Custodial, non-custodial, MPC or smart-contract wallet - what is the difference?
The real question is who can move the funds. In a custodial wallet your company holds the keys, usually in HSMs, and users sign in with a password, as on an exchange. In a non-custodial wallet the user holds a seed phrase on their own device and nobody else can sign. An MPC wallet splits signing between parties, so it lands on either side of that line depending on who holds the shares. A smart-contract wallet is an on-chain account with its own rules, built on ERC-4337; since Ethereum's 2025 Pectra upgrade, an existing address can also delegate to such code under EIP-7702.
Products often combine them, for example an MPC key that owns a smart account. If you need a dApp that connects to wallets users already have, rather than a wallet of your own, Web3 app development is the better fit.
What is an MPC wallet, and who holds the key shares?
An MPC wallet never has one private key sitting in one place. At setup the parties run distributed key generation: each ends up with a secret share, and together they control one public address. To send, a threshold of them - say 2 of 3 - runs a signing protocol that outputs a normal ECDSA or EdDSA signature, so the chain sees an ordinary account.
Who holds the shares decides what you have built. In a typical consumer design one share lives on the user's phone, one with your server or an MPC provider, and one in an encrypted backup the user controls. If your company can sign with two shares on its own, the wallet is custodial. Recovery follows the same logic: the backup and server shares issue a fresh device share, the old one is invalidated by refreshing all shares, and the address stays the same.
Should we license an MPC provider or build threshold signing in-house?
For most products, license. Commercial MPC and wallet-infrastructure providers run the signing nodes, publish their security reviews and carry the on-call burden; you pay per wallet or per signature and accept their chain list, price changes and exit terms. In-house means running open-source threshold-signature libraries yourself: you control the cost curve and the chain list, but also own protocol upgrades, node hardening and a specialist cryptography review, which is expensive and slow to book.
Our default is to put the provider behind one signer interface in your code - the one shown in the Architecture section - so moving to another provider, or to in-house signing once volume justifies it, changes one module rather than the whole wallet. We recommend an option once we know your expected users, chains and custody model.
Where are the keys stored on a phone and in a browser extension?
On a phone, the seed or key share is encrypted with a key held in hardware: the Secure Enclave on iPhone, the Android Keystore (StrongBox where the device has it) on Android. That hardware key only unlocks after Face ID, a fingerprint or the passcode, and it cannot be copied off the device. The Secure Enclave cannot sign with secp256k1, the curve Bitcoin and Ethereum use, so it guards the wallet key rather than holding it.
A browser extension has no such hardware. Its vault is encrypted with a key stretched from the user's password and locks again after a timeout, which is why extension wallets steer large balances toward hardware wallets. Passkeys are the exception: a passkey signs with P-256 inside the device, and a smart-contract account can verify that signature on-chain, so users get Face ID login with no seed phrase to lose.
What does supporting another chain involve, and how do swaps and on-ramps fit in?
Adding an EVM network is mostly configuration: the same address and signing code, plus a chain ID, RPC endpoints and a token list. Solana and Cosmos are different families, with other curves or address formats, derivation paths, fee models and token standards, so each gets its own client module; Bitcoin adds UTXO handling and PSBT signing on top. Budget by chain family, not by chain name.
Swaps, bridges and fiat on-ramps come from third parties: a DEX aggregator API for quotes and routes, and an on-ramp provider that takes the card payment and runs the buyer's KYC under its own licence. You sign their commercial terms; we build the quote, simulation and confirmation screens around them and show users the fee and the provider before they approve. If trading grows into the product itself, DeFi development is the page to read next.
What does a wallet security review cover, and what can nobody guarantee?
Before release we test what attackers target: seed and share generation, storage and backup, the signing flow, transaction simulation and the approval screen, dApp session handling, and any contracts such as smart accounts or multisig vaults. The audit package - architecture, threat model, test results - goes to the independent firm you choose; we fix what it finds and re-test. If your project is mostly contracts, smart contract development is the closer match.
What no honest company can promise is a wallet that cannot be hacked. A review lowers risk at one point in time. It does not cover a user who signs a malicious approval, a phished seed phrase, a rooted phone or a flaw found later in an open-source library. That is why we build readable transaction previews and unlimited-approval warnings into the wallet, and why patching continues after launch.
How much does a crypto wallet cost, and should we hire in-house instead?
A wallet from our starter base starts from $3,699 and takes 3-6 weeks, depending on platforms, chains and the key model. A custom wallet MVP typically costs $8,000-$25,000 and is scoped at 2-8 weeks; larger scopes are quoted in writing before work starts. After launch, budget for RPC and indexing services, any MPC or on-ramp provider fees, the independent audit, and either your own engineers or a retainer from $2,299/month.
Hiring in-house pays off once the wallet is your core product and can keep a team busy every month. Before that, you need a mix that is rare in one hire: applied cryptography, iOS and Android security, extension development and smart contracts. A company already shipping those pieces gets you to launch sooner, and because you keep 100% of the source code, moving the wallet in-house later is a handover, not a rewrite.