OKX Banner
BTC $77,210.00 (-1.43%)
ETH $2,403.56 (-2.00%)
BNB $687.67 (-0.10%)
XRP $1.34 (-2.97%)
SOL $99.39 (-3.04%)
TRX $0.33 (-0.17%)
HYPE $81.59 (-3.28%)
ZEC $812.22 (-5.79%)
DOGE $0.08 (-1.49%)
RAIN $0.02 (+1.37%)
XMR $510.39 (-0.25%)
LEO $9.25 (-1.20%)
LINK $11.15 (-2.76%)
ADA $0.20 (-1.73%)
XLM $0.17 (-2.64%)
BCH $244.46 (-1.82%)
CC $0.11 (-6.27%)
LTC $49.29 (-1.01%)
GRAM $1.33 (-2.16%)
UNI $5.86 (+2.57%)

AEREDIUM's New Tool Replaces Single-Key Control on Smart Contracts

Share on X icon · Published 1 hour ago on September 2, 2026 · Nikolas Sargeant

AEREDIUM launches AERSeal, using threshold signing and multi-party approval policies to replace single-key control of EVM smart contracts.

AEREDIUM's New Tool Replaces Single-Key Control on Smart Contracts

AEREDIUM has introduced AERSeal, a smart contract security product designed to eliminate the risks created when privileged administrative functions depend on a single private key.

In a press release shared with Cryptowisser, AEREDIUM stated that AERSeal is the company’s first complete product built using AERKey, its threshold-key infrastructure. It replaces single-key control with an approval-based system involving multiple authorized signatories.

The product supports smart contracts on EVM and EVM-compatible blockchain networks without requiring the underlying contracts to be moved.

AERSeal Targets Single-Key Security Risks

Smart contracts can include administrative permissions that allow authorized operators to mint assets, implement upgrades, and execute other sensitive functions.

When a single private key controls these permissions, that key becomes a critical point of failure. Losing it can permanently remove access to the contract’s administrative features, while theft or compromise could allow an attacker to take control.

AERSeal addresses this risk by transferring privileged contract powers to a threshold key controlled through a distributed signing process.

AERSeal divides the threshold key into multiple shares and stores them separately inside hardware-attested enclaves.

The system does not reconstruct the shares into a complete private key in a single location. Instead, the distributed components work together to generate signatures using the CGGMP24 threshold-signing protocol.

This structure is intended to prevent any individual, device or exposed private key from independently controlling a smart contract’s privileged functions.

Organizations Can Set M-of-N Approval Policies

AERSeal allows customers to determine who can authorize sensitive contract actions and how many approvals are required.

Organizations establish an M-of-N policy, under which a specified number of authorized participants must approve an action before it can proceed. For example, a company could require three approvals from a group of five eligible signatories.

After custody is activated, privileged actions such as contract upgrades or asset minting must follow the predefined process.

Authorized signatories approve requests with their passkeys. Once the required approval threshold is reached, the distributed key cluster generates the necessary signature.

Before activating custody, AERSeal identifies the privileged permissions attached to a customer’s smart contract.

The organization must then transfer those permissions to the threshold key. AERSeal verifies the transaction onchain to confirm that all relevant powers have been transferred successfully.

This process is designed to ensure the previous administrator key no longer retains control over protected functions.

Customers Can Independently Verify Threshold Keys

AERSeal also provides customers with tools to verify the threshold key assigned to their organization.

Using address derivation and a newly signed challenge, customers can confirm both the derivation and possession of the key. The verification can be performed independently, including offline, rather than requiring customers to rely solely on AEREDIUM’s assurances.

According to the company, this approach provides cryptographic evidence that the correct threshold key has been assigned and is operational.

The AERSeal onboarding process consists of several stages:

  • Know Your Customer checks for individuals or Know Your Business checks for organizations

  • Smart contract registration

  • Independent cryptographic key verification

  • Transfer of privileged contract permissions

  • Onchain confirmation of the transfer

  • Activation of the customer’s approval policy

The process combines identity verification, technical configuration, and blockchain-based confirmation before threshold custody becomes active.

AEREDIUM Introduces First End-to-End AERKey Product

“AERSeal is the first complete product to put AERKey into operation from end to end,” said AEREDIUM founder and CEO Albert Dadon.

Dadon said the product aims to eliminate the idea that control over an entire smart contract should depend on one private key. He added that threshold signing and defined approval policies allow organizations to distribute and independently verify control.

AERSeal forms part of AEREDIUM’s AER360 product family. Aeredium Network LLC provides the service using AERKey infrastructure developed by AEREDIUM.

AEREDIUM Holdings Inc. builds The Trust Layer: blockchain infrastructure for institutional settlement in which correctness is enforced by hardware, cryptography and autonomous oversight rather than promised by intermediaries. AEREDIUM operates from Melbourne, Tel Aviv and Austin, Texas.

 

KuCoin Web3 Wallet Adds Limit Orders and Intent-Based Trading
Next article KuCoin Web3 Wallet Adds Limit Orders and Intent-Based Trading
Nikolas Sargeant
Nikolas Sargeant Editor-in-Chief

Nik is a content and public relations specialist with an ever-growing interest in Crypto. He has been published on several leading Crypto and blockchain based news sites. He is currently based in Spain, but hails from the Pacific Northwest in the US.