Texture
Resources

Security Protocols

Explore the advanced cryptographic technologies and infrastructure, such as Multi-Party Computation (MPC), used to protect digital wealth.

A time-lock is a security protocol that places a mandatory delay on any transaction before it is broadcast to the network. This acts as a critical safety net against unauthorised access or physical coercion. If a withdrawal is initiated without your consent, the time-lock provides a cooldown period (typically 24 to 48 hours) to detect the activity and cancel the transaction before the funds can leave a custodian.

Multi-Party Computation (MPC) is an advanced security technology. Instead of creating a single password or private key, MPC generates multiple independent cryptographic shards. These shards are stored separately in highly secure, isolated environments. To authorise a transaction, a specific number of these separate shards must interact securely without ever combining into a single, vulnerable key.

A private key is a secure alphanumeric code that proves ownership of your digital assets and allows you to authorise transactions. It functions much like a highly complex password or PIN for a traditional bank account. Because anyone who possesses the private key can move the associated funds, protecting it is the most critical aspect of cryptocurrency security. Premium digital banks use technologies like Multi-Party Computation to secure these keys without relying on a single point of failure.

A multi-signature (multi-sig) wallet requires multiple complete private keys to authorise a transaction. This creates a visible footprint on the blockchain, revealing the security setup. MPC technology is more advanced. It creates separate, invisible key shares rather than multiple whole keys. When an MPC transaction is authorised, it looks like a standard, single-signature transaction on the blockchain, providing superior privacy and greater flexibility in managing security protocols.

A Bitcoin node is a computer connected to the Bitcoin network that independently verifies and records every transaction. Nodes matter for security because they ensure no single entity can alter the ledger or cheat the system. Many secure digital asset platforms run their own full nodes to independently verify client transactions. This ensures absolute accuracy and removes reliance on third parties to validate the security of the network.

A seed phrase is a master recovery code typically made up of a specific sequence of 12 to 24 random words. It functions as a backup tool that allows you to recover your private keys and access your cryptocurrency if you lose your self-custodied digital wallet or physical device. Because anyone who knows these words can access your funds, it is critical to store the seed phrase entirely offline in a secure physical location. Using a regulated custodian to hold your digital assets removes the need to manage your own keys or rely on seed phrases.

The primary difference is that a public key is used to receive funds, while a private key is used to authorise spending them. A public key functions like a traditional bank account number that you can safely share with others so they can send you cryptocurrency. A private key acts like the highly secure password or PIN to that account, which must never be shared with anyone to prevent unauthorised withdrawals.

Address whitelisting is a security feature that restricts outbound cryptocurrency transfers only to a list of pre-approved recipient addresses. When this feature is activated, your funds cannot be withdrawn or sent to any new, unknown destination without passing through a strict verification process. This provides a powerful layer of defence against hackers, ensuring that even if your account credentials are compromised, it is harder for attackers to move your funds to their own wallets.

Phishing attacks target cryptocurrency investors by tricking them into voluntarily handing over their private keys, seed phrases, or account login credentials. Scammers often achieve this by creating fake websites, impersonating customer support agents on social media, or sending deceptive emails that closely mimic legitimate financial platforms. To stay secure, investors should always verify official website URLs and remember that no reputable platform will ever ask you to share your private keys or seed phrase.

Two-factor authentication (2FA) is a security protocol that requires a user to provide two distinct forms of identification before accessing an account or authorising a transaction. This usually involves entering a standard password followed by a temporary code generated by an authenticator app. This ensures that even if a hacker discovers your login credentials, they cannot access your wealth without physical possession of your secondary device.

An aerial drone view looking down the rugged ridge of the Rock of Gibraltar surrounded by blue ocean water.

Still have questions before you join us?

Let's talk

Be in the know.
Unlock the future of money.

Get the latest Bitcoin news, product updates, and exclusive insights from Xapo Bank.