feature

Curv boss Itay Malinger is on a mission to eliminate the private keys from crypto wallets

BusinessFebruary 9, 2021, 1:45PM EST
Curv boss Itay Malinger is on a mission to eliminate the private keys from crypto wallets
Partner offers

Quick Take

  • Curv is a pioneer in multi-party computation, an emerging vein of cryptography that is now being applied to cryptocurrency security.
  • The past three years have been an “uphill battle” to persuade potential customers that MPC is better, says Malinger, but the message may be starting to sink in.

We'd love your feedback.

Advertisement

Describing what a company does rarely warrants more than a single sentence. In the case of Curv, that is not going to do the trick.  

It’s not enough simply to call the firm a pioneer in the area of multiparty computation (MPC). After all, according to co-founder and CEO Itay Malinger, being able to clearly explain the cryptographic technology underlying the company’s software is crucial to the firm’s success. 

That’s been tough sledding for most of the company’s three-year existence, he says. But these days, just as crypto has started to find its way into the mainstream, it may be starting to click.

Malinger’s company is one of a dizzying number of outfits out there aiming to capitalize on the growing demand for crypto custody. But Curv, which raised $23 million from investors including CommerzVentures, Coinbase Ventures and Digital Currency Group in July 2020, is one of only a few firms to venture into the realm of MPC, a technology that is arguably still unproven for mainstream applications. 

“We were the first to announce a product in MPC,” says Malinger over a Zoom call. “I’m happy to see that others have come through. I think that for the software-based solutions, it is becoming the standard.”

Now if only Malinger could help more people wrap their heads around how it works.

Cyber heritage

Malinger is a relative newcomer to crypto, but he’s no stranger to the high-stakes field of cybersecurity. He and Curv co-founder Dan Yadlin belong to the long line of cybersecurity entrepreneurs who have spent time in the Israeli intelligence services.

The firm’s chairman, Nadav Zafrir, used to run Unit 8200, the Israeli equivalent of the National Security Agency in America.

“It’s not a coincidence that all of the MPC players are based out of Israel because there’s not only a cybersecurity hub in Israel, but also a cryptography hub in the Israeli academia,” says Malinger.

He launched Curv in 2017 after a stint of national service and three years in cybersecurity at Akamai Technologies, the Cambridge, Massachusetts-based content delivery network.  

Malinger and Yadlin decided to enter the market after witnessing the spate of hacks that plagued crypto exchanges several years ago.

At Akamai, it was Malinger’s job to help secure e-commerce businesses against the theft of credit card details. Criminals profit from such work by selling card details on the black market.

“But the monetization of a hundred million credit cards is a very long process, it can take you a year,” he says. “What was interesting about crypto was that the monetization of $100 million stolen in crypto is immediate. So you saw a shift of the bad guys going from stealing credit cards to going after the digital asset exchanges."

Malinger decided to follow them.

A software-based alternative

Malinger’s starting point was that the process of securing cryptocurrencies against expert thieves called for a software-as-a-service product.

The existing solutions — primarily so-called hot (internet-connected) and cold (separate from the internet) digital wallets — were not up to scratch.

“The idea behind Curv was to replace all this legacy — it’s funny that I’m saying legacy, after all it’s only been ten years since bitcoin was introduced,” he says.

What Malinger built is a cloud-based wallet that can be used to secure cryptocurrencies without compromising on easy access and control of the assets.

One of Curv’s key selling points is that it removes private keys — which are used to prove ownership of crypto — as a single point of failure. Many of the biggest crypto heists have come after attackers gained access to private keys associated with internet-connected wallets owned by crypto exchanges.

This is where MPC comes into play.

MPC is a vein of cryptography focused on creating tools that let multiple individuals compute a function that requires inputs from each — in a way that does not require participants to reveal their inputs to the others. 

In practice, it gives crypto holders a way to sign off on transactions in a distributed way such that, in theory, a hacker cannot obtain their private keys — even if they somehow got access to their computers.

This offers an alternative to multi-signature (commonly called “multisig”) schemes, which require multiple key-holders to sign off on transactions. 

Why is an alternative needed? Because different protocols have different multi-signature mechanisms.

“You don’t want to change your security infrastructure for every blockchain you have,” Malinger says.

MPC clearly now the keys have gone

Now Malinger just has to explain how the technology works — and why it’s better than conventional crypto wallets. It is only recently, he admits, that even the most expert industry technicians have begun to fully grasp the underlying concepts.

“If I were to have this conversation with even the more advanced people – and I did have those conversations with very well-known exchanges three years ago – they would tell me that what I’m saying is impossible,” he says, adding:

“Luckily, I think that over the past two years, MPC has become mainstream in the sense that the majority of the technical buyers understand the concept and believe in the cryptography behind it. This was not the case literally three years ago.”

The key point he is trying to elucidate is that existing forms of crypto security are built to secure private keys; MPC is more secure, he says, because it does away with them.

“In an MPC world, there is no private key. There are secrets that are distributed between various parties and it is never assembled at any point in time,” he says. “MPC enables us to sign the transaction without bringing those pieces together. This is the breakthrough.”

Thankfully, Malinger has come up with some examples to help listeners conceptualize what the hell he’s talking about.

He asks me to imagine that the two of us want to sign a transaction using MPC, and that my key is the number five, and that his key is the number forty-five, the combination of which is fifty. 

I’m with him so far. But now things get trickier.

“We are able to sign a transaction that would be corresponding to fifty, without calculating fifty. So you never tell me that you had five, I never tell you that I had forty-five, and there’s no place in the world, not even for a second, in which the five and the forty-five are kept together so that they can be derived as the number fifty, and yet we are able to sign as if that fifty was assembled,” he says excitedly.

Never in an interview has anyone spoken at such length about adding five and forty-five to make fifty.

But this is all still rather abstract. Surely, I ask, there has to be some party that knows the combination of these codes is the correct one? Another example beckons.

I am now asked to imagine I want to send three bitcoins to Bob. I take these instructions and my key (still five), run some calculations and send Malinger the result, but this does not reveal that my key is five. He goes through the same process with his key (forty-five) in response.

“This will go back and forth, back and forth between the two of us for a few times. Six times, ballpark. At the end of the process, we both will have a signed transaction of three bitcoins to bob, but we never learned each other’s secret,” he says.

“What we have achieved is the ability to have the private key separate — distributed between several parties — and only if there is complete consensus between the parties as to what is the destination, what is the amount, then and only then we will be able to sign only that transaction that there was a consensus about.”

Still, no matter how technically impressive that may be, the last three years have been an “uphill battle” when it comes to persuading prospective customers that MPC is the right approach for securing their digital assets, says Malinger. 

That may be starting to change. Hard though it may be to grasp, customers across the financial spectrum are now using Curv’s technology.

Its client roster includes crypto firms (like Mexican exchange BitSo), incumbent financial institutions (including French bank BNP Paribas and Franklin Templeton, the asset manager) and fintechs (such as investment platform eToro and German digital bank Solarisbank).

Malinger won’t be drawn into commenting on Curv’s competitors in the MPC arena — which include Fireblocks and Unbound Tech, among others — other than to say that each has a distinctive focus. 

“Most of our customers are programmatic buyers that need to build an infrastructure that would be software-defined and software-controlled,” he says. This time, however, he did not offer an analogy to explain what that means.


© 2026 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.