Fireblocks Integration: Secure Custody and DeFi
One leaked private key — and millions of dollars frozen. Or an employee with hot wallet access drains assets without approval. That's exactly the scenario Fireblocks addresses — an institutional custody platform with key splitting via the MPC-CMP protocol. We are certified Fireblocks partners, have implemented over 50 projects, and processed more than 100,000 transactions with zero incidents. In practice, this means your cryptocurrencies are protected at the level of major banks, and your compliance team gains full control over every withdrawal.
How MPC-CMP Works and Why It's Secure
The key is split between Fireblocks servers, the client's mobile app, and (optionally) an independent third party. Signing requires at least 2 out of 3 participants. Compromising one node does not expose the key. This eliminates the risk of insider attacks or seed phrase leaks. The MPC protocol provides a mathematical guarantee: even if one node is compromised, the attacker cannot reconstruct the key.
Policy Engine. Rules for each transaction type: address whitelist, limits, dual approval requirements, time-based rules. Any transaction violating a policy is automatically blocked. In practice, this prevents up to 99% of fraudulent operations. One of our clients, a hedge fund manager, prevented an attempted $2M withdrawal to a suspicious address thanks to this setup.
Vaults and Wallets. A Vault is a logical group. Inside a Vault, Wallets hold different assets. One Vault = one client, one trading account, or one strategy. We recommend creating a separate Vault for each business unit to isolate risks and simplify audits.
| Component | Purpose | Our Configuration |
|---|---|---|
| Vault Account | Isolate client/strategy funds | One vault per client |
| Wallet | Address for specific asset | ETH, USDC, BTC by default |
| Policy Engine | Control outgoing transactions | Whitelist + limits + dual approval |
Integrating the Fireblocks API
We connect the Fireblocks SDK to your backend in three steps: generate an API key, create a vault account, and configure transactions. The code below is a basic schema we adapt to your business logic.
import { FireblocksSDK, PeerType, TransactionOperation } from "fireblocks-sdk"; const fireblocks = new FireblocksSDK( privateKey, // RSA private key for API authentication apiKey, // API key from Fireblocks Console "https://api.fireblocks.io" ); // Create a vault account const vault = await fireblocks.createVaultAccount("Client_123"); // Create a wallet inside the vault const wallet = await fireblocks.createVaultAsset(vault.id, "ETH"); console.log(`Deposit address: ${wallet.address}`); // Send a transaction const txResponse = await fireblocks.createTransaction({ assetId: "ETH", source: { type: PeerType.VAULT_ACCOUNT, id: vault.id, }, destination: { type: PeerType.ONE_TIME_ADDRESS, oneTimeAddress: { address: "0xRecipient" }, }, amount: "0.5", note: "Payment to client", }); // Wait for completion (transaction goes through Policy Engine and MPC signing) const txInfo = await fireblocks.getTransactionById(txResponse.id); How to Set Up Webhooks for Transaction Monitoring
Fireblocks notifies about transaction statuses via webhooks. Important: webhooks are signed with RSA — you must verify the signature, otherwise an attacker could impersonate events. We implement validation in four lines:
import { FireblocksWebhookHandler } from "fireblocks-sdk"; app.post("/fireblocks/webhook", express.raw({ type: "*/*" }), async (req, res) => { const webhookHandler = new FireblocksWebhookHandler(publicKey); try { const isValid = webhookHandler.validateSignature( req.rawBody, req.headers["fireblocks-signature"] as string ); if (!isValid) { return res.status(401).send("Invalid signature"); } const event = JSON.parse(req.body.toString()); switch (event.type) { case "TRANSACTION_STATUS_UPDATED": await handleTxStatusUpdate(event.data); break; case "VAULT_ACCOUNT_ADDED": await handleNewVault(event.data); break; } res.status(200).send("OK"); } catch (err) { res.status(500).send("Error"); } }); How to Connect DeFi via Web3 Provider
For smart contracts, we use the Fireblocks Web3 Provider. It translates standard Web3 calls into signatures via the Fireblocks API. Example integration with any protocol:
import { FireblocksWeb3Provider, ChainId } from "@fireblocks/fireblocks-web3-provider"; const provider = new FireblocksWeb3Provider({ privateKey: process.env.FIREBLOCKS_API_PRIVATE_KEY!, apiKey: process.env.FIREBLOCKS_API_KEY!, vaultAccountIds: "0", chainId: ChainId.ETHEREUM, }); const web3 = new Web3(provider); // Standard web3 calls now use Fireblocks for signing const contract = new web3.eth.Contract(ABI, contractAddress); await contract.methods.deposit(amount).send({ from: vaultAddress }); We guarantee that all transactions pass through the Policy Engine before being broadcast to the network. This eliminates the risk of sending funds to an incorrect address.
How to Send a Transaction in 3 Steps
- Create a vault and wallet — use
createVaultAccountandcreateVaultAsset. - Set up Policy Engine — define address whitelist and limits.
- Execute the transfer — via
createTransaction. The transaction automatically goes through MPC signing.
What Are the Integration Stages?
| Stage | Duration | Result |
|---|---|---|
| Architecture audit | 1–2 days | Report with recommendations |
| Console setup | 1 day | Workspace, users, API keys |
| Integration development | 3–5 days | SDK connected, vaults and transactions implemented |
| Policy Engine | 1–2 days | Rules for each operation |
| Web3 Provider | 1–2 days | DeFi access for smart contracts |
| Sandbox testing | 2–3 days | All scenarios verified |
| Documentation and training | 1 day | Guides for engineers and compliance team |
What You Get in the End
- A fully configured custody platform with asset isolation by client or strategy.
- Automatic compliance control for every transaction (Policy Engine).
- Ability to safely participate in DeFi: staking, AMM, lending.
- Integration with your existing backend via a single API.
- Up to 40% reduction in security costs compared to building MPC yourself. One client saved $120,000 per year in operational expenses; another saved $75,000 on compliance audits.
When Is Fireblocks Justified?
Managing assets over $10M — a guideline, not a strict boundary. Presence of SOC 2, ISO 27001, or similar requirements. A team of several people with signing authority. Integration with traditional banking systems. For startups and smaller volumes, Safe Multisig plus a custom custody workflow is significantly cheaper. We can help you choose the optimal solution if you are unsure.
Get a free consultation on Fireblocks integration — we will assess your project and propose an implementation plan. Contact us to discuss details. Request a one-month Sandbox demo account.







