Live data from Hacker News

Crypto Startup Bankrupt After Losing Password to $38.9M Crypto Wallet

404media.co

11–20 of 25 posts

Re: Crypto Startup Bankrupt After Losing Password to $38.9M Crypto Wallet

#11
post #6
post #4

I’m reminded of the dotcom bubble when companies would proudly show off their “we’re in the big boy club” server rooms with millions of dollars in Cisco and Sun hardware, Oracle and BEA licenses, etc. and hope you wouldn’t notice that they had three customers and no sysadmins. Around the time you’re paying someone to metal etch your encryption keys, anyone with a shred of ethics should be asking whether that’s anythi…

This is a solved problem in crypto and having even a billion in a single wallet is fine. That’s why multi-sig were created, it’s used more as a redundancy mechanism than a voting one.

Even with multisig, each individual key holder has to manage their device, and the steel backup for that device. And there exists possibility of collusion between n of m of the multi sig holders against the other holders. Seems like it would still keep me up at night (though with SVB, standard bank accounts are starting to look shaky too).

Having not worked for a crypto company, curious what the standard best practices are for securing the "keys to the kingdom" (literally).

Re: Crypto Startup Bankrupt After Losing Password to $38.9M Crypto Wallet

#12

> Rather than write down the seed phrases, Prime Trust opted to laser etch them into a piece of steel ... which ... it lost So, someone or someones have the steel piece(s) with the seed phrases on them. And that person or persons will be able to retrieve the funds at a future date, when the timing and location seems suitable. Maybe in say, Switzerland, when the prices for ETH, Bitcoin (etc) are high. That's pretty in…

They should contact the laser etching company and see if the gcode file is still on drive of the etching machine...

(They probably requested the company shred the files or whatevs but given the overall low level of due diligence I'd say it's worth a shot).

Re: Crypto Startup Bankrupt After Losing Password to $38.9M Crypto Wallet

#14
post #13

Cynical take, but what if it’s all a scam to steal 38.9M for themselves. That they haven’t actually lost the password… Just wait a few years and suddenly we’re rich!

It may be cynical, but everybody is thinking it.

Re: Crypto Startup Bankrupt After Losing Password to $38.9M Crypto Wallet

#15
post #6
post #4

I’m reminded of the dotcom bubble when companies would proudly show off their “we’re in the big boy club” server rooms with millions of dollars in Cisco and Sun hardware, Oracle and BEA licenses, etc. and hope you wouldn’t notice that they had three customers and no sysadmins. Around the time you’re paying someone to metal etch your encryption keys, anyone with a shred of ethics should be asking whether that’s anythi…

This is a solved problem in crypto and having even a billion in a single wallet is fine. That’s why multi-sig were created, it’s used more as a redundancy mechanism than a voting one.

It's definitely not a "solved problem", especially the non-technical aspects. For example, uh, see this current post we are on.

Re: Crypto Startup Bankrupt After Losing Password to $38.9M Crypto Wallet

#16
post #6

Earlier quoted context omitted.

This is a solved problem in crypto and having even a billion in a single wallet is fine. That’s why multi-sig were created, it’s used more as a redundancy mechanism than a voting one.

Even with multisig, each individual key holder has to manage their device, and the steel backup for that device. And there exists possibility of collusion between n of m of the multi sig holders against the other holders. Seems like it would still keep me up at night (though with SVB, standard bank accounts are starting to look shaky too). Having not worked for a crypto company, curious what the standard best practic…

There is no collusion, that’s the point of multi-sig, it’s akin to voting powers.

You can use multisig yourself too: ie you can use a key you remember, or the one in your safe. Along with a key in your phone. So two out of three. If someone gets the key in your safe, he can’t access your coins (he’ll need your phone too).

Re: Crypto Startup Bankrupt After Losing Password to $38.9M Crypto Wallet

#17
post #6
post #4

I’m reminded of the dotcom bubble when companies would proudly show off their “we’re in the big boy club” server rooms with millions of dollars in Cisco and Sun hardware, Oracle and BEA licenses, etc. and hope you wouldn’t notice that they had three customers and no sysadmins. Around the time you’re paying someone to metal etch your encryption keys, anyone with a shred of ethics should be asking whether that’s anythi…

This is a solved problem in crypto and having even a billion in a single wallet is fine. That’s why multi-sig were created, it’s used more as a redundancy mechanism than a voting one.

multi-sig addresses one aspect of the problem but not everything. The underlying problem is that the system is brittle rather than robust, and multisig only helps with a specific challenge (“I don’t want a single key loss to lose everything, but don’t want to make copies of the same key”). It doesn’t help with many common scenarios: “I was compromised”, “my employee abused access to my keys”, “someone made a typo in a transfer”, “I am choosing not to comply with a court order”, “our CFO died unexpectedly”, etc.

Contrast this with how easily this could have been resolved in the financial systems which are actually used and you get an immediate appreciation of how valuable it is to have a way to handle human error in systems used by humans.

Re: Crypto Startup Bankrupt After Losing Password to $38.9M Crypto Wallet

#18
post #16

Earlier quoted context omitted.

Even with multisig, each individual key holder has to manage their device, and the steel backup for that device. And there exists possibility of collusion between n of m of the multi sig holders against the other holders. Seems like it would still keep me up at night (though with SVB, standard bank accounts are starting to look shaky too). Having not worked for a crypto company, curious what the standard best practic…

There is no collusion, that’s the point of multi-sig, it’s akin to voting powers. You can use multisig yourself too: ie you can use a key you remember, or the one in your safe. Along with a key in your phone. So two out of three. If someone gets the key in your safe, he can’t access your coins (he’ll need your phone too).

There is collusion, of exactly the form described. Just because the collusion happens through voting doesn't make it not collusion.

Re: Crypto Startup Bankrupt After Losing Password to $38.9M Crypto Wallet

#19
> Prime Trust pitches itself as a crypto fintech company designed to help other startups offer crypto retirement plans, know-your-customer interfaces, ensure liquidity, and a host of other services.

A crypto pension plan administered by this lot? Sounds like a recipe for multiple heart attacks.

Re: Crypto Startup Bankrupt After Losing Password to $38.9M Crypto Wallet

#20
post #6

Earlier quoted context omitted.

This is a solved problem in crypto and having even a billion in a single wallet is fine. That’s why multi-sig were created, it’s used more as a redundancy mechanism than a voting one.

Even with multisig, each individual key holder has to manage their device, and the steel backup for that device. And there exists possibility of collusion between n of m of the multi sig holders against the other holders. Seems like it would still keep me up at night (though with SVB, standard bank accounts are starting to look shaky too). Having not worked for a crypto company, curious what the standard best practic…

even the laser etcher is a problem :)
Post reply on HN