Act I · MPC and threshold signing
The recipe that must never exist
Multi-party computation (MPC) lets a group use a secret key without anyone ever holding the whole key. It starts with a simple problem: one key kept in one place is a single point of failure, and cutting it into pieces doesn't help, because every piece still gives part of the key away. The answer is a different kind of piece, called a share. A share isn't a piece of the key. On its own, it's random noise. The key only appears when enough shares come together, and with MPC, shares can even sign without the key ever being rebuilt.
Why cutting the key doesn't work
A key kept by one person, on one device, can be lost, stolen or misused in one go. Copying it into more hands doesn't fix that: every copy still opens the door. Requiring several keys spreads the responsibility, but each of those keys is still a whole secret.
The obvious next step is to cut one key into pieces and give each person one. But a piece of a key is still part of the key. In the story, the half key's teeth are the real key's teeth. Whoever holds it already knows part of the secret, and only has to guess the rest.
A share isn't a piece of the key
The story's answer is a different kind of piece. The pieces of metal on the bench look nothing like the key, and nothing like each other. Each one, on its own, is just random scrap. But place enough of them under the right light, and together their shadow forms a cat. The cat stands in for the key.
Two pieces cast only meaningless shapes: no cat, just noise. Add a third and the cat appears. The smallest number of shares that reveals the key is called the threshold; here it's three. Add a fourth and you get the same cat. Extra shares don't change the key, and the key isn't cut into five parts that must all be found. Any three shares from the set are enough.
How shares really work
In 1979, Adi Shamir showed how to make shares in a two-page paper called How to Share a Secret. In the real version, the secret is a number. Pick two more numbers at random and use all three to draw a curve. The secret is where the curve starts, at x = 0. Each holder gets one point on the curve, and that point is their share.
Any three points fix a curve like this one, so any three shares can find where it starts, and every group of three finds the same secret. Rebuilding the curve from its points is called interpolation. With only one or two points, there are always curves that pass through them and start at any number you like. Because the two extra numbers were random, every secret is equally possible. Too few shares don't reveal a smaller part of the answer. They reveal nothing.
The arithmetic wraps around, like a clock. In the lab it wraps at 257, so every value stays between 0 and 256; mathematicians call this GF(257). The lab's colors use the same method on three numbers at once, the red, green and blue values of white. Any three shares rebuild white, and a fourth gives the same white, not a brighter one.
Signing without rebuilding the key
If the shares have to meet to rebuild the key, that meeting place becomes a single point of failure again. Anyone who reaches it gets the whole key. Multi-party computation avoids the meeting. Each holder keeps its share and uses it to compute a small contribution. Enough contributions together produce a signature, approving a payment or a change just as the whole key would, but the key itself is never rebuilt anywhere. Using MPC this way is called threshold signing.
Real systems can go one step further. Instead of splitting a key that already exists, the holders can set up the key together, so the whole key never exists, not even at the start. This is called distributed key generation, and it's what the lab's opening illustrates. MPC covers more than signing, too: the same idea lets a group compute other results without revealing their private inputs.
What happened at Radiant
On 16 October 2024, the crypto lending platform Radiant Capital lost about $50 million. Attackers compromised the devices of at least three of its signers. Their screens showed ordinary transactions, while their hardware wallets signed malicious ones. Radiant's wallets on two of its networks needed three signatures out of eleven signers; on two others, three out of nine.
The attack shows why it matters who can use a key, and how many people must agree. It doesn't show that MPC would have stopped it. A group of three can still be tricked into approving the wrong thing, whether they hold keys or shares.
Refreshing shares and changing holders
Refreshing gives every holder a new share of the same key. Old shares can't be combined with new ones, so an attacker who steals one share now and another after a refresh can't use them together. Changing holders works the same way: the group issues a new set of shares for the same key, and the departing holder's old share stops working with the new set.
Refreshing doesn't erase copies, though. Anyone who copied enough shares from the same old set, three in this lab, can still rebuild the key. Real systems need clear rules for deleting old shares, spotting break-ins and recovering from them.
What you can try
In the lab, five holders each keep one share, and any three can sign. Choose who takes part, and watch a signature succeed with three shares and fail with two. Refresh the shares, or add, remove and replace holders, and the key stays the same. The maths panel shows the real numbers behind the shares: pick any shares and see whether they can find the secret.
Where the model stops
The pieces of metal and their shadow are an analogy: real shares are numbers, and the cat stands in for the key. The lab's arithmetic is real, but it uses small numbers, and the whole model runs in your browser, where a real system would keep each share on a separate machine. The signing scene illustrates holders sending contributions; it doesn't produce a real signature that another system could check. And sharing a key doesn't stop people being tricked into approving the wrong thing.
Narration transcript
The narration as spoken in Act I. The explanation above covers what the illustrations leave out.
Everyone knows this part: one key, in one place, in one person's care, is a single point of failure.
Copying the key puts it in more hands. Every copy still opens the door.
In October 2024, a crypto lending platform used eleven signing keys. Three were needed to approve changes.
Attackers compromised three signers’ machines. The screens showed routine work.
In the background, around fifty million dollars moved.
More keys spread the responsibility. But each key is still a whole secret.
So we cut the key into pieces and gave one to each person. But look at this piece. Whoever holds it can already see the key's real teeth. They know part of the secret, and only have to guess the rest.
We need a different kind of piece. Look at these. None of them is part of the key. On its own, each one is just random. But when enough of them come together, the key appears. These pieces are called shares.
In 1979, Adi Shamir showed how to make shares, in a two-page paper called How to Share a Secret.
Here's how that can work. Each of these pieces of metal is a share. Put them under the right light, and together they cast a cat. Think of the cat as the key.
Shamir's trick was to mix randomness into every share. Measure one as closely as you like. Its shape tells you nothing about the cat.
Two shares aren't enough. Look at their shadows. No cat, just noise.
Add a third, and the cat appears. The smallest number of shares that reveals the key is called the threshold. Here, it's three.
Add a fourth, and you get the same cat. Extra shares don't change the key.
But to rebuild the key, the shares have to meet somewhere. Whoever gets into that room gets the whole key. We're back to a single point of failure.
So the shares never meet. Each holder keeps its share and sends only a small contribution, like these streams of light. Together, they sign, approving the payment just as the whole key would. But the key itself is never rebuilt. This is called multi-party computation, or MPC.
Now it's your turn. Here are five shares. They look different, but they work the same way. Any three can sign together. See what happens when you choose who takes part.
Sources
- Radiant Capital Post-Mortem — 18 October 2024
The date, the approximate loss, the faked transaction screens, the compromised devices and how many signatures each wallet needed.
- Adi Shamir — How to Share a Secret (1979)
How a secret can be split so that any threshold of shares rebuilds it while fewer reveal nothing. The original paper, hosted on a university site.
- NIST — Multi-Party Threshold Cryptography
How threshold cryptography uses MPC to set up keys, sign and perform other operations.