SEC Approves Onchain Stock Trading, Bans Synthetic Tokens
The SEC approved onchain stock trading while banning synthetic tokens, following criticism from AMC's CEO. Robinhood and others welcomed the move.
The Vault released its own MPC library for institutional custody after a Halborn audit, with plans for open-sourcing and new post-quantum protocols.
Barcelona, 17 September 2026. The Vault, a Swiss and EU-regulated platform for institutional digital asset custody, has introduced its own multi-party computation (MPC) library. MPC is the cryptographic technique that lets separate parties each hold a share of a signing key, meaning the full private key is never assembled on a single device or server. The rollout comes after an independent security review by blockchain security firm Halborn, whose final report was delivered earlier this week and confirmed that every issue raised had been fixed and verified.
Artem Stopnevich, chief executive of The Vault, unveiled the library at the European Blockchain Convention in Barcelona, calling it the first sovereign cryptographic library for institutional custody in Europe, and noting that it followed an independent audit by Halborn.
The library supports The Vault’s co-signing model, where no single participant — The Vault included — can move assets without another party’s approval. Many custody providers buy this component from an external vendor, locking themselves into the vendor’s schedule for security patches, the curves and protocols it supports, and how much it will disclose during due diligence.
The Vault has built it internally, which the company describes as sovereign cryptography: the code, the signing protocol and the release cycle are all controlled by the platform, so security updates are shipped on its own timeline, auditors can inspect the entire codebase, and the protocol can adapt as standards change.
“For an institution, custody is a risk decision that has to be signed off internally, and it comes down to a single question: who is able to move an asset, and under what controls,” said Artem Stopnevich, Chief Executive Officer of The Vault, speaking on the sidelines of the European Blockchain Convention in Barcelona, where he joined a panel on the custody of tokenised funds. “We are the only EU-regulated custody provider running institutional MPC cryptography of its own making, and we took the view that we would not put it in front of clients until somebody outside this company had taken it apart at the protocol level, which is what Halborn has now done.”
The library covers distributed key generation, resharing, refresh and recovery, threshold ECDSA and EdDSA signing, as well as commitment, oblivious transfer and zero-knowledge proof primitives, plus the transport that moves protocol messages between signers. It is written in Rust, a systems language whose compiler ensures memory safety without needing a garbage collector, and the same implementation runs on The Vault’s servers and in the mobile signer for iOS and Android, so a single codebase is covered by the audit.
“The properties we need at the signing layer are the ones the compiler can enforce for us: no use-after-free, no data races across the concurrent rounds of a protocol, and explicit control over how key material is held in memory and erased once it is no longer needed,” said Yurii Derbasov, Chief Technology Officer at The Vault. “The language does not make a protocol correct, which is why the design itself needed an external review of this depth.”
Halborn’s audit covered 91 files, spanning the cryptographic core, its test suite and the iOS and Android signer apps. Issues found during the review were resolved in the codebase as the engagement ran, and Halborn checked each fix against the specific commit that implemented it, confirming the remaining items in August 2026.
“It was a pleasure to work together with The Vault on securing their MPC custody. Security was clearly a priority for their team, and all findings raised during the engagement were remediated and verified. For institutional custody, proprietary cryptography gives providers direct control over security fixes and protocol updates, and allows auditors to examine the complete implementation rather than stopping at a vendor boundary. That matters when clients are performing technical due diligence on who can move their assets.” said Gabi Urrutia, SVP Security & Field CISO at Halborn.
With co-signing, the client keeps a key share on their own device, and the mobile signer is the app that holds and uses that share. It is offered as an add-on to The Vault’s SaaS custody product.
Going forward, The Vault plans to release the Rust library as open source so anyone can review the cryptography, and its cryptography team is developing two new protocols.
The first is a threshold version of ML-DSA, the post-quantum signature scheme standardized by NIST under FIPS 204 for a single signer; there is currently no NIST-standard threshold form, and candidate approaches — both classical and post-quantum — are in a competitive selection process under the NIST First Call for Multi-Party Threshold Schemes, which started in January 2026. The second is a new threshold post-quantum password-authenticated key exchange, or PAKE.
The full report is available to institutional clients on request (media@thevault.inc).
About The Vault
The Vault is a Swiss and EU-regulated institutional infrastructure platform for digital assets, serving corporate treasuries, financial institutions, family offices, and payment providers. It covers the full lifecycle, from secure custody and treasury operations to back-office management and wallet infrastructure, and is built on proprietary threshold MPC cryptography developed by an in-house research team. It is available in SaaS and On-Premise, with a bespoke modular architecture that can be customized to each company’s needs and frameworks.
Share to
Disclaimer: this article comes from third-party media and is provided for reference only. It does not constitute investment advice. Crypto and other financial products carry significant price volatility risk, so please make your own decisions carefully.
The SEC approved onchain stock trading while banning synthetic tokens, following criticism from AMC's CEO. Robinhood and others welcomed the move.
iFX EXPO Asia will take place at the Hong Kong Convention and Exhibition Centre from 7-9 October 2026, expecting over 5,000 attendees.
South Korea referred 18 Polymarket users to prosecutors over $12.7M in bets, part of a wider crackdown on the prediction market.
A House panel approved a bill to create a strategic Bitcoin reserve in a 28-21 vote, while another committee advanced a digital asset tax bill. Both face…