MPC with no single key
The signing components are created, stored and operated separately. The full private key never exists in one place, so no single point controls the asset on its own.
Security at Coinbox
All Coinbox client crypto is held using Fireblocks through Coinbox's institutional custody infrastructure. MPC-CMP, two-factor authentication and stronger checks for sensitive actions create end-to-end protection.
Fireblocks by the numbers
As of 2026, Fireblocks serves more than 2,400 organisations and 100 banks worldwide and has secured over $14 trillion in digital-asset transactions.
Source: Fireblocks, 2026
MPC technology
With MPC, signing is produced through several encrypted shares. The shares are never assembled into a complete private key, removing the need to keep one full key in a single location.
The same technology. An institutional standard.
The crypto in your account is held using the same technology that serves more than 100 banks and thousands of financial organisations worldwide.
The signature is protected at every stage
Institutional adoption
As of 2026, more than 100 banks use Fireblocks. These names show the scale at which the technology protects financial activity every day.
Institution figures are current for 2026 and based on their official sources
MPC-CMP technology
Instead of storing a complete private key, MPC-CMP splits signing power across separate cryptographic shares. The shares remain separate and create a signature together without exposing or reconstructing a complete key.
Account protection
Coinbox security continues after sign-in. Two-factor authentication, security alerts and stronger checks for address management and withdrawals protect the actions where confirming your identity matters most.
Externally examined controls
The Fireblocks security programme is examined through third-party standards and audits and supported by a global security operations centre running 24/7.
The SOC 2 Type II examination was completed with zero material findings.
ISO 27001, 27017, 27018 and 22301 cover information security, cloud, privacy and business continuity.
Fireblocks was the first platform to achieve C4 CCSS Qualified Service Provider Level 3.
Analysts across the US, EMEA and APAC monitor systems around the clock.
Proof from the source
We collected the official Fireblocks and institution sources so you can review the full data for yourself.
Protection in layers
Security is not a single feature. It combines custody infrastructure, identity, permissions, authentication and activity records.
All crypto is held using Fireblocks with distributed MPC-based signing.
Built-in password requirements and 2FA through an authenticator app or SMS.
Address management and crypto withdrawals require an additional authentication layer.
Security events are recorded, sensitive changes trigger alerts, and lock and recovery processes are available.
A sensitive account action
When you add an address or withdraw crypto, the account asks for stronger authentication and shows the action details before approval.
A clear holding structure
Protection at Coinbox starts with how client assets are held and recorded, and continues through the infrastructure used for crypto actions.
Client money is held in dedicated client accounts at Israeli banks, separate from company assets.
All client crypto is held using Fireblocks through Coinbox's institutional custody infrastructure, separate from company crypto.
Coinbox operates under extended financial asset service licence No. 71398, issued by the Capital Market, Insurance and Savings Authority.
Security tools in your account
Your account includes straightforward tools for strengthening access and sensitive actions.
Coinbox displays the password requirements as you set it up.
Choose an authenticator app or SMS in your profile security settings.
The confirmation screen and stronger authentication let you review the action details.
Access can be locked and recovery started through Coinbox support.
Straight from Coinbox
All Coinbox customers' crypto is held through Fireblocks in the Coinbox institutional custody infrastructure, separately from the company's crypto. As of 2026, Fireblocks' MPC-CMP technology is used by more than 100 banks and 2,400 organisations worldwide.
Updated 29 August 2026
The signing components are created, stored and operated separately. The full private key never exists in one place, so no single point controls the asset on its own.
You can turn on 2FA with an authenticator app or SMS. Sensitive actions such as managing addresses and withdrawing crypto require stronger authentication.
Password rules, security activity alerts, event logging, account lock and a recovery path give you clear tools to manage access to your account.
As of 2026, Fireblocks has secured more than 14 trillion dollars in digital asset transactions, and more than 550 million wallets have been created on its infrastructure.
Managing addresses and withdrawing crypto require stronger authentication before they go through. Changes and security events also trigger account alerts.
All Coinbox customers' crypto is held through Fireblocks in the Coinbox institutional custody infrastructure, separately from the company's crypto.
MPC is a cryptographic method that splits the ability to sign across several separate components. A transaction is signed through a joint computation, without ever assembling a full private key in one place.
MPC-CMP is the signing protocol developed by Fireblocks. The components of the key are stored separately and together produce a signature without exposing or reconstructing a full private key. The protocol is open to review by independent cryptographers, researchers and auditors.
MPC removes the dependence on one full private key, supports separation of duties and allows approval and permission processes suited to institutional activity.
As of 2026, more than 100 banks and 2,400 organisations use the Fireblocks infrastructure, including BNY, Banking Circle and Revolut. BNY alone oversees 62.6 trillion dollars in assets under custody and administration.
As of 2026, Fireblocks has secured more than 14 trillion dollars in digital asset transactions across more than 150 blockchains, and more than 550 million wallets have been created on its infrastructure.
In its security report, Fireblocks lists SOC 2 Type II with no material findings, ISO 27001, ISO 27017, ISO 27018 and ISO 22301, and C4 CCSS Qualified Service Provider certification at level 3.
Yes. Fireblocks states that its security operations centre runs 24/7 with analysts in the United States, in Europe, the Middle East and Africa, and in Asia-Pacific.
Yes. You can turn on two-factor authentication from your profile page, using an authenticator app or SMS.
During sign-up, Coinbox shows and checks the password requirements, including the length and the mix of characters the account needs.
Managing addresses and withdrawing crypto require a verified login and two-factor authentication. The address, asset, network and action are checked within the guided process.
Yes. Coinbox logs security activity and sends alerts about sensitive events, such as adding an authentication factor or a new withdrawal destination.
Yes. Customer funds are held in dedicated customer accounts at banks in Israel, and all customers' crypto is held through Fireblocks, separately from the company's crypto. Each customer's entitlements are recorded in the Coinbox systems.
Coinbox operates under extended financial asset service licence no. 71398. The licence details and the signed document are available on the licence page of the website.
Open a Coinbox account with Fireblocks custody, MPC technology and built-in security controls.