CoinTrust

ChainIT Launches Biometric MPC Wallets for Web3 Firms

chainit

ChainIT Inc. has begun rolling out organizational multi-party computation wallets that use biometric verification instead of memorized passwords, seeking to strengthen identity and transaction controls for institutional Web3 operations.

The production release, announced on Oct. 7 during TOKEN2049 Week in Singapore, requires a verified and currently authorized member of an organization to approve each transaction before it can be signed.

The launch follows the company’s presentation of its Agentic Web3 Complete Commerce architecture a day earlier. While that framework examines how artificial intelligence agents could eventually conduct transactions under defined limits, the new wallet focuses on ensuring that human participants are properly identified and authorized before organizational assets can be moved.

ChainIT’s wallet links a verified person’s identity and current organizational authority to the exact transaction being approved, requiring authorization checks before an institutional transaction can be signed.

Biometric Verification Replaces Passwords

The wallet removes the need for users to remember an account password or passphrase by combining biometric liveness detection, device verification, and cryptographic identity proofs.

Under the organizational workflow, a member completes a live biometric check and wallet authentication before issuing an operation-specific approval through their individual wallet identity.

That verification occurs outside the signing enclaves. A separate Primary enclave, an isolated computing environment responsible for authorization checks, then determines whether the wallet-signed approval came from a registered organizational member and corresponds to the requested transaction.

Before signing can proceed, the system verifies that the approval is valid, that the individual remains an active member, and that the authorization matches the precise action being requested. Approvals expire after a short period and can only be used once, preventing authorization for one transaction from being reused for another.

The governance system also connects organizational officers, assigned roles, authority levels, and wallet policies. Adding or removing members and issuing invitations require separate verified authorization, extending the controls beyond individual transactions to the management of organizational permissions.

MPC Keeps Private Keys Distributed

The organizational wallet uses two-party MPC signing, in which the signing key is divided into two cryptographic shares. Each share is protected inside an isolated AWS Nitro Enclave.

Both enclaves must participate in the signing process to generate a standard Ethereum-compatible signature. The complete private key is never reconstructed, while stored MPC key material is encrypted.

A member’s personal authorization key remains separate from the organization’s signing shares. The individual approves the specific transaction, after which the Primary enclave verifies the authorization before the joint signing process begins.

The MPC architecture prevents either signing party from independently producing the organization’s signature, while keeping organizational key shares inside protected enclave infrastructure rather than on employees’ devices.

ChainIT Executive Vice President of Verified Payments and Commerce Eric Tacl said the system is intended to connect verified individuals, organizational authority, transaction-specific permissions and the resulting action rather than simply provide another transaction-signing mechanism.

The wallet capability is included at no additional cost with each ChainIT organizational digital identity profile. Existing organizational wallets are being migrated from the company’s previous model, although functionality and integrations can vary depending on the deployment.

Wallet Launch Supports Agentic Commerce Strategy

The wallet release forms part of ChainIT’s broader strategy around AI-enabled Web3 commerce. On Oct. 6, the company presented a white paper examining how AI-initiated transactions could combine verified identity, delegated authority, compliance controls, and verifiable settlement.

The proposed architecture distinguishes between creating a valid cryptographic signature and establishing whether the correct party had the authority to approve a transaction.

Under the model, AI agents would operate under bounded delegation from verified principals. Their permitted purposes, counterparties, payment methods, transaction values, and operating periods could be defined in advance.

Transactions falling within those predetermined parameters could potentially proceed through automated controls, while exceptions would follow a separate approval process. Access to a wallet or session alone would not constitute payment authority.

The architecture is designed to support multiple payment rails, including qualified stablecoins, tokenized deposits, cards, ACH, wire transfers, and instant payments. ChainIT said the framework is not dependent on a single stablecoin issuer, blockchain or wallet.

The company also distinguishes between technologies already deployed, published architecture, development and pilot initiatives, proposed execution models and external dependencies, noting that the white paper does not mean every described component is generally available.

Institutional Web3 Controls

ChainIT describes its platform as infrastructure for verified identity, organizational authority, compliance and what it calls Complete Commerce. The company says its technology is supported by 15 issued patents and is already used in treasury operations involving major U.S. banks.

The company is positioning transaction-specific authorization as a critical layer for institutional Web3 adoption, particularly as organizations move toward automated and AI-assisted financial activity.

ChainIT said integrations involving external partners and AI agents operating under defined limits are being developed and tested separately from the newly released human-authorized wallet.

The company is also seeking integrations with wallet providers, exchanges, marketplaces, payment platforms, and enterprise Web3 organizations that require verified access and controlled organizational transactions.

Exit mobile version