Offline & Online Accounts Pairing
Overview
In Blockdaemon Institutional Vault, the cold wallet is an offline signing layer: MPC key material stays split across two air-gapped cold nodes (often in separate secure rooms). The hot (online) wallet is where you create activity, run policy, and prepare transactions; cold nodes only co-sign batches brought to them, so full signing keys are not held on internet-connected systems. Pairing is the one-time ceremony that binds hot infrastructure to those cold nodes, without it, cold-backed accounts and cold signing cannot operate. This guide covers pairing only; hot and cold use separate Vault accounts.
π
Note:
Remember that Hot wallet and Cold wallet are separate entities.
Pairing the Hot & Cold Wallet
Air-gapped cold nodes
Online (hot) wallet infrastructure
1a. Download Hot pairing message
1b. Download Hot pairing message
2a. Upload Hot pairing
2b. Upload Hot pairing
3. Two-node MPC over broker: pairing + initial presignature pool
4a. Export Cold pairing
4b. Export Cold pairing
5a. Upload Cold pairing
5b. Upload Cold pairing
6. Persist cold pairing & master key
Wallet Service
MPC Policy node(s)
MPC Cold Node 1 (Secure Room 1)
MPC Cold Node 2 (Secure Room 2)
π§βπΌ Cold Operator 1
π§βπΌ Cold Operator 2
Cold pairing process
The diagram is the one-time setup: it establishes trust and exchanges pairing key material between the online Wallet Service / Policy nodes and two air-gapped MPC cold nodes. Full cold signing keys never leave the cold environment.
What the diagram shows
- Steps 1β2 β Hot β cold: The Wallet Service exposes a Hot pairing message (including the hot sideβs approval public key). Each operator carries it into their secure room and uploads it to their node ( 1a/1b β 2a/2b) so each cold node knows which hot deployment it is bound to.
- Step 3 β Cold β cold (MPC): Both nodes coordinate over an on-premises broker (still isolated from the public internetβtypically a local network or other controlled link). They run two-party MPC: distributed key shares, cold extended public key material, and an initial presignature pool. Neither node ever holds the complete private key alone.
- Steps 4β5 β Cold β hot: Each node outputs a Cold pairing message; operators bring both files online and upload them to the Wallet Service ( 4a/4b β 5a/5b) so the hot side can derive deposit addresses and verify future cold partial signatures.
- Step 6 β Finalize: The Wallet Service and Policy nodes persist the cold pairing and cold master key attachment, completing custody wiring for later cold batch signing.
Step-by-step pairing (Vault UI)
To integrate the Hot and Cold wallet, follow the steps below:
Navigate to your Hot wallet, and log in.
Click Settings.
Click the Wallet Pairing tab.
Click the Download Hot Pairing Message button, and you'll receive a prompt to download the pairing message file. This file initiates and authenticates the connection with the Cold wallet.
Navigate to the Cold wallet.
π
Note:
Ensure that you have accessed the Cold wallet from an air-gapped computer/device.
Click Settings.
Under the Wallet Information tab, click the Upload pairing message button.
Select your downloaded pairing message file from your Hot Wallet and click Upload.
Navigate back to the Wallet Pairing tab under Settings on your Hot wallet. Click the Upload pairing message button.
Upload the file you downloaded from the Cold wallet. This action will automatically populate the extended public key and master key fields, ensuring a secure Hot and Cold wallet integration.
Once paired, you can create new accounts. Click Accounts.
Click the New Account button.
Fill in the account name, enable the Cold Account to enable the cold storage feature, and click Create.
A notification window will appear, confirming the successful pairing of keys between the Hot and Cold wallet.
π
Note:
Keep in mind that the security architecture involves both the parent keys and a multi-layered security system structure. As a result, even if the parent keys are compromised, the overall security of the system remains resilient and intact.