@zachxbt 2 of the 3 incidents in the screen shot involve breaching their CRM, which contained all of our PII. Now we get scams in the mail at our homes.
If you don’t want scammers knowing your name, phone, and home address, choose a hardware isolated wallet that doesn’t collect it.
Define huge security hole? Our wallet was built with inheritance in mind, and we would suggest a printed Recovery Sheet for the estate attorney or the trusted heir(s)/executor.
At present death is not an on chain event, so gating access based on it isn’t possible in self custody. Would love to consider other approaches that would work well for estate planning.
Our condolences to the family and we hope you can recover their estate.
@dankrad@udiWertheimer While passkeys can’t be created in the secure enclave, iOS and watchOS wallet developers can create SE keys using kSecAttrTokenIDSecureEnclave, and encrypt key material with P-256.
See https://t.co/u28WbeXlTv for details on this approach.
@coinbureau Seed phrases are difficult for users to handle safely. We’ve criticized users who may be new to self custody, when the fault lies with the operational practices we encourage.
This is why we designed Cryptograph’s wallet recovery flows around paraphrase encrypted QR code sheets.
The watch on your wrist decodes the bytes it signs. The keys never leave. There is no seed phrase to type. The customer database does not exist.
Seven cases, the architectural answer to each: https://t.co/wWFghhlt7l
Bybit signed bytes that did not match its screen. Slope sent seed phrases to a logging vendor. G. Love typed his into a counterfeit Mac app. BadgerDAO and Ledger Connect Kit injected drainer modals into legitimate dApps. Ledger's customer database leaked and fueled physical attacks.
@llamaonthebrink Points 1 and 2 are not mutually exclusive.
We noticed wallets becoming fintech, with KYC and privacy concerns; we also noticed a rise in mobile malware.
So we built a mobile wallet that knows nothing about you and stores your keys outside your phone.
Info in profile.
@Punk4725 Ledger’s CRM was breached at least once (that we know) of in 2020. We received the same letter in another country. It terrified us so much that we built a hardware isolated wallet that never needs your home address.
Info in profile.
Sorry this happened to you too.