logoalt Hacker News

WatchDogtoday at 4:44 AM1 replyview on HN

> took a private key from KMS

They used KMS to sign the minting operation, but they didn't "take" the key, AWS KMS doesn't let you extract keys.


Replies

pants2today at 5:43 AM

^ this is a common security misconception in crypto. "We're using an HSM, they can't steal our private key." OK genius now you still have to secure the HSM.

There's no shortcut to MPC/multisig with 3+ keyholders.

show 2 replies