Overview
The MFA Security Shield replaces single seed phrase control with a configurable Security Shield — a rule set of authentication factors enforced by the Radix Engine's Access Controller (not application-level logic).
Rollout Phases
- Phase 1 (live on Stokenet, Oct 2025) — Configure a Security Shield, apply to accounts/personas, sign transactions using shield factors
- Phase 2 (on Stokenet, Dec 2025) — Update shield configuration, exercise recovery flows
- Phase 3 (mainnet prep) — Regain access to shielded accounts if phone/wallet backup is lost
Supported Factors
Phone biometrics, Ledger hardware wallets, Arculus NFC cards, off-device mnemonic phrases, and trusted person recovery. Users combine factors into custom rules (e.g., "phone + Ledger for large transfers, phone only for small amounts").
Unlike account abstraction on other chains, Radix MFA is enforced at the engine level — the Access Controller is a system component, not user-deployed code.
