A Threshold Signature Scheme (TSS) is a cryptographic protocol in which a private key is distributed among n parties such that any subset of at least t parties can jointly compute a valid digital signature without any single party ever possessing the complete private key, while fewer than t parties gain zero information about the key. TSS extends threshold secret sharing (Shamir’s Secret Sharing) to the signing operation itself, producing a signature that is indistinguishable on-chain from a standard single-key signature, thereby enhancing privacy and reducing transaction fees compared to traditional on-chain multisig. TSS underpins distributed key management for exchanges, MPC wallets, and cross-chain bridge custody architectures.
Content
- The mathematical foundations of threshold signature schemes trace to Shamir’s Secret Sharing (1979) and the subsequent body of work on threshold cryptography by Desmedt, Frankel, Pedersen, and others through the 1990s. Classical threshold RSA signatures allowed n parties to share an RSA private key with t-of-n reconstruction, but early constructions required a trusted dealer and incurred significant communication overhead. The rise of elliptic curve cryptography in blockchain contexts motivated new t-of-n ECDSA protocols in the 2010s. GG18 (Gennaro and Goldfeder, 2018) was among the first practical t-of-n ECDSA TSS protocols without a trusted dealer, enabling threshold custody for Bitcoin and Ethereum without changes to the underlying chain protocols.
- The technical core of a TSS protocol for ECDSA involves two challenges: generating shares of the private key without a trusted dealer (distributed key generation, DKG), and computing the ECDSA signature’s nonce r = k·G and the signature value s = k^(-1)(h + r·x) mod n without revealing x (the private key) or k (the nonce). Since k is a function of a random nonce and the message, computing it in a distributed manner requires multiplicative-to-additive (MtA) share conversion protocols. GG20 introduced paillier encryption-based MtA. FROST (Flexible Round-Optimised Schnorr Threshold, 2020) achieves the same goal for Schnorr signatures in two rounds rather than the multi-round ECDSA variants, making it practically faster and simpler.
- TSS is now deployed at scale in institutional cryptocurrency custody. Major custodians (Fireblocks, Coinbase Custody, BitGo) offer MPC/TSS-based custody as an alternative to hardware security modules (HSMs) with traditional multisig. The TSS model disperses signing authority across geographically separated servers running within secure enclaves, so compromise of any single node or datacenter does not yield signing authority. Cross-chain bridge protocols — frequently targeted by catastrophic hacks — are adopting TSS to eliminate the single-keyholding custodian that represents an attractive target.
- In 2024–2025 FROST standardisation through the IETF (RFC 9591) has provided a stable specification for Schnorr threshold signatures, and the Bitcoin Taproot upgrade enabling Schnorr signatures on-chain has made FROST-based custody operationally viable for Bitcoin. MuSig2 (another Schnorr multi-party signing protocol) is a simpler key-aggregation scheme for the cooperative case (all parties are honest). Research into proactive secret sharing (periodically refreshing shares to limit the window in which an attacker must compromise t nodes) and threshold BLS signatures for use in proof-of-stake consensus is active. The intersection of TSS with trusted execution environments (Intel TDX, AMD SEV) for cloud-based MPC wallets is an emerging enterprise custody architecture.