Who Fireblocks is
Fireblocks is a digital asset infrastructure company founded in 2018 and headquartered in New York. Its wallets protect keys with multi-party computation (MPC), and a policy engine checks every transaction before it is signed. Around the wallets sit the Fireblocks Network for transfers between counterparties, tokenisation, payments and staking.
Exchanges, fintechs, payment providers, banks and trading firms run their wallets on it, and in the US, Fireblocks Trust Company is a limited purpose trust company chartered by the New York State Department of Financial Services. Policy control built into the wallets is why Fireblocks is one of the custody providers our module connects to.
What it does in your platform
Custody & wallets
Holds the keys for your hot, warm and cold wallets in Fireblocks vault accounts, and gives each customer a deposit address on every chain you support. A withdrawal reaches Fireblocks only after the module's limits, screening and approvals, then passes the policy you set in Fireblocks before it is signed.
How the connection works
One connector in the Custody & wallets module talks to the Fireblocks API, signing every request with your API private key. Fireblocks reports back through signed webhooks.
An address per customer
The module asks Fireblocks for a deposit address on the chain the customer picks, and your app shows it.
Fireblocks sees the deposit
When a transfer reaches the address, Fireblocks sends a signed webhook, then another each time its status or its number of confirmations changes.
Screened and credited
Once Fireblocks marks the transfer completed, the module screens it and credits the customer, and the movement appears in the backoffice.
A withdrawal request
A customer asks to withdraw. The module applies your limits, screening and approvals, then creates the transaction in Fireblocks.
Policy, then signature
Fireblocks checks the transaction against your Transaction Authorization Policy before the key shares sign it. For a hot wallet, an API co-signer you deploy approves and signs automatically.
Broadcast and reconciled
Fireblocks broadcasts the transaction, its webhooks follow it to completion, and the module reconciles the movement with the chain.
Next to other providers
Fireblocks holds the keys; the module holds the rules. Limits, screening, approvals and reconciliation work the same whether the keys sit with Fireblocks, another custody provider or your own MPC or HSM setup, and balances are checked against the chain itself.
Moving away from Fireblocks later means moving the funds and issuing new deposit addresses, not rebuilding your apps. We add a connector if we do not have one for the new provider yet.
When Fireblocks fits best
A strong fit when
- You want MPC wallets for your hot, warm and cold tiers, run by a provider rather than your own team.
- You move enough deposits and withdrawals to want signing automated under a policy engine.
- You settle with exchanges and counterparties that already use the Fireblocks Network.
Also worth a look
- Another custody provider from the same group, such as BitGo, Copper or Cobo, if your counterparties or your regulator point to one.
- Your own MPC cluster or HSMs, when the keys must stay in your infrastructure.
How we get you live
The contract
We help you get your Fireblocks account and contract in place, with the workspace set up for the chains and assets you support.
The policy
We set up the Transaction Authorization Policy with you, so it matches the module's limits and approvals, and deploy the API co-signer for your hot wallet.
The keys
The API key and its private key go into your platform's secrets and nowhere else. Every webhook is checked against Fireblocks' signing key before the module acts on it.
A full test run
The whole flow runs in a Fireblocks testnet workspace with test assets, from a deposit address to a reconciled withdrawal, before real funds move.
