The key that is never assembled
Shamir rebuilds the private key in one process every time you sign, so it protects the key at rest and abandons it when it matters. Threshold signatures never assemble it.
Split the key into five shares, require three to sign, keep the shares in different places. That is the sentence every custody design starts with, and it describes two schemes that could not be more different at the moment of signing. Under Shamir's secret sharing, the three shares are brought together, the private key is reconstructed in one process's memory, the signature is produced, and the key is discarded. Under a threshold signature scheme, the three parties each compute a partial signature from their own share, the partials are combined, and a valid signature appears without the whole key ever existing anywhere. For a system that signs once a year, the difference is academic. For a system that signs many times a day, it is the entire threat model, and the question to ask of any custody design is not how many shares exist but whether a full key ever exists in one memory.
The reconstruction moment
I call it the reconstruction moment: the instant, if any, at which the complete private key exists in one address space. A custody design is audited by locating that moment, where it happens, in which process, for how long, and who could read that process's memory during it. Shamir has one on every signature. A hardware wallet has one permanently, inside the secure element, which is the point of the secure element. A threshold scheme has none during signing, and the audit question becomes whether it has one anywhere else: at key generation, if a dealer creates the key and splits it; at backup, if the shares are combined to produce a recovery phrase; at recovery, if the phrase is used to rebuild them.
The moment has a duration as well as a place, and the duration matters less than people hope. A key that exists in memory for a millisecond is still a key that existed in memory, and an attacker who can read the process can read it in that millisecond, because the attacker is not waiting for a lucky moment; they are reading every signature. Once the moment is located, the rest of the audit writes itself. The process that holds the reconstructed key is the target; whoever can read its memory, dump its core, attach a debugger, or compromise the host it runs on has the key, and every one of the four other shares was irrelevant to that attacker. A Shamir design protects the key at rest, in the interval between signatures, and abandons it at the moment it is used. For a cold key that signs a treasury transfer twice a year, that interval is almost all of the time and the trade is fine. For a hot wallet that executes arbitrage across five venues, the moment recurs hundreds of times a day, on a machine that is connected to the internet by design, and the interval in which Shamir protects anything shrinks toward nothing.
What threshold signatures changed
The schemes that avoid the moment are threshold signature schemes, and the practical ones have converged over the last few years. For ECDSA, the curve Ethereum and Bitcoin use, the line runs from Gennaro and Goldfeder's 2018 protocol, through their 2020 protocol with a non-interactive online phase and identifiable aborts, to CGGMP21, whose abstract commits to only the last round needing the message, with the other rounds done in a preprocessing stage, plus a periodic refresh that gives proactive security. For Schnorr signatures, FROST, standardised as RFC 9591 in June 2024, signs in two rounds, and the first round can be run ahead of time so that the signature needs one round when the message arrives.
The progression in the table is about latency, not security: every protocol on it is reconstruction-free during signing, and what improved was how much of the work could be done before the message existed, which is what makes a threshold scheme usable on a hot path where a signature is needed within a block time. That is the property a bot needs. A key that is never assembled is only useful if the signature it produces arrives before the opportunity is gone.
The moments outside signing
The audit is not finished when signing is shown to be reconstruction-free, because the other three lifecycle events can reintroduce the moment. Key generation is the first: a scheme that has a dealer create the private key and split it has a reconstruction moment at birth, in the dealer's memory, and everything after is protecting a key that already existed in one place; distributed key generation, which every protocol in the table supports, avoids it. Backup is the second and the one that most often undoes the design: a product that exports a seed phrase for recovery has, at that moment, combined the shares, and a user who writes the phrase on paper has a full key in one place for the life of the paper. Recovery is the third, and it mirrors backup.
A design is reconstruction-free only if no moment exists in signing, generation, backup and recovery alike. The honest alternative for backup is share-level recovery: each share is backed up separately, to separate custodians or devices, and recovery means re-establishing enough shares to sign, never rebuilding the key. That is more work for the user than a seed phrase, and it is the price of the property.
Where the standards are
The reason to write this in 2026 is that the standards process has caught up with the practice. FROST has an RFC. NIST's multi-party threshold cryptography project published its final call for threshold schemes, NIST IR 8214C, on 20 January 2026, and is running preview talks for the submissions through the year, with the third set scheduled for 29 and 30 September 2026. The vocabulary in which a custody design is described to an auditor is about to become standard, and the reconstruction moment is the property that vocabulary is organised around, even where it is not named that way.
What this means for a hot wallet
I run a bot that executes flash-loan arbitrage from a hot wallet across five venues, which is the kind of system that signs many times a day from a machine that is online by definition, and the reconstruction moment is the lens I use to think about its custody without claiming any particular scheme for it. Shamir, for that wallet, would be a key-at-rest protection on a key that is almost never at rest. Threshold signing removes the moment from the hot path, at the cost of a round of communication per signature that the newer protocols have pushed almost entirely into preprocessing. What it does not remove is every other way a hot wallet loses money: a compromised host can still be made to sign a transaction it should not, with a perfectly reconstruction-free protocol, because the protocol authenticates the shares and not the intent.
That last point is the boundary of the argument. Locating the reconstruction moment tells you whether an attacker who reads memory gets the key. It does not tell you whether an attacker who controls the process gets a signature, which is a policy question, answered by transaction limits, allow-lists and a signer that refuses what the policy forbids. A custody design needs both answers. The first one is a single question, and the schemes that answer it well have RFC numbers now.
Get new posts by email
Occasional essays on engineering, AI, and building for the people technology leaves behind.
Subscribe with RSS