<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Chain Concepts]]></title><description><![CDATA[The Chain Concepts Substack explores the economics behind blockchain, examining applications and protocols, with deep dive conversations on adoption for individuals, institutions, and industries.]]></description><link>https://blog.austin-sanderson.com</link><image><url>https://substackcdn.com/image/fetch/$s_!EUwh!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ca144bf-2047-434a-88cf-e7e7c7972af2_1024x1024.png</url><title>Chain Concepts</title><link>https://blog.austin-sanderson.com</link></image><generator>Substack</generator><lastBuildDate>Thu, 14 May 2026 11:46:21 GMT</lastBuildDate><atom:link href="https://blog.austin-sanderson.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[AskIT LLC]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[chainconcepts@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[chainconcepts@substack.com]]></itunes:email><itunes:name><![CDATA[Austin Sanderson]]></itunes:name></itunes:owner><itunes:author><![CDATA[Austin Sanderson]]></itunes:author><googleplay:owner><![CDATA[chainconcepts@substack.com]]></googleplay:owner><googleplay:email><![CDATA[chainconcepts@substack.com]]></googleplay:email><googleplay:author><![CDATA[Austin Sanderson]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[The Paradox of Self Custody and Trust]]></title><description><![CDATA[You are getting ready to send funds to an exchange from your hardware wallet.]]></description><link>https://blog.austin-sanderson.com/p/the-paradox-of-self-custody-and-trust</link><guid isPermaLink="false">https://blog.austin-sanderson.com/p/the-paradox-of-self-custody-and-trust</guid><dc:creator><![CDATA[Austin Sanderson]]></dc:creator><pubDate>Mon, 04 Sep 2023 15:26:38 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!-lHY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7387c226-2820-4d4c-93ab-26c99309e6a2_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-lHY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7387c226-2820-4d4c-93ab-26c99309e6a2_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-lHY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7387c226-2820-4d4c-93ab-26c99309e6a2_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!-lHY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7387c226-2820-4d4c-93ab-26c99309e6a2_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!-lHY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7387c226-2820-4d4c-93ab-26c99309e6a2_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!-lHY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7387c226-2820-4d4c-93ab-26c99309e6a2_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-lHY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7387c226-2820-4d4c-93ab-26c99309e6a2_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7387c226-2820-4d4c-93ab-26c99309e6a2_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2128427,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-lHY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7387c226-2820-4d4c-93ab-26c99309e6a2_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!-lHY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7387c226-2820-4d4c-93ab-26c99309e6a2_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!-lHY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7387c226-2820-4d4c-93ab-26c99309e6a2_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!-lHY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7387c226-2820-4d4c-93ab-26c99309e6a2_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><blockquote><p><em>You are getting ready to send funds to an exchange from your hardware wallet. You copy the public address from the exchange and into the wallet software. After triple-checking the address, you are confident you are not a victim of clipboard hijacking and have copied it correctly. Holding your breath, you click to approve the transaction. Now you've sent your funds to the chain and there is no turning back. Waiting in suspense, you check the transaction on the chain explorer, and you can see that it has one confirmation. Then two, then three. It finally settles, you exhale, and go on about your business.</em></p></blockquote><p>Those of use who have been a part of the space for a while are very familiar with this sense of unrest. Whether you're a newb or a maxi from the early days, we've all been there. And most of us started by always sending a small test transaction first. The truth is that confidence in making these transactions grows only through proper vigilance, but for some, it was unfortunately learned by making costly mistakes. After all, a core property of blockchain is <a href="https://wiki.austin-sanderson.com/Chain+Concepts/Consensus/Finality">finality</a> - sending to the wrong chain or address is effectively irreversible. </p><p>In part, what makes blockchain transactions irreversible is that there is no centralized party to appeal to. <em>There is no singular body to trust</em>. The network must reach final agreement via cryptographic consensus, making a blockchain a trustless financial system of record. </p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.austin-sanderson.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Chain Concepts! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>On the contrary: <a href="https://wiki.austin-sanderson.com/Chain+Concepts/Self+Custody/Self+Custody">self custody</a> (the practice which allows us to "be our own bank") is not necessarily trustless. It does, however, reduce exposure to financial intermediaries, so it empowers us with more financial sovereignty. And in an era where central banks consistently prove greedy, taking self custody of funds is an alluring prospect for new buyers. <em>But it can also be daunting</em>. Indeed, hardware wallets were designed to solve many of the associated fears of self custody. By abstracting away private key custodianship, hardware wallet manufacturers have created new trust relationships. </p><p>Because of this, anyone who plans to self-custody "crypto" should have at least a primitive understanding of <a href="https://wiki.austin-sanderson.com/Chain+Concepts/Cryptography/Public+Key+Cryptography">public key cryptography</a>, which is used to ensure blockchain transactions are authorized. Even though the word crypto often carries a negative connotation in the community, the term should not be considered taboo. Cryptographic consensus is the very foundation of our trust in valid transactions and blocks because it allows all nodes to synchronize sets of transactions <em>independently</em>. </p><p>Cryptography indeed enables secure monetary systems, networks, and data transactions. It is used to verify private keys without directly accessing them; it also verifies the owner of the wallet using <a href="https://wiki.austin-sanderson.com/Chain+Concepts/Cryptography/Signature+Algorithms">signature algorithms</a>. Still, vectors of trust and risk do permeate self-custody practices in the crypto space, which introduces this paradox of self custody and trust.</p><h3>In Crypto We Trust</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AUYn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b9e5b34-7d0d-4c50-90bd-f39e762c4206_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AUYn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b9e5b34-7d0d-4c50-90bd-f39e762c4206_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!AUYn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b9e5b34-7d0d-4c50-90bd-f39e762c4206_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!AUYn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b9e5b34-7d0d-4c50-90bd-f39e762c4206_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!AUYn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b9e5b34-7d0d-4c50-90bd-f39e762c4206_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AUYn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b9e5b34-7d0d-4c50-90bd-f39e762c4206_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1b9e5b34-7d0d-4c50-90bd-f39e762c4206_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2497685,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!AUYn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b9e5b34-7d0d-4c50-90bd-f39e762c4206_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!AUYn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b9e5b34-7d0d-4c50-90bd-f39e762c4206_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!AUYn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b9e5b34-7d0d-4c50-90bd-f39e762c4206_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!AUYn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b9e5b34-7d0d-4c50-90bd-f39e762c4206_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Those who willfully enter the crypto space are indeed trusting many things including cryptography, consensus mechanisms, and game theory equilibria. While it isn't ignorant to trust in cryptographic protocols, implementations of crypto wallets have always carried known risks. </p><p>In <a href="https://arxiv.org/pdf/1501.00447.pdf">How Perfect Offline Wallets Can Still Leak Bitcoin Private Keys (PDF)</a>, researchers show how a wallet sending transactions could fall victim to malicious implementations. <a href="https://wiki.austin-sanderson.com/Chain+Concepts/Cryptography/Elliptic+Curve+Cryptography">Elliptic Curve Cryptography</a>, for example, is what is used to generate public-private key pairs and digital signatures, and early implementations of the <a href="https://wiki.austin-sanderson.com/Chain+Concepts/Cryptography/Signature+Algorithms#Elliptic+Curve+Digital+Signature+Algorithm+(ECDSA)">Elliptic Curve Digital Signature Algorithm (ECDSA)</a> had known vulnerabilities. In this research example, the point along the <a href="https://wiki.austin-sanderson.com/Chain+Concepts/Cryptography/Elliptic+Curve+Cryptography#secp256k1+curve">secp256k1</a> elliptic curve is chosen by the wallet software instead of the algorithm's libraries. Under this configuration, the randomness with which that point is selected is <em>external</em> to the ECDSA algorithm. </p><p>Nefarious code can then choose a point along the secp256k1 elliptic curve that is non-random or predictable, allowing for the effective forgery of digital signatures. Later implementations adhering to <a href="https://wiki.austin-sanderson.com/Chain+Concepts/Cryptography/Elliptic+Curve+Cryptography#RFC-6979">RFC-6979</a> helped mitigate this by selecting random numbers deterministically. This mechanism - internal to the algorithm's libraries - ensured that the nonce (i.e., number used only once) is <em>not reused</em> across multiple digital signatures. </p><p><em>The point is that most in the space implicitly trust cryptography</em>. In doing so, we may blindly assume blockchain security models are robust enough. One such blind spot is the expectation that blockchain consensus is <a href="https://wiki.austin-sanderson.com/Chain+Concepts/Cryptography/Quantum+Resistance">quantum resistant</a>, which is an arguably negligible threat. Perhaps more critically, we must acknowledge our trust in consensus game theory principles. <a href="https://wiki.austin-sanderson.com/Chain+Concepts/Consensus/Hashpower">Hashpower</a> must be decentralized enough to protect against coercion, collusion, and censorship. Ultimately, the longest chain needs to win to achieve <a href="https://wiki.austin-sanderson.com/Chain+Concepts/Consensus/Immutability">immutability</a> and to maintain trust in the consensus. </p><p>This much should be clear, but things can get fuzzy on the question of trust when talking about wallet transactions. Bottom line, funds would never be sent anywhere on the blockchain without some piece of code being executed on a device. When the wallet holds the private keys, <em>self custody is then a bit of a misnomer</em>. And perhaps the entire community is doing itself a disservice by not making one important distinction:</p><blockquote><p><a href="https://wiki.austin-sanderson.com/Chain+Concepts/Self+Custody/Self+Custody">Self custody</a> is not necessarily <a href="https://wiki.austin-sanderson.com/Chain+Concepts/Self+Custody/Self+Hosting">self hosting</a>. The storage device or software can be the key custodian, even when the owner is its sole operator. Self custody then does not equate to trustlessness; it is just a form of financial choice and control. Any notion that trustlessness can be achieved in some pure, unadulterated sense must be a logical fallacy. </p></blockquote><p>And so we also trust in wallet manufacturers, third-party chip certifiers, sellers, shippers, code auditors, and - biggest of all - firmware developers. Maybe you do have a truly <a href="https://wiki.austin-sanderson.com/Chain+Concepts/Self+Custody/Wallet+Types#Airgapped+%2F+Offline">airgapped, offline solution</a>. Or maybe you have a <a href="https://wiki.austin-sanderson.com/Chain+Concepts/Self+Custody/Wallet+Types#Paper">paper wallet</a>, but even then you are trusting in seed generation methods (i.e., <a href="https://wiki.austin-sanderson.com/Chain+Concepts/Cryptography/Entropy">entropy</a>). Above all else, you are trusting yourself and your own environment. But as members of the crypto community, what we can focus on is what we can control. </p><p>In <a href="https://vitalik.ca/general/2021/01/11/recovery.html">Why We Need Wide Adoption of Social Recovery Wallets</a>, <a href="https://wiki.austin-sanderson.com/Chain+Concepts/People/%40Vitalik+Buterin">Vitalik Buterin</a> writes:</p><div class="pullquote"><p>To me, the goal of crypto was never to remove the need for&nbsp;all&nbsp;trust.&nbsp;Rather, the goal of crypto is to give people access to cryptographic and economic building blocks that give people more&nbsp;choice&nbsp;in whom to trust, and furthermore allow people to build more&nbsp;constrained&nbsp;forms of trust: giving someone the power to do some things on your behalf without giving them the power to do everything.</p></div><p>This power of choice cannot be overstated. Choosing to self-custody is empowering, and with hardware wallets, it may feel safer and more secure. Indeed, private keys are isolated, and as the sole operator, you can maintain control. Risk management is therefore vital, but the question of acceptable risk is a highly subjective one. It is largely determined by a user's knowledge of options, their technical skill, operational security, and overall risk tolerance. While the problems of malicious software may never fully be solved, hardware wallets can significantly reduce the risks of such key exposure or loss of funds. To restate the obvious, however, fears about private key leakage or disclosure are still valid. </p><p>Holding this frame, users' perceptions of hardware wallet security were recently shaken by <a href="https://blog.austin-sanderson.com/i/135163468/cold-storage-maybe-its-not-so-cold-anymore">announcements of key recovery features</a>. And by extension, so was trust in many types of self custody. Given this shift in user psychology, an opportunity is presented to take back our choice of control. Future adoption of Bitcoin and other digital assets will rely upon these security perceptions. <em>An improved user experience for those who wish to self-custody their funds</em>. To combat new risk vectors, what users can do is to choose their own cryptographic circles of trust. </p><h3>The Circle of Trust</h3><h4>Secret Sharing and Social Recovery</h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!m4BX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cb4f149-0814-4ea3-ac96-01db835a2823_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!m4BX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cb4f149-0814-4ea3-ac96-01db835a2823_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!m4BX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cb4f149-0814-4ea3-ac96-01db835a2823_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!m4BX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cb4f149-0814-4ea3-ac96-01db835a2823_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!m4BX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cb4f149-0814-4ea3-ac96-01db835a2823_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!m4BX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cb4f149-0814-4ea3-ac96-01db835a2823_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1cb4f149-0814-4ea3-ac96-01db835a2823_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2256518,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!m4BX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cb4f149-0814-4ea3-ac96-01db835a2823_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!m4BX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cb4f149-0814-4ea3-ac96-01db835a2823_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!m4BX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cb4f149-0814-4ea3-ac96-01db835a2823_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!m4BX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cb4f149-0814-4ea3-ac96-01db835a2823_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Most in the community are familiar with ever-growing estimates that ~4 million BTC are assumed lost forever, a number roughly equal to 20% of the final Bitcoin supply. Others may have heard the stories of Bitcoin being lost on the legendary "boating accidents". While the latter is mostly anecdotal, the former statistics do highlight the need for improved self-custody methods <em>especially to protect novice users from loss</em>. While private key recovery is controversial (and with good reason), it is because of lost funds that social recovery features may be both desirable and in demand. Regardless of any user preferences, <em>there is some historical precedent here</em>. </p><p><a href="https://wiki.austin-sanderson.com/Chain+Concepts/Cryptography/Secret+Sharing">Secret sharing</a> was first introduced by Adi Shamir in 1979 as part of his paper <a href="https://wiki.austin-sanderson.com/Chain+Concepts/Whitepapers+and+Research/How+to+Share+a+Secret+(Shamir+1979).pdf">How to Share a Secret (PDF)</a>. The idea behind it was simple yet powerful - divide something (like a private key) into multiple parts so that only specified combinations could unlock it. Still today, this method provides enhanced security against unauthorized access, but it poses challenges when users lose portions of their keys. Because losing private keys means losing access to assets permanently, <a href="https://wiki.austin-sanderson.com/Chain+Concepts/Self+Custody/Social+Recovery">social recovery</a> is a natural evolution of secret sharing. In social recovery systems, a group of trusted guardians are chosen to hold an encrypted share of the seed. </p><p>When needed, these contacts can come together and decrypt the respective portions to reconstruct or recover the original seed. <a href="https://wiki.austin-sanderson.com/Chain+Concepts/Cryptography/Secret+Sharing#Verifiable+Secret+Sharing+(VSS)">Verifiable Secret Sharing (VSS)</a>, an extension of Shamir's initial concept, plays an important role in enhancing trust within such social recovery systems. VSS allows any participant in the scheme to verify whether their share is correct without revealing it. Ensuring integrity while maintaining confidentiality, VSS checks that guardians hold valid shares before they attempt to reconstruct the original key. Without these verification measures, malicious actors can potentially provide incorrect shares and compromise the entire process. Social recovery is then akin to <a href="https://wiki.austin-sanderson.com/Chain+Concepts/Cryptography/Signature+Schemes#Multi-signature+(Multi-sig)">multi-sig schemes</a>, where wallet owners can require M of N key shard custodians to process a transaction. </p><p>Both social recovery and multi-sig schemes require a high level of trust that one's guardians or custodians will cooperate when needed. Assuming you can rely on enough of your custodians, such methods have no single point of failure, or put another way, <em>no single point of vulnerability</em>. Such methods can distribute risk; they can also displace or redistribute trust. Multi-sig then ensures that no single person can access funds without agreement from multiple parties. With social recovery, key reconstructions are also only possible with a trusted circle of one's choosing. </p><p>Hardware wallet manufacturers have responded with similar recovery features. Ledger, for example, launched a recovery feature in which they <em>effectively choose your custodians for you</em>. These custodians holding private key fragments could be viewed as "key escrow firms". Under this configuration, users do give up some degree of control. Whatever option users choose, proper self custody or hosting takes technical prowess and vigilance. </p><p>Ultimately, users need to assess the risk and trust vectors to make the right choice for their needs. Some may actually want self-custody options that protect them against user error, where others will want to internalize as much risk as they can by self-hosting. At the end of the day, the Bitcoin blockchain is an open-source, peer-to-peer monetary network. <strong>Transparency is therefore the key to trust</strong>. This is why many people self-host, and why calls for open-sourced firmware for all hardware wallet manufacturers are <em>both valid and critical</em> for adoption. </p><p>Bigger picture, what self custody is really about is <em>true</em> ownership of assets. It speaks to an understated wisdom that centralized banking systems have inherent flaws as financial custodians. Power centers introduce greed, and greed begets power. The ability to self custody does not solve this, nor is trustlessness alone a solution. With self custody, though, we can regain some financial sovereignty. We can put our trust in systems we choose and control. And that is what this financial revolution is about. &#9996;&#127996;  </p><p>You can check out an overview of <a href="https://wiki.austin-sanderson.com/Chain+Concepts/Self+Custody/Self+Custody">Self Custody</a> in the <a href="https://wiki.austin-sanderson.com/Chain+Concepts/Chain+Concepts+Explained">Chain Concepts wiki</a>, along with:</p><p>- information on <a href="https://wiki.austin-sanderson.com/Chain+Concepts/Self+Custody/Attack+Vectors">wallet attack vectors</a>,</p><p>- atomic explanations of <a href="https://wiki.austin-sanderson.com/Chain+Concepts/Self+Custody/Wallet+Types">wallet types</a>, </p><p>- and some examples of <a href="https://wiki.austin-sanderson.com/Chain+Concepts/Self+Custody/Software+and+Web+Wallets">software and web wallets</a>.</p><p>Subscribe or share now for early access to my next article under the working title <em>You Cannot Decentralize Greed</em>. Don't forget to revisit the wiki for upcoming updates. &#129305;&#127996;</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.austin-sanderson.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Chain Concepts! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Not Your Keys, Not Your Coins v2.0]]></title><description><![CDATA[For many in the crypto community, the last 18 months have been a tumultuous journey.]]></description><link>https://blog.austin-sanderson.com/p/not-your-keys-not-your-coins-v20</link><guid isPermaLink="false">https://blog.austin-sanderson.com/p/not-your-keys-not-your-coins-v20</guid><dc:creator><![CDATA[Austin Sanderson]]></dc:creator><pubDate>Tue, 18 Jul 2023 01:23:35 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!y38p!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77b11679-8e04-4a13-b69d-a56a49de11f7_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!y38p!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77b11679-8e04-4a13-b69d-a56a49de11f7_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!y38p!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77b11679-8e04-4a13-b69d-a56a49de11f7_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!y38p!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77b11679-8e04-4a13-b69d-a56a49de11f7_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!y38p!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77b11679-8e04-4a13-b69d-a56a49de11f7_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!y38p!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77b11679-8e04-4a13-b69d-a56a49de11f7_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!y38p!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77b11679-8e04-4a13-b69d-a56a49de11f7_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/77b11679-8e04-4a13-b69d-a56a49de11f7_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2462462,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!y38p!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77b11679-8e04-4a13-b69d-a56a49de11f7_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!y38p!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77b11679-8e04-4a13-b69d-a56a49de11f7_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!y38p!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77b11679-8e04-4a13-b69d-a56a49de11f7_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!y38p!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77b11679-8e04-4a13-b69d-a56a49de11f7_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>For many in the crypto community, the last 18 months have been a tumultuous journey. Many long-term holders have endured volatility before, but the Spring and Summer of 2021 undoubtedly kickstarted a hellish bear market. This market - filled with the usual amount of uncertainty - was still quite unique in its own right.  Most notably, a seismic shift in Bitcoin <a href="https://wiki.austin-sanderson.com/Chain+Concepts/Consensus/Hashpower">hashpower</a> began in May of 2021, during which roughly 50-60% of Bitcoin's computational power poured out of China. The price of Bitcoin (BTC) then experienced swings of ~40% in the span of days or weeks, demonstrating volatility the likes of which we had not seen since the 2017 bull run. </p><p>Still, the Bitcoin network proved resilient in the face of major migrations, bolstering its claim as a decentralized and secure monetary network. Despite the looming bear market, some remained incredibly bullish. Companies like MicroStrategy, for example, was investing hundreds of millions of dollars in BTC. Under this light, the digital asset landscape was looking more stable and secure, making it palatable for investors of all kinds. </p><p>Of course, market cycles do exist, and the <a href="https://wiki.austin-sanderson.com/Chain+Concepts/Tokenomics/Bitcoin+Halving">Bitcoin Halving</a> is a key part of that. But just like in 2017, many arrived late to the party in 2021 and locked in severe losses.  Around the same time, some holders were staying in the game with serious conviction, locking up their Ethereum on-chain prior to its migration to Proof of Stake. <strong>Then, at an uncertain point, the 2021 correction caused a shift in investor thinking</strong>. </p><p>In droves, retail investors sought refuge in stablecoin banks. Others placed their BTC and ETH into platforms for percentage yields <em>in the mere single digits</em>. Everyone wanted to earn while they waited on the sidelines. This trend rapidly normalized yield-seeking behavior, building a pyramid of liquidity pools with low-to-no oversight. Under this new normal, investors unwittingly exposed themselves to <a href="https://wiki.austin-sanderson.com/Chain+Concepts/Concepts/Counterparty+Risk">counterparty risk</a> at a level never before seen. And the kicker? This was all done in an ecosystem that should&#8217;ve read the tea leaves of impending collapse. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sZyK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F258c74a1-3097-4b54-a61c-d81b36f269f0_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sZyK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F258c74a1-3097-4b54-a61c-d81b36f269f0_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!sZyK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F258c74a1-3097-4b54-a61c-d81b36f269f0_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!sZyK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F258c74a1-3097-4b54-a61c-d81b36f269f0_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!sZyK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F258c74a1-3097-4b54-a61c-d81b36f269f0_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sZyK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F258c74a1-3097-4b54-a61c-d81b36f269f0_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/258c74a1-3097-4b54-a61c-d81b36f269f0_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2001338,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sZyK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F258c74a1-3097-4b54-a61c-d81b36f269f0_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!sZyK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F258c74a1-3097-4b54-a61c-d81b36f269f0_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!sZyK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F258c74a1-3097-4b54-a61c-d81b36f269f0_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!sZyK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F258c74a1-3097-4b54-a61c-d81b36f269f0_1536x1024.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Indeed, there were some signs, and then those signs turned into waving red flags. As firms like BlockFi <a href="https://www.sec.gov/news/press-release/2022-26">agreed to pay regulators $100 million</a>, the company was slowly reducing the yields in the name of "sound risk management". In Mid 2022, Voyager Digital even suspended customer withdrawals, later seeking out firms who could absorb their losses. And in spite of <a href="https://restructuring.ra.kroll.com/FTX/Home-DownloadPDF?id1=MTQ0OTk1OQ==&amp;id2=-1">ongoing litigation</a>, Voyager customers have only just received ~35% of assets back. As a stark example of this pyramid of illiquidity, the now-defunct <a href="https://www.coindesk.com/business/2022/09/27/ftx-wins-bid-to-buy-voyager-digitals-assets/">FTX actually had plans to buy Voyager Digital</a>. </p><p>Still today, the saga continues for those with funds frozen in the Gemini Earn program, who are <a href="https://www.forbes.com/sites/johnhyatt/2022/12/06/customers-of-crypto-billionaires-winklevoss-gemini-plead-for-lost-funds/?sh=6c1201ec7653">collectively owed ~$900 million</a>. Any investor with funds locked up, whether it's $1000 of BTC or $100k worth of USDC, has a daily reminder of the lessons taught by Satoshi Nakamoto's staunchest fans. Trite but true, conventional wisdom has always been <strong>Not Your Keys, Not Your Coins</strong>. It has been repeated so often that it must be considered dogma. </p><p>With untold losses too many small fortunes to count, all too many have lost funds to theft, scams, centralized exchanges, forgotten memories, and simple human error. So now, there is another side to this coin. Many investors decided to promptly exit exchanges and move funds to cold storage, reemphasizing the importance of proper self custody.  Just a few months later, many who had blind faith in cold storage have had their conviction shaken yet again, bringing us to <strong>version 2.0 of Not Your Keys, Not Your Coins</strong>. </p><h3>Cold Storage - Maybe It's Not So Cold Anymore</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6hYo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b617a0e-e2f8-4e6e-a70e-6d0a2012153c_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6hYo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b617a0e-e2f8-4e6e-a70e-6d0a2012153c_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!6hYo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b617a0e-e2f8-4e6e-a70e-6d0a2012153c_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!6hYo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b617a0e-e2f8-4e6e-a70e-6d0a2012153c_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!6hYo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b617a0e-e2f8-4e6e-a70e-6d0a2012153c_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6hYo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b617a0e-e2f8-4e6e-a70e-6d0a2012153c_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1b617a0e-e2f8-4e6e-a70e-6d0a2012153c_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2456057,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6hYo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b617a0e-e2f8-4e6e-a70e-6d0a2012153c_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!6hYo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b617a0e-e2f8-4e6e-a70e-6d0a2012153c_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!6hYo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b617a0e-e2f8-4e6e-a70e-6d0a2012153c_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!6hYo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b617a0e-e2f8-4e6e-a70e-6d0a2012153c_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In mid-May, Ledger <a href="https://twitter.com/Ledger/status/1658458714771169282?s=20">announced a recovery feature</a> for its hardware wallet that would allow a user to back up their seed to three separate companies: Coincover, Ledger, and EscrowTech, where each company secures one fragment of the encrypted <a href="https://wiki.austin-sanderson.com/Chain+Concepts/Cryptography/Seeds%2C+Keys%2C+Transaction+Signing#Pre-BIP39">pre-BIP39</a> version of your private key. To enable the feature, users must cryptographically sign from their hardware wallets in the same way they would send funds. Still, doubts about the security of the firmware, and fears of backdoors, thundered across the crypto community. This all came in the form of cries about censorship or potential seizure, where key custodians may be coerced by centralized agents of control. No matter where you land on this issue, it is true that having cloud custodians of your keys, whether divided or not, introduces <em>very real attack surfaces</em>. </p><p>The overall response has still been relatively mixed. Some took hammers to their Ledger device, and others silently reassessed their self custody practices. Some take the view that nothing fundamental has changed with respect to transaction processing or hardware. Others question manufacturer integrity <em>and by extension the device itself</em>. Sentiment from social media suggested that Ledger owners had an expectation that their keys could never be extracted from the device. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QaD3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b3bf606-1775-4eee-b321-cc2f45340ee7_1098x516.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QaD3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b3bf606-1775-4eee-b321-cc2f45340ee7_1098x516.jpeg 424w, https://substackcdn.com/image/fetch/$s_!QaD3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b3bf606-1775-4eee-b321-cc2f45340ee7_1098x516.jpeg 848w, https://substackcdn.com/image/fetch/$s_!QaD3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b3bf606-1775-4eee-b321-cc2f45340ee7_1098x516.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!QaD3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b3bf606-1775-4eee-b321-cc2f45340ee7_1098x516.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QaD3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b3bf606-1775-4eee-b321-cc2f45340ee7_1098x516.jpeg" width="1098" height="516" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6b3bf606-1775-4eee-b321-cc2f45340ee7_1098x516.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:516,&quot;width&quot;:1098,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:166583,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QaD3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b3bf606-1775-4eee-b321-cc2f45340ee7_1098x516.jpeg 424w, https://substackcdn.com/image/fetch/$s_!QaD3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b3bf606-1775-4eee-b321-cc2f45340ee7_1098x516.jpeg 848w, https://substackcdn.com/image/fetch/$s_!QaD3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b3bf606-1775-4eee-b321-cc2f45340ee7_1098x516.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!QaD3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b3bf606-1775-4eee-b321-cc2f45340ee7_1098x516.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Many cited the Tweet above as the reason for their stance, while others may have been in denial of the fact that they trusted the manufacturer implicitly. Prior to this feature announcement, consumer opinion was that the Ledger wallets were a black box, and the device itself can only ever know the key. Community backlash then came in the form of demands for open-sourcing the code. Ledger rather swiftly rolled back their plan, releasing the <a href="https://github.com/LedgerHQ/recover-whitepaper">Ledger Recover Technical White Paper</a> and <a href="https://twitter.com/_pgauthier/status/1661012614753943559">vowing to open-source code</a> prior to the feature's release. </p><p>We don&#8217;t yet know how this will play out. What is obvious is that recent events have sparked a debate with some incredibly nuanced, albeit technical talks on what "trustlessness" practically means. This has forced many to ask the hard question: <em>Is there a form of self custody that is truly free of trust?</em></p><p>To delve deeper into this, what follows is an article entitled The Paradox of Self Custody and Trust. It includes core concepts of cryptographic transactions, consensus, and trust. It examines the perils of taking full custody of digital assets, while comparing industry options to more &#8220;pure&#8221; forms of self custody.  It will also take a clear-eyed view of how self custody methods can affect adoption. Feel free to like, share, or subscribe to spread the word!</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.austin-sanderson.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Chain Concepts! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.austin-sanderson.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Chain Concepts! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item></channel></rss>