How a leading trading firm achieved 25x faster transaction signing and moved their latency-sensitive DeFi strategies into production

From 600 ms to 24 ms on decentralized exchanges without giving up institutional-grade key security

24 ms p50

Signing Latency

99.999%

system uptime

500 million

signing operations per month

"Our MPC signing infrastructure was adding more than 600 ms of latency per transaction, which meant several of our most promising DeFi strategies weren't viable. Cubist gave us the performance we needed to deploy them without compromising our security model."

CISO · Leading Trading Firm
In this article
Company Name
Tier-1 Trading Firm
Industry
Financial Services
Pain Point
Signing latency for DeFi trading
Products Used
CubeSigner On-Premise, C2F
About the Company
High frequency trading firm operating market making, arbitrage, and other latency-sensitive DeFi strategies

The Problem

When infrastructure becomes 
a business decision

Firms trading on decentralized exchanges (DEXes) have two contradictory requirements: wallets holding millions of dollars must be protected to institutional standards, and trading strategies must execute within milliseconds to keep up with markets. Historically, firms have had to compromise on one to achieve the other. One of DeFi's highest-volume algorithmic trading firms was unwilling to make that tradeoff. This case study examines how they used an on-premise deployment of the Cubist platform to hit their latency targets and move profitable new strategies into production without compromising on security.

The firm had already invested heavily in a key management system based on multi-party computation (MPC). Their MPC provider met the firm's security requirements and was trusted in production.

But security alone wasn't the problem; security at speed was.

The MPC provider’s signing latency regularly exceeded 600 ms per request, which made latency-sensitive trading strategies impossible to implement or put them at a severe competitive disadvantage and, as a result, left millions of dollars on the table. While 600 ms is perfectly acceptable for manual custody workflows, it is far too slow for DEX trading, which has unique challenges compared to trading on centralized exchanges because the trading wallet must generate a unique cryptographic signature for every transaction. On DEXes, signing is on the critical path between identifying an opportunity and finalizing a transaction on-chain, and one of the few latency components traders directly control. Not only can the added latency destroy profitability (e.g., prices move, arbitrageurs react, liquidity disappears, priority lost in the mempool, etc.), but it renders some strategies infeasible.

Some of the firm's most promising trading strategies required sub-100 ms end-to-end execution, but their MPC provider was consuming several times that budget on its own. This is a fundamental limitation of MPC technology: generating a signature requires several network round trips between parties holding key shares, introducing latency that is difficult to eliminate.

The common alternative, hot wallets, can achieve extremely low latency because signing happens directly within the application infrastructure, by, for example, storing keys in memory. Hot wallets may be acceptable for smaller balances or less sophisticated operations, but for a firm managing significant capital and running automated strategies around the clock, they concentrate too much risk in systems that are exposed to the Internet and routinely process untrusted inputs. Managing hot wallets is a security operations nightmare because every person or system with access to a private key becomes a potential vector for catastrophic asset loss, and continuously managing, auditing, and enforcing that access is difficult and error-prone. Hot wallets were not an option for this firm; they take security seriously—e.g., we can't even disclose who they are since this would be disclosing details of their internal systems.

What had initially been a security-focused decision was now impacting the firm's ability to execute novel trading strategies. They had effectively been forced to choose between the security model they needed and the latency their strategies required. No vendor they’d previously evaluated could give them both.

“We knew where the opportunities were, but our signing infrastructure prevented us from acting on them. We weren't looking for a marginal latency improvement. We were looking for a way to unlock entire classes of new trading opportunities.”


Head of Trading · Leading Trading Firm

The Solution

Why they chose Cubist

The firm deployed Cubist's CubeSigner and Confidential Cloud Functions (C2F) within their own cloud environment, co-locating the custody infrastructure within the same environment and geographic region as their trading systems. CubeSigner's latency is already lower than any other product on the market, but deploying within the same virtual private cloud setup further eliminates the network latency associated with traditional custody platforms, where requests must round-trip across the public Internet before a transaction can be submitted on-chain.

The firm also needed to preserve strict controls over the types of transactions that traders and automated systems can sign—restricting the protocols, tokens, volume, withdrawal addresses, etc.—and under which conditions. Every signing request passes through CubeSigner's policy engine at the time of signing, where both built-in and custom controls are enforced before a signature is generated.

Using C2F, the firm authored policies that incorporate real-time market data, allowing trading activity to be automatically enabled, restricted, or conditioned based on market prices. Governance policies separately control how signing policies can be changed and by whom. Today, no single user has unilateral control over anything.

This architecture combines the performance benefits of local wallet infrastructure with the security guarantees of hardware-backed key protection. CubeSigner signing keys are generated and accessed exclusively in AWS Nitro Enclaves, never leave the hardware boundary, and are anchored to a FIPS 140-3 Hardware Security Module root of trust. Every signing operation executes within an isolated environment, ensuring that raw key material remains inaccessible even to privileged users and the surrounding cloud infrastructure. Built-in disaster recovery and key recovery mechanisms ensure operational continuity even in catastrophic, whole region failures.

As a result of deploying CubeSigner, the firm's new trading strategies are able to operate at scale without relying on unrestricted hot wallet access or bypassing the controls that govern how capital is deployed. Since every policy decision is cryptographically attested, the firm can also prove to regulators that every trade was evaluated against their risk controls, producing a real-time, tamper-proof record of governance.

Beyond single-venue execution, Cubist is building a cross-venue rebalancer to help firms like this optimize capital allocation across CEX and DEX liquidity in real time.

The Results

Industry-leading performance

After deploying CubeSigner, the firm’s signing latency dropped from over 600 ms to a measured p50 of 24 ms (p90 28 ms, p95 32 ms), roughly a 25x improvement. Profitable strategies that needed sub-100ms decision-to-execution went from infeasible to running in production. “The interesting thing is that we don't really talk about signing latency anymore. It's no longer the constraint that's driving decisions about what we can and can't deploy,” said the Head of Trading.

And the setup holds up at scale: the firm now runs around 17 million signing operations a day (that’s 500 million per month) with 99.999% measured uptime.

“It's one thing to hit a latency target in a benchmark. What's mattered to us is being able to sustain that performance while processing hundreds of millions of signing operations every month in real market conditions,” said the Head of Trading. They traded continuously through major volatility events, including the October 2025 and February 2026 market dislocations, with no observed degradation in signing performance.

“People tend to think of security controls as something that slows systems down. The Cubist platform has helped us design and implement controls that let our business move faster,” said the CISO.

Results at a glance

  • 25x faster signing latency
  • 24 ms p50 / 28 ms p90 / 32 ms p95 transaction signing
  • 17 million signing operations per day
  • 99.999% system uptime
  • No observed degradation during major market volatility events

Why it matters for trading firms

For trading firms using MPC products, signing latency limits the feasibility of latency-sensitive and other complex trading strategies. Using branded hot wallets is not a realistic solution.

Cubist can help you model what latency could look like with CubeSigner deployed close to your trading infrastructure.

We can also help you implement programmable policies that unlock the use of both private and public data to inform your trading operation.

See how faster signing and our programmable policy engine can unlock more PnL and opportunities.

Use Cases

Explore Related Case Studies