Skip to content

Hot wallet compromise risk #9

@diorwave

Description

@diorwave

Problem

Server holds liquidity private keys in runtime.

Attack vectors:

  • server hack
  • dependency exploit
  • log leakage

Result: total funds stolen.

Required Solution

Introduce wallet security layer:

  • isolated signing service
  • per-swap derived addresses
  • withdrawal limits
  • optional MPC/HSM

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions