Building infrastructure for DeFi @finest_tokenize @BlockSign_io (Asset Operation & eSign & Verify/onboarding) @beginwallet, Cardano Ambassador, IANTD Cave Diver

Mos Eisley
Your crypto security shouldn’t depend on one key, one device or one person. Below is the first of 5 BlockSign posts explaining how different NON-CUSTODIAL key-management architectures can help you protect your digital assets while you remain in control. Read them. Understand the differences. And maybe HODL a little more relaxed. One point upfront: @BlockSign_io can’t unilaterally move your funds. Ever. We provide governance, not custody. If custody is required, our regulated partner @nbxcom provides it. Your assets. Your control. Find the covers of all posts below — and follow @BlockSign_io for the full series and more insights on digital asset security and governance. Post 1/5↓
Custody vs. non-custody. BlockSign never has your keys. Governance is not custody. On the BlockSign platform, asset owners define and enforce who is allowed to do what: roles, approvals, limits and policies — while remaining in full control of their assets. For institutional and professional investors that require custody, optional custody is provided by our regulated custody partner @nbxcom. BlockSign cannot access, move or manage your funds. Never!
Made with AI
1
4
264
That’s quite cool! Well done @Cardano_CF
Learn to build a Cardano app with an AI agent. The Cardano Academy's new course, Agentic Coding on Cardano, is live. This free course teaches you to direct an AI agent, audit its code and prove each result on testnet. Time to build the agentic way. cardanofoundation.org/en/aca…
1
8
203
Five BlockSign products. One trust platform. Digital trust is not one problem. That is why @BlockSign_io is building one shared trust infrastructure across five products: Asset Operations. eSign. Verify. CallShield. Verkauft! Different products. Different markets. The same foundation: identity, authority, approval and verifiable evidence. Built to be embedded into the workflows where trust actually matters. Your assets. Your control.
64
CIP-113 is moving from specification to operations. And that’s where things get interesting. At BlockSign, we have now successfully executed a governed programmable-token lifecycle on Cardano Preview: → Registration + initial mint → Separate mint → Wallet-to-wallet transfer → Burn All confirmed on-chain. But making a transaction work is only half the challenge. Institutional operations need to answer different questions: - Who is allowed to initiate it? - Who must approve it? - What exactly was approved? - Can the transaction change after approval? - Who can execute it? - And can all of this be proven afterwards? That’s why BlockSign separates: Intent → Build → Validate → Approve → Execute → Confirm → Evidence ❗️Changing the transaction means changing the approval.❗️ This week, CIP-113 builders are meeting to discuss improvements to the emerging infrastructure. Our testing is already producing concrete operational learnings around governance, transaction flows and the requirements for using programmable tokens in real-world environments. The next step is bigger than minting tokens. It’s making programmable assets operationally ready for institutions. @planetmaaz @michaeldotada @Cardano
Cardano has a regulated-asset interoperability problem we need to solve. CIP-113 enables programmable assets. But if every regulated stablecoin comes with its own compliance and transaction logic, wallets, DEXs, exchanges, custodians and infrastructure providers may have to integrate each asset individually. That doesn’t scale. PR #1266 addresses this for regulated stablecoins by exploring a shared standard for capabilities such as mint/burn, freeze/seize, roles, key rotation, upgrades and redemption. But the underlying question goes beyond stablecoins. The same challenge will increasingly matter for RWAs, tokenized commodities, securities, funds and other regulated assets. If Cardano wants to become serious infrastructure for institutional assets, interoperability must be designed in from the beginning, not retrofitted later. PR #1266 is still a proposal. That makes NOW the right time to get involved. Builders. Issuers. Wallets. DeFi protocols. Custodians. Institutions. ➡️ Read it. Challenge it. Contribute. 👉 GitHub PR #1266: github.com/cardano-foundatio… This discussion could become very important for Cardano’s institutional future.
2
4
11
905
TIMxBRIDGE retweeted
Smart Contract Security, and Continuous Auditing - Why One Check Is No Longer Enough x.com/i/broadcasts/1NxaroOqL…
11
46
165
58,701
Shamir or FROST? The right architecture depends on how you use your assets. Over the last posts, we looked at two approaches to distributed key management: Shamir Secret Sharing and FROST threshold signatures. Both can remove dependency on a single keyholder. But they solve different operational problems. Shamir is fundamentally simple to understand: split a secret into several shares and define a threshold — for example, 3-of-5. When recovery is required, enough shares are combined and the original secret can be reconstructed. That makes Shamir particularly interesting when the main objective is secure backup and recovery. A single asset owner can even distribute their shares across separate secure locations. The trade-off comes when the key needs to be used. Once the threshold is reached, the complete secret can exist again during reconstruction. The reconstruction environment therefore becomes part of the security model. FROST approaches everyday operation differently. Again, participants hold shares of a common signing key and a threshold can be defined. But during normal signing, the required participants cooperate to create signature shares. Those are combined into one valid Schnorr signature — without reconstructing the complete signing key. That makes FROST particularly interesting when distributed control is required not only for recovery, but for regular transaction signing. So which is better? There is no universal answer. For an individual investor or single high-value trader, Shamir can offer an understandable way to distribute recovery material and avoid keeping one complete secret in one location. For a family office or small organization, the decision increasingly depends on operational requirements. Is distributed control primarily needed for disaster recovery, or should several people participate every time important assets are moved? For SMEs, institutions and professional asset operations, FROST can become particularly interesting where multiple authorized participants should jointly sign transactions without reconstructing the complete signing key during normal operation. And there are more questions than security alone: - How easy is the initial setup? - How does recovery work? - How convenient is everyday signing? - What happens when a participant leaves? - How are shares replaced or refreshed? - What happens if participants are unavailable? - Which blockchains and signature schemes are supported? - And how does the cryptographic threshold connect to the organization’s actual governance? That last question is crucial. A 3-of-5 cryptographic threshold does not automatically tell you who is allowed to initiate a €5 million transaction, which assets they may move, which addresses are permitted or what transaction limits apply. That is governance. With BlockSign, organizations can choose a key-management architecture that fits their operational and security requirements and combine it with roles, approvals, policies, transaction limits and audit evidence. Shamir distributes the secret. FROST distributes the signing process. BlockSign adds the governance around it. Not sure which architecture fits your digital asset operations? Talk to us.
What if you could sign with a private key, without ever bringing the complete key back together? That is the idea behind FROST (= Flexible Round-Optimized Schnorr Threshold) Signatures. Imagine a 3-of-5 setup. Five participants each hold a secret share of a common signing key. At least three must cooperate to create a valid signature. But unlike the reconstruction process we described in our Shamir post, the participants do not need to combine their shares to reconstruct the complete private key before signing. Instead, each participating signer uses its own share to produce a signature share. Once the required threshold participates, those signature shares are aggregated into one valid Schnorr signature. The complete group signing key does not need to be reconstructed during normal signing. This removes an important risk: there is no moment during normal signing when the complete private key needs to be brought together in one place. And compromising a single participant is not enough. An attacker would need to compromise enough signing participants to reach the defined threshold. But cryptography alone is not governance. FROST can enforce that, for example, 3-of-5 cryptographic participants must cooperate. BlockSign adds the operational governance around it: who may initiate a transaction, who may approve it, which limits apply and which assets or addresses are permitted. With BlockSign, organizations can choose the key-management architecture that fits their security and governance requirements, including Shamir-based and FROST-based models. Shamir can reconstruct the secret. FROST creates the signature without reconstructing it during normal signing. In our next and final post in this series, we’ll put Shamir and FROST side by side and explain when the differences matter. Want to discuss which key-management architecture fits your digital asset operations? Talk to us. DM us.
Made with AI
2
8
384
YES YES YES …and f@&€ing YES! I got tickets for OASIS in Manchester! #Hyped @oasis
1
2
269
Happy Wochenende! Mir war das ganze gendern ziemlich egal, bis jetzt… Richtig gut übersetzt! So macht das Thema wieder Spaß!
1
2
217
Key Management Is Not Custody: Why the Architecture Matters A private key can control millions in digital assets. If access to those assets ultimately depends on one key, one person or one device, security becomes a single point of failure. The key can be lost or compromised. A keyholder can become unavailable. A device can fail. And even strong governance policies have limited value if one individual can technically bypass them. For institutional digital asset operations, protecting the key is therefore not enough. Control itself needs to be distributed. And this is important: distributed key management is not the same as custody. It is a technical architecture for determining how cryptographic control is distributed and how many participants are required to authorize an operation. Instead of giving one party unilateral control, cryptographic mechanisms can require multiple participants before assets can be moved. There are different ways to achieve this. Two important approaches are Shamir Secret Sharing and FROST threshold signatures. Both distribute control, but they do it in fundamentally different ways. Shamir distributes the secret. FROST distributes the signing process. In our next posts, we’ll explain both approaches and why the difference matters for institutional digital asset operations.
Custody vs. non-custody. BlockSign never has your keys. Governance is not custody. On the BlockSign platform, asset owners define and enforce who is allowed to do what: roles, approvals, limits and policies — while remaining in full control of their assets. For institutional and professional investors that require custody, optional custody is provided by our regulated custody partner @nbxcom. BlockSign cannot access, move or manage your funds. Never!
1
7
705
I came to Cardano to build. Then I discovered that building on Cardano also means living through its eras. 1. I ran a stake pool and watched blocks arrive. 2. I co-founded an NFT project and lived the NFT madness, watching our mint in real time with the team and wondering how fast 5,410 NFTs could disappear. 3. I worked on digital identity when blockchain identity was still a promise. 4. I helped build wallets. 5. I experimented with email communication on-chain. 6. I tokenized physical gold and silver and learned that putting a real-world asset on-chain is much easier than creating a real-world market for it. And today, I work on bringing digital assets, identity and verifiable authority into environments where institutions actually need them. Some things worked. Some failed. Some were simply too early. And some taught me that the hardest part of blockchain was never the blockchain. It was finding a problem worth solving. That’s what these years of Cardano mean to me. Nine years from now, I hope Cardano has become boring. Not because nothing is happening. But because nobody needs to talk about the blockchain anymore. Companies use it. Institutions rely on it. People interact with it without even knowing it’s underneath. The technology disappears. The utility remains. That would be success. I will be still here. Still building. Happy 9th birthday, @Cardano. #Cardano9
Nine years ago today, Cardano minted its first block. A global community has been building this blockchain ever since. Some are in this video, and many more are reading this. This celebration is yours. Happy 9th birthday, Cardano.
3
1
60
1,578
OGs doing OG stuff! Thanks guys! Awesome!
Cardanoscan is no longer the Cardanoscan you remember. That is not an easy sentence to write. We’ve moved beyond the old homepage. Today, we’re unveiling a redesigned Home Page with DeFi, chain stats, network activity, and more. New home. Same chain. cardanoscan.io/
11
226
I believe @Cardano_Prime represents an excellent initiative. We're successfully positioning Cardano's outstanding and unique technology for institutional and professional investors, while simultaneously onboarding new end-users to the ecosystem and toward Cardano's products. There's a wonderful German saying that captures this perfectly: "Problem erkannt, Problem gebannt", problem identified, problem solved. What Prime is doing is systematically identifying these problems, and I really respect that approach. It's what I call "brutal truth" and honestly, that's the only thing that will actually help us move forward. Without honest, unflinching analysis of where we stand, we can't build real solutions. That clarity is what we need. Time to move forward! With @BlockSign_io and our partner, we have identified exactly where the market needs innovation: institutional digital asset operations paired with flexible, customizable eSign solutions. That's our opportunity. #TrustLayer
The Cardano DeFi Ecosystem Audit is complete. 25 categories. Five scoring dimensions. Two reference ecosystems. It is the Phase 1 core deliverable of the @Cardano PRIME program, and it sets the baseline for everything that follows. Here is where Cardano stands.
5
1
30
918
Time to thrive not survive! Right with you @astroboysoup @alphagrowth1 gave most of us what we already knew, some have been grinding for over a year now, were currently at half a mill in Usdm deployed goto usdmdefi.com and join the fight for true commerce onchain @nbxcom @BlockSign_io @USDMOfficial @PlominLegacy @FluidTokens
Our ecosystem scored a 51.3 out of 100! That's bad, but you know what? We can fix it and be ready for the next wave. We know the problems and gaps now, so let's roll up our sleeves and get to work fixing them. @alphagrowth1 and @OrionFund will help turn the ship around.
6
28
1,638
A valid blockchain signature is not proof of business approval. The reported @Fetch_ai and @nunet_global incident raises an important question: Who can technically act and who is actually authorized to do so? Published reports describe FET being withdrawn from a token converter and unauthorized NTX being minted through a privileged account, involving approximately $2 million in reported token value. These reports do not establish a definitive root cause. The broader governance issue is clear: for a standard Ethereum account, possession of the private key enables signing. It does not demonstrate that an operation received the organization’s required business approvals. This distinction is central to @BlockSign_io Asset Operations. Asset combines policy-based approvals, action-specific requirements, transaction limits and audit logging. Business approval and cryptographic signing are treated as separate control layers—not as interchangeable concepts. For token converters and issuance systems, our recommended approach is to govern the actual privileged operations: releasing reserves, minting tokens and changing permissions. That scope must include off-chain authorization messages, not just outgoing transactions. A signed message can authorize an economically significant on-chain action. BlockSign Verify addresses the human-verification layer. Verify provides proof-of-human checks that can complement an appropriately integrated approval process. But human presence is not the same as corporate authority: a real person is not automatically an authorized decision-maker. For sensitive operations, our recommended design links a server-validated verification result to the authenticated, authorized approver and the exact instruction. The recipient, amount and action should be clear, and approval must not be reusable for a different operation. One condition is essential: the controls must govern the actual execution path. An unrestricted private key used outside the controlled workflow can bypass interface-based approvals. Effective protection therefore requires bringing signing authority into the controlled architecture—not merely adding another screen before a transaction. Our position is straightforward: Human verification. Independent approval. Controlled execution. Audit evidence across the workflow. Not a retrospective promise that one product would automatically have prevented this incident, but a design principle for institutional digital-asset operations. The question is not only “Who can sign?” It is “Who may authorize which operation, under what conditions?”
Made with AI
1
1
3
465
Congratulations!
Digital in. Cash out. NBX is now a registered MoneyGram agent, effective 4 Oct 2026. Once live: stablecoins pay out as cash across 200+ countries and 470,000+ locations. A regulated rail for remittance, aid and payroll.
1
5
170
European custody powerhouse incoming: Deutsche Bank 🇩🇪 partners with Austria's Bitpanda 🇦🇹 & Switzerland's Taurus 🇨🇭 to launch crypto custody in 2026. Bitcoin, Ethereum, stablecoins, secured & regulated under MiCA. While the US crypto framework remains fragmented across regulators, Europe is building institutional-grade infrastructure with clear rules. Global banks are watching. The regulatory divergence is real. Plus: Austria & Germany still offer favorable tax treatment on crypto held >1 year. Traditional finance is choosing Europe. That’s why we build @BlockSign_io
6
194
CLARITY Act fails Senate cloture. What this means: ✅ Stablecoin yields continue uninterrupted ✅ No DeFi developer liability rules ✅ Status quo regulatory patchwork remains The crypto market just dodged a bullet. What’s your take?
1
1
6
318
This is important for Cardano - Technically and commercially!
Cardano has a regulated-asset interoperability problem we need to solve. CIP-113 enables programmable assets. But if every regulated stablecoin comes with its own compliance and transaction logic, wallets, DEXs, exchanges, custodians and infrastructure providers may have to integrate each asset individually. That doesn’t scale. PR #1266 addresses this for regulated stablecoins by exploring a shared standard for capabilities such as mint/burn, freeze/seize, roles, key rotation, upgrades and redemption. But the underlying question goes beyond stablecoins. The same challenge will increasingly matter for RWAs, tokenized commodities, securities, funds and other regulated assets. If Cardano wants to become serious infrastructure for institutional assets, interoperability must be designed in from the beginning, not retrofitted later. PR #1266 is still a proposal. That makes NOW the right time to get involved. Builders. Issuers. Wallets. DeFi protocols. Custodians. Institutions. ➡️ Read it. Challenge it. Contribute. 👉 GitHub PR #1266: github.com/cardano-foundatio… This discussion could become very important for Cardano’s institutional future.
1
6
286
Deutsches Crypto Steuerrecht 🔍: Du verlierst den Seed zu einer Wallet mit Bitcoin im Wert von 250.000 €. Wirtschaftlicher Schaden: möglicherweise 250.000 €. Steuerlich ansetzbarer Verlust in Deutschland: unter Umständen 0 €. Warum? Bei privat gehaltenen Bitcoin gilt grundsätzlich § 23 EStG. Steuerlich relevant wird regelmäßig eine Veräußerung, also zum Beispiel: → Verkauf gegen Euro → Tausch gegen USD → Tausch gegen andere Kryptowerte Der bloße Verlust des Private Keys ist dagegen grundsätzlich weder Verkauf noch Tausch. Das heißt: 1. Hardware-Wallet verloren. 2. Seed nicht mehr auffindbar. 3. Keine Wiederherstellung möglich. Wirtschaftlich können die Bitcoin endgültig verloren sein. Steuerlich liegt dadurch aber nicht automatisch ein realisierter Verlust vor. Beispiel: Bitcoin ursprünglich für 25.000 € gekauft. Heutiger Wert: 250.000 €. Seed endgültig verloren. Wirtschaftlicher Verlust: bis zu 250.000 €. Steuerlich realisierter Verlust im Privatvermögen: grundsätzlich 0 €. Auch die ursprünglichen Anschaffungskosten von 25.000 € können allein wegen des verlorenen Zugangs nicht einfach als Verlust angesetzt werden. Und daraus entsteht auch kein automatischer Verlustausgleich mit Aktiengewinnen, Dividenden oder anderen Kapitaleinkünften. Hinzu kommt eine deutsche Besonderheit: Bei privaten Kryptowerten gilt grundsätzlich die Einjahresfrist. Wer Bitcoin länger als ein Jahr hält, kann Gewinne bei einer regulären Veräußerung grundsätzlich steuerfrei realisieren. Umgekehrt sind Verluste nach Ablauf dieser Frist regelmäßig ebenfalls steuerlich nicht nutzbar. Wird der Seed Jahre später doch wiedergefunden, entsteht dadurch grundsätzlich auch kein neuer Anschaffungszeitpunkt. Kein neuer Kauf. Keine neue Kostenbasis. Die ursprüngliche steuerliche Historie bleibt bestehen. Ganz anders kann die Situation bei Unternehmen aussehen. Liegen Bitcoin im Betriebsvermögen, gelten nicht einfach die privaten Regeln des § 23 EStG. Wenn eine GmbH oder ein gewerblicher Betrieb den Private Key nachweislich und endgültig verliert, stellt sich eine andere Frage: Ist das Wirtschaftsgut dauerhaft wertgemindert oder wirtschaftlich vollständig nicht mehr verwertbar? Dann können bilanziell Fragen wie → Wertberichtigung → Abschreibung → Ausbuchung relevant werden. Besonders spannend ist dabei die BFH-Logik zur wirtschaftlichen Verfügungsmacht: Wer den Private Key kontrolliert, kann tatsächlich über die Kryptowerte verfügen. Wenn dieser Schlüssel endgültig verloren geht, geht möglicherweise auch genau die wirtschaftliche Verfügungsmacht verloren, an die die steuerliche Zurechnung anknüpft. Das bedeutet aber nicht automatisch, dass dadurch im Privatvermögen ein Verlust nach § 23 EStG entsteht. Denn auch dann fehlt regelmäßig der notwendige Veräußerungsvorgang. Wer eine Wallet oder einen Seed verliert, sollte deshalb unbedingt dokumentieren: → Wallet-Adresse → Bestand → Anschaffungszeitpunkte → Anschaffungskosten → Transaktionshistorie → Zeitpunkt und Ursache des Verlusts → vorhandene Backups → technische Nachweise zur fehlenden Wiederherstellbarkeit Bei Unternehmen zusätzlich gegebenenfalls: → interne Incident-Dokumentation → technische Untersuchung → Nachweise zur Schlüsselverwaltung → Polizeianzeige bei Diebstahl Das Fazit: Privatvermögen: Ein wirtschaftlicher Totalverlust kann steuerlich trotzdem 0 € Verlust bedeuten. Betriebsvermögen: Derselbe technische Verlust kann sehr wohl bilanzielle und steuerliche Folgen haben. Und genau deshalb sollte man „Wallet verloren“ steuerlich niemals pauschal behandeln. Ein Thema das in der Zukunft immer wieder aufpoppen wird!
6
154