules offers battle-tested security across 500+ EVM chains and is fully open source. Fireblocks is the institutional standard for MPC-based custody with configurable compliance policies.

If you want zero server dependency: Vultisig distributes all key shares across your own devices. There is no server to compromise, no provider that can shut down, and no guardian to become unavailable. The cost is operational complexity in managing multiple devices.

For comparisons of specific implementations, see our social recovery wallet comparison and passkey wallet comparison.

Frequently Asked Questions

What is a seedless wallet?

A seedless wallet is a cryptocurrency wallet that does not require users to write down or store a seed phrase (the 12- or 24-word mnemonic defined by BIP-39). Instead, key material is distributed across multiple locations: server shares (MPC), device secure enclaves (passkeys), guardians (social recovery), or multiple user-owned devices (threshold signatures). The goal is to eliminate the single point of failure that seed phrases represent while maintaining the user's ability to recover funds if a device is lost.

Are MPC wallets safe?

MPC wallets can be safe when properly implemented, but the security depends heavily on the specific implementation rather than the protocol alone. The BitForge vulnerabilities disclosed in August 2023 showed that even well-funded MPC providers can have critical implementation flaws that allow key extraction. The Multichain bridge exploit in July 2023 demonstrated that server-dependent MPC systems can become single points of failure if the operators are compromised. When evaluating an MPC wallet, check whether the implementation has been independently audited, whether recovery works without the provider's cooperation, and whether the code is open source.

Can I use a seedless wallet for Bitcoin?

Yes, but options are more limited than on EVM chains. ZenGo supports Bitcoin through its 2-of-2 MPC scheme. Vultisig supports native Bitcoin through DKLS23 threshold signatures across user devices. Spark uses FROST threshold signatures to enable seedless Bitcoin custody with unilateral exit capability. Passkey-based wallets (Coinbase Smart Wallet, Clave) and social recovery wallets (Argent, Safe) do not support native Bitcoin because they rely on smart contract accounts that Bitcoin's UTXO model does not support.

What happens if my seedless wallet provider shuts down?

It depends on the architecture. ZenGo deposits master decryption keys with an independent escrow provider, allowing users to reconstruct their keys even if ZenGo's servers are permanently offline. Passkey and social recovery wallets store everything on-chain, so provider shutdown does not affect fund access. Vultisig has no server component in its Secure Vault mode, so provider shutdown is irrelevant. For Spark, users can unilaterally exit their VTXOs to on-chain Bitcoin regardless of whether the Spark Service Operator is operational. The highest risk is with MPC wallets that do not offer independent recovery: if the provider goes offline and no recovery mechanism exists, funds can become inaccessible.

How do FROST signatures differ from MPC-based threshold ECDSA?

FROST operates on Schnorr signatures and completes signing in two communication rounds (one with preprocessing), compared to six or more rounds for GG-20 and three rounds for the newer DKLS23 protocol. FROST signatures are indistinguishable from regular single-key Schnorr signatures on-chain, providing a privacy benefit: observers cannot tell that multiple parties were involved. FROST works natively with Bitcoin's Taproot and was standardized as RFC 9591 in 2024. Threshold ECDSA is required for pre-Taproot Bitcoin and non-Schnorr chains but carries more implementation complexity due to the need for Paillier encryption or oblivious transfer sub-protocols.

Is social recovery better than a seed phrase?

Social recovery eliminates the single-point-of-failure risk of seed phrases (which can be lost, stolen, or destroyed) but introduces different risks: guardian collusion, guardian unavailability, and front-end attacks on the signing interface. The Safe/Bybit incident in February 2025 showed that multisig wallets can be compromised through supply chain attacks even when the underlying smart contracts are secure. For most users, social recovery is a meaningful UX improvement over seed phrases, provided guardians are chosen carefully and timelocks are enabled to prevent rushed malicious recoveries.

Which seedless wallet approach is most decentralized?

Among current implementations, Lit Protocol and Vultisig represent the most decentralized approaches. Lit distributes key shares across an independent node network with no central server, though it depends on network liveness. Vultisig eliminates all external dependencies by distributing shares exclusively across the user's own devices. On Bitcoin, Spark's FROST-based model provides a middle ground: the Spark operators (Lightspark, Flashnet, Breez) facilitate off-chain operations, but the user retains unilateral exit capability, making it non-custodial despite the cooperative signing model.

This tool is for informational purposes only and does not constitute financial or security advice. Wallet security models, supported chains, and open-source status change frequently. Always verify current capabilities on each provider's official documentation before making custody decisions.

Build with Spark

Integrate bitcoin, Lightning, and stablecoins into your app with a few lines of code.

Read the docs →