Skip to main content

Security at Coinbox

Security without compromise, from your account to your crypto.

All Coinbox client crypto is held using Fireblocks through Coinbox's institutional custody infrastructure. MPC-CMP, two-factor authentication and stronger checks for sensitive actions create end-to-end protection.

  • Fireblocks
  • MPC-CMP
  • Two-factor authentication
  • Israeli licence 71398

Fireblocks by the numbers

Experience measured in trillions of dollars.

As of 2026, Fireblocks serves more than 2,400 organisations and 100 banks worldwide and has secured over $14 trillion in digital-asset transactions.

Source: Fireblocks, 2026

in secured digital-asset transactions
$14T+
organisations worldwide
2,400+
banks
100+
wallets created
550M+

MPC technology

No complete private key in one place.

With MPC, signing is produced through several encrypted shares. The shares are never assembled into a complete private key, removing the need to keep one full key in a single location.

The same technology. An institutional standard.

Infrastructure used by financial institutions and banks worldwide.

The crypto in your account is held using the same technology that serves more than 100 banks and thousands of financial organisations worldwide.

  • Encrypted share A
  • Encrypted share B
  • Encrypted share C
  • Action verification
MPC approval

The signature is protected at every stage

Institutional adoption

Security chosen by some of the world's largest financial institutions.

As of 2026, more than 100 banks use Fireblocks. These names show the scale at which the technology protects financial activity every day.

  • BNYOne of the world's largest custodians, with $62.6 trillion in assets under custody and/or administration.
  • Banking CircleA global payments bank serving more than 900 financial institutions and processing over €1.5 trillion a year.
  • RevolutOne of the world's largest digital banks, with more than 80 million customers.

Institution figures are current for 2026 and based on their official sources

MPC-CMP technology

Signing power is distributed. A complete private key is never stored in one place.

Instead of storing a complete private key, MPC-CMP splits signing power across separate cryptographic shares. The shares remain separate and create a signature together without exposing or reconstructing a complete key.

Separate key shares

MPC-CMP signature

A complete private key is never stored in one place

  • No single key location

    No single file, device or location holds a complete private key on its own.

  • Open to scrutiny

    Fireblocks published MPC-CMP for review by cryptographers, researchers and independent auditors.

  • Signing without exposing a complete key

    The key shares participate in the cryptographic signature without joining into or exposing a complete private key.

  • Hardware-backed isolation

    Protocol implementations support hardware-isolated environments including Intel SGX and AWS Nitro Enclaves.

Account protection

Access is protected. Sensitive actions are protected even further.

Coinbox security continues after sign-in. Two-factor authentication, security alerts and stronger checks for address management and withdrawals protect the actions where confirming your identity matters most.

  • Password and two-factor authentication

    Built-in password rules and 2FA through an authenticator app or SMS strengthen sign-in protection.

  • Extra checks for sensitive actions

    Address management and crypto withdrawals require an additional authentication layer before execution.

  • Security alerts

    Sensitive changes and events trigger alerts, keeping you informed about activity in your account.

  • Account lock and recovery

    When needed, access can be locked and an orderly recovery process started through the Coinbox team.

Externally examined controls

Independent standards and round-the-clock monitoring.

The Fireblocks security programme is examined through third-party standards and audits and supported by a global security operations centre running 24/7.

  • SOC 2 Type II

    The SOC 2 Type II examination was completed with zero material findings.

  • Four ISO standards

    ISO 27001, 27017, 27018 and 22301 cover information security, cloud, privacy and business continuity.

  • CCSS Level 3

    Fireblocks was the first platform to achieve C4 CCSS Qualified Service Provider Level 3.

  • 24/7 security operations

    Analysts across the US, EMEA and APAC monitor systems around the clock.

Proof from the source

Every figure is open for review.

We collected the official Fireblocks and institution sources so you can review the full data for yourself.

Protection in layers

From custody to each account action.

Security is not a single feature. It combines custody infrastructure, identity, permissions, authentication and activity records.

  • Fireblocks custody with MPC

    All crypto is held using Fireblocks with distributed MPC-based signing.

  • Password and two-factor authentication

    Built-in password requirements and 2FA through an authenticator app or SMS.

  • Stronger checks for sensitive actions

    Address management and crypto withdrawals require an additional authentication layer.

  • Alerts, records and account lock

    Security events are recorded, sensitive changes trigger alerts, and lock and recovery processes are available.

A sensitive account action

Sensitive actions receive an extra layer of protection.

When you add an address or withdraw crypto, the account asks for stronger authentication and shows the action details before approval.

  1. Protected sign-in

  2. Two-factor authentication

  3. Additional action check

  4. Approval and instant status

A clear holding structure

Separation, custody and orderly records.

Protection at Coinbox starts with how client assets are held and recorded, and continues through the infrastructure used for crypto actions.

  • Client money

    Client money is held in dedicated client accounts at Israeli banks, separate from company assets.

  • Digital assets

    All client crypto is held using Fireblocks through Coinbox's institutional custody infrastructure, separate from company crypto.

  • Israeli licence

    Coinbox operates under extended financial asset service licence No. 71398, issued by the Capital Market, Insurance and Savings Authority.

Security tools in your account

Recommendations that work with the controls already available in Coinbox.

Your account includes straightforward tools for strengthening access and sensitive actions.

  • Choose a unique password

    Coinbox displays the password requirements as you set it up.

  • Enable 2FA

    Choose an authenticator app or SMS in your profile security settings.

  • Check the address before withdrawing

    The confirmation screen and stronger authentication let you review the action details.

  • Contact us about unfamiliar activity

    Access can be locked and recovery started through Coinbox support.

Straight from Coinbox

How Coinbox protects your crypto and account

All Coinbox customers' crypto is held through Fireblocks in the Coinbox institutional custody infrastructure, separately from the company's crypto. As of 2026, Fireblocks' MPC-CMP technology is used by more than 100 banks and 2,400 organisations worldwide.

Updated 29 August 2026

MPC with no single key

The signing components are created, stored and operated separately. The full private key never exists in one place, so no single point controls the asset on its own.

Two-factor authentication

You can turn on 2FA with an authenticator app or SMS. Sensitive actions such as managing addresses and withdrawing crypto require stronger authentication.

Account controls and alerts

Password rules, security activity alerts, event logging, account lock and a recovery path give you clear tools to manage access to your account.

Institutional scale

As of 2026, Fireblocks has secured more than 14 trillion dollars in digital asset transactions, and more than 550 million wallets have been created on its infrastructure.

Protection for sensitive actions

Managing addresses and withdrawing crypto require stronger authentication before they go through. Changes and security events also trigger account alerts.

Frequently asked questions

Where is Coinbox customers' crypto held?

All Coinbox customers' crypto is held through Fireblocks in the Coinbox institutional custody infrastructure, separately from the company's crypto.

What is MPC technology?

MPC is a cryptographic method that splits the ability to sign across several separate components. A transaction is signed through a joint computation, without ever assembling a full private key in one place.

What is Fireblocks' MPC-CMP?

MPC-CMP is the signing protocol developed by Fireblocks. The components of the key are stored separately and together produce a signature without exposing or reconstructing a full private key. The protocol is open to review by independent cryptographers, researchers and auditors.

What is the advantage of MPC for holding crypto?

MPC removes the dependence on one full private key, supports separation of duties and allows approval and permission processes suited to institutional activity.

Who uses Fireblocks?

As of 2026, more than 100 banks and 2,400 organisations use the Fireblocks infrastructure, including BNY, Banking Circle and Revolut. BNY alone oversees 62.6 trillion dollars in assets under custody and administration.

How much activity runs on the Fireblocks infrastructure?

As of 2026, Fireblocks has secured more than 14 trillion dollars in digital asset transactions across more than 150 blockchains, and more than 550 million wallets have been created on its infrastructure.

Which security standards does Fireblocks report?

In its security report, Fireblocks lists SOC 2 Type II with no material findings, ISO 27001, ISO 27017, ISO 27018 and ISO 22301, and C4 CCSS Qualified Service Provider certification at level 3.

Is the Fireblocks security operation monitored around the clock?

Yes. Fireblocks states that its security operations centre runs 24/7 with analysts in the United States, in Europe, the Middle East and Africa, and in Asia-Pacific.

Can I turn on two-factor authentication at Coinbox?

Yes. You can turn on two-factor authentication from your profile page, using an authenticator app or SMS.

How does Coinbox help me choose a strong password?

During sign-up, Coinbox shows and checks the password requirements, including the length and the mix of characters the account needs.

Which controls run before a crypto withdrawal?

Managing addresses and withdrawing crypto require a verified login and two-factor authentication. The address, asset, network and action are checked within the guided process.

Do I get alerts about changes to my account security?

Yes. Coinbox logs security activity and sends alerts about sensitive events, such as adding an authentication factor or a new withdrawal destination.

Are customer assets separated from company assets?

Yes. Customer funds are held in dedicated customer accounts at banks in Israel, and all customers' crypto is held through Fireblocks, separately from the company's crypto. Each customer's entitlements are recorded in the Coinbox systems.

How does the licence fit into the Coinbox setup?

Coinbox operates under extended financial asset service licence no. 71398. The licence details and the signed document are available on the licence page of the website.

Advanced security in an account that is easy to use.

Open a Coinbox account with Fireblocks custody, MPC technology and built-in security controls.