QORTRACE LABS · SUBSCRIPTION

MPC Vendor Matrix. The PQC posture of every custody stack on the table.

Fireblocks. Coinbase Custody. Privy. Lit. Web3Auth. Safeheron. DFNS. Turnkey. Capsule. Cobo. Zengo. Sepior. Ledger Vault. 15+ vendors, scored against the same 9 criteria QorTrace's MPC Wallet PQC audit methodology uses. Procurement and custody-counterparty teams subscribe so they always know which vendor has a credible PQC migration path before signing.

15+ vendors
Institutional + consumer
9 PQC criteria
DKG · share storage · rotation · recovery
CSV · PDF · JSON
For procurement docs
Methodology refresh
Quarterly (Pro) · Monthly (Ent)
PUBLIC PREVIEW · 3 OF 15 VENDORS

See exactly what subscribers get.

MATRIX v1.0 · as of 2026-02-15
Fireblocks
Institutional MPC custody
QORTRACE SCORE
62
PROTOCOLGG18 / CGGMP21 threshold ECDSA + EdDSA (chain-aware)
SIGNATURE PQC PATHNo public roadmap (as of 2026-02-15)
DKG PQC PATHECDH-only over TLS 1.3 — HNDL-exposed
SHARE STORAGE KEMAES-256-GCM, classical KDF, HSM-backed
ROTATION PROTOCOLProactive refresh available (CGGMP21 §6)
RECOVERY SCHEMEQuorum-sharded recovery package, classical
ATTESTATIONECDSA P-256, audit-trail signed
QORTRACE NOTES
Strong rotation surface (the ceremony exists, which is rare); the gap is everywhere else. HNDL on DKG transcripts is the highest-priority risk.
Coinbase Custody / WaaS
Institutional MPC custody
QORTRACE SCORE
68
PROTOCOLGG18 / DKLs threshold ECDSA
SIGNATURE PQC PATHNo public roadmap
DKG PQC PATHHybrid ECDH + private hardware enclave
SHARE STORAGE KEMAWS Nitro Enclaves + KMS, classical wrap
ROTATION PROTOCOLDocumented (cadence undisclosed)
RECOVERY SCHEMEM-of-N quorum custody, classical
ATTESTATIONECDSA, FIPS 140-2 L3 HSM
QORTRACE NOTES
Best-in-class operational controls; the cryptographic surface is still classical end-to-end. The Nitro Enclave shrinks (but does not eliminate) the HNDL window.
Privy MPC
Consumer MPC wallet (embedded)
QORTRACE SCORE
51
PROTOCOLDKLs threshold ECDSA, 2-of-2 device + cloud shares
SIGNATURE PQC PATHNo public roadmap
DKG PQC PATHTLS 1.3 enrollment, no hybrid KEM
SHARE STORAGE KEMDevice Keychain + cloud HSM, classical
ROTATION PROTOCOLNot exposed in the SDK
RECOVERY SCHEMEEmail + social recovery, classical
ATTESTATIONECDSA
QORTRACE NOTES
Consumer-grade UX optimised; rotation gap + classical recovery path are the headline risks. The embedded-wallet audience is the most HNDL-naive segment of the market.
ALSO IN THE MATRIX · SUBSCRIBER-ONLY
Lit Protocol
Programmable decentralised key management
SCORE LOCKED
Web3Auth (tKey)
Consumer MPC wallet (embedded)
SCORE LOCKED
Safeheron
Institutional MPC custody
SCORE LOCKED
DFNS
Institutional MPC custody (API-first)
SCORE LOCKED
Turnkey
Institutional MPC custody (API-first)
SCORE LOCKED
Capsule (Para)
Consumer MPC wallet (embedded)
SCORE LOCKED
Cobo MPC
Institutional MPC custody
SCORE LOCKED
Zengo
Consumer MPC wallet
SCORE LOCKED
Sepior / Curv (legacy)
Institutional MPC custody
SCORE LOCKED
Knox Custody
Institutional MPC custody
SCORE LOCKED
Ledger Vault
Hybrid HSM + MPC
SCORE LOCKED
Particle Network
Consumer MPC wallet (embedded)
SCORE LOCKED
SUBSCRIPTION TIERS

Pick your tier. Cancel anytime.

PRO
$5,000
/ year · 3 seats
  • Full maintained matrix (15+ vendors)
  • Quarterly methodology refresh
  • CSV / PDF / JSON export
  • Vendor-side change alerts (email)
  • 1-hour analyst Q&A per quarter
Best for procurement + custody-counterparty diligence teams.
Need procurement / NDA first? contact sales.
MOST POPULAR
ENTERPRISE
$15,000
/ year · 25 seats
  • Everything in Pro
  • Custom vendor additions on request
  • Monthly methodology refresh
  • Slack / Teams real-time alert channel
  • Quarterly executive briefing call
  • Private redistribution rights (internal docs)
  • SOC 2 / ISO 27001 / DORA mapping per vendor
Best for regulated financial institutions + custody operators.
Need procurement / NDA first? contact sales.
Already commissioning the MPC audit?

The matrix is bundled into every MPC Wallet PQC Compatibility Checker engagement at no extra cost. Subscribe only if you want the maintained feed *between* audit engagements.

See the MPC Wallet PQC Audit