Wallet infrastructure
Lit Protocol vs Privy
See who controls your wallet’s permissions.
Compare who can change a wallet’s permissions and who can replace the software that enforces them.
Scope: Lit Chipotle in ChainSecured mode and Privy’s TEE wallet infrastructure.
Operator authority
Three questions about operator authority.
| Control | Lit · ChainSecured | Privy |
|---|---|---|
| Who can change the permissions? | Your account wallet approves permission changes on Base. A usage API key can run authorized Actions but cannot change those permissions.[6][1] | Owners and authorization-key quorums control wallet actions through Privy’s API. Those rules are enforced by its enclave; they are not customer permissions recorded in Lit’s public contract system.[4] |
| Who can approve replacement code? | The approvers authorized by the governance contracts can approve runtime releases. The key-management system checks on-chain approval and hardware attestation before releasing keys. Deploying new code is not enough.[7][8] | Privy documents multiple reviewers, protected builds, hardware keys, and staged deployments. These constrain release operators; the cited architecture does not establish a public, on-chain runtime approval gate.[3] |
| Who can stop access? | The API operator or runtime host can interrupt normal signing. On-chain permissions remain inspectable, but execution still needs the runtime and key-management system. Recovery requires a separate plan.[9][7] | Wallet actions, including normal key export, go through Privy’s authorization and enclave path. Evaluate the actual recovery setup separately from the wallet’s ownership label.[4] |
Who can change the permissions?
- Lit · ChainSecured
- Your account wallet approves permission changes on Base. A usage API key can run authorized Actions but cannot change those permissions.[6][1]
- Privy
- Owners and authorization-key quorums control wallet actions through Privy’s API. Those rules are enforced by its enclave; they are not customer permissions recorded in Lit’s public contract system.[4]
Who can approve replacement code?
- Lit · ChainSecured
- The approvers authorized by the governance contracts can approve runtime releases. The key-management system checks on-chain approval and hardware attestation before releasing keys. Deploying new code is not enough.[7][8]
- Privy
- Privy documents multiple reviewers, protected builds, hardware keys, and staged deployments. These constrain release operators; the cited architecture does not establish a public, on-chain runtime approval gate.[3]
Who can stop access?
- Lit · ChainSecured
- The API operator or runtime host can interrupt normal signing. On-chain permissions remain inspectable, but execution still needs the runtime and key-management system. Recovery requires a separate plan.[9][7]
- Privy
- Wallet actions, including normal key export, go through Privy’s authorization and enclave path. Evaluate the actual recovery setup separately from the wallet’s ownership label.[4]
The Lit advantage
Your on-chain rules govern signing
Lit records account permissions and authorized code on-chain. Users and applications can check the same rules directly, without relying on the wallet provider’s API.[1][2]
How ChainSecured worksWhat custody means in practice
A user-held authorization key is meaningful control. The next question is who can change the system that recognizes it. Lit makes account permissions and runtime approvals visible on-chain, while keeping their separate upgrade authorities explicit.[4][10]
Shared protections
Both protect key operations inside confidential hardware. Privy also verifies authorization signatures and enforces wallet policies in its enclave.[3][4][5]
Sources and review scope
These comparisons use published documentation and the source code linked below. We have not audited or tested the providers’ live systems. Configurations vary, and source code alone does not establish who currently owns a deployed contract or how it is configured.
- Lit: Chain Secured
- Lit: Groups and action permissions
- Privy: Security architecture
- Privy: Wallet policies and controls
- Lit: What is attestation?
- Chipotle: account mutation authorization (reviewed source)
- Lit: On-Chain KMS
- Lit: Upgrade governance
- Lit: Architecture
- Lit: verification and contract administration
- Chipotle: contract owner upgrade authority (reviewed source)