6529 Profile picture
Mar 23 24 tweets 5 min read
1/ On dropping NFTs safely for your collectors

This is a thread for artists and developers who have existing collectors and want to give them something extra - a free NFT or preferential access to a new collection
2/ In this thread, I will propose best practices that:

✅Do not encourage bad safety habits in NFT security

and

✅ Do not annoy large collectors

Doing this is all upside, no downside for you, person issuing NFTs
3/ For those new around here, my long overview on NFT safety is here:

4/ For those more technically oriented, the elegant and long-term solution to the problem I am about to discuss is rights delegation embedded into NFTs/wallets.

But until we solve this problem in the future, we need to operate better in the present.

5/ There are broadly speaking three popular ways to give preferential access to NFTs to existing collectors.

a) Airdrop the NFT
b) Use the NFT as a mintpass
c) Use a snapshot of the wallet as a mintpass
6/ Airdrop

In airdrops, you send the NFT to the wallet of people who have your existing collection.

While generally it is bad form to airdrop random things into people's wallets, it is not necessarily so with your existing collectors
7/ For smaller collections (e.g. 1 of 1 artists), you might even manually check with all your collectors if they want the airdrop.

For larger collections, it is a judgement call.

Generally people will be OK with it, if they are already a collector.
8/ This is an awesome outcome for a collector because you don't have to do anything and time is the most precious thing!

Don't have to find your hardware wallet, don't have to carefully check if you are minting on the right site, don't have to de-cold storage multi-sigs.
9/ For the artist, it can be a bit of a logistical nuisance and you have to pay the gas fees, but depending on the situation, you may consider it a cost of doing business.
10/ The second model is using the existing NFT itself as a mintpass.

This can be done more or less safely for the collector by moving the NFT to an empty address and then minting from that address.

That way, the worst case is that you lose 1 NFT, not your whole wallet
11/ "But wait 6529, I don't plan to rug my collectors"

Sure, but things happen - maybe your contractor goes rogue and injects malicious code in your site.

If everyone mints from their wallet on every new contract, eventually one of them will be a rug.
12/ While this can be acceptable safety-wise for collector, the collector may have to pay gas 4 times (move to tx wallet, move back, move new NFT to archival, mint NFT).

Even worse, if you are in a multi-sig, this may require pulling keys out of cold storage.
13/ I have skipped multiple mints like this because it was just not worth it to go through the aggravation of moving something out of the multi-sig.

It has to be valuable and I and others need to be in the right places for this to be doable
14/ Also, if you are going to do this, put LONG deadlines or no deadlines at all.

Nobody should be traveling with the keys to their archival wallets so, if there is a 2 week deadline for example, it is easy to miss the window to mint.
15/ There is a nuance of this model which is "sell a mintpass" or "grant/airdrop a mintpass" that is separate from the NFT artwork

In other words, instead of having to mint with an @lphaCentauriKid 1 of 1, mint with a mintpass airdropped to ACK 1 of 1 collectors
16/ This is a lower risk model for me.

I would be comfortable keeping a mintpass in a single signature hardware wallet, while I would not feel comfortable keeping my ACK 1 of 1s in anything less than a multi-sig.

And if a collector sells their mintpass, so be it IMHO
17/ The worst model is using a "wallet snapshot" as a mintpass.

This checks which wallet held a specific NFT on a specific day and allows only them to mint.

This is basically a disaster security wise for any high quality NFTs.
18/ It is logical to believe that people keep their best NFTs in their most secure wallet/address.

If you snapshot that address, you are asking (training) them to connect their prized wallet to random contracts.

This is a very bad habit and, as a field, we should stop it
19/ I think it is fair to say that 6529 Museum and 6529 Capital will almost certainly not participate going forward in any drops done in this model.

Our core NFTs are all in multi-sigs and we are generally not willing to connect that multi-sig to new untrusted contracts.
20/ I have no interest in auditing the contract, in trying to figure out how it works and so on.

Life is short, I am busy and also I am not taking on the responsibility of being sure a contract is safe.

Computer security and bugs are HARD!
21/ So, to recap-the most elegant solution is rights delegation so, say, The Tulip sits in a wallet that never acts, but either the NFT or the wallet delegates minting or airdrops to a transaction wallet.

We need to get there to have composability & safety.

And we will.
22/ Until then though, here is my tl;dr

Best Choices For Safety (collector dynamics to consider)
✅Airdrops
✅Mintpasses separate from the art NFTs

Acceptable For Safety (a bit inconvenient)
✅The art NFTs as mintpasses

Unacceptable For Safety
✅Wallet snapshots as mintpasses
23/ I hope this makes sense to everyone.

Let's see if we can work together to make NFT land a bit safer, while we work on better UX models for wallets

🤝🚀🥷
24/ If this is your first time here, we fight for an open metaverse running on decentralized rails.

Many more tweetstorms are here

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with 6529

6529 Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @punk6529

Mar 23
1/ Every time I post "get a hardware wallet", 10 people reply "but this does not protect you from signing approvals to scam sites"

This is of course true but a completely separate topic

The purpose of a HW is to protect you from malicious software on your PC, not from yourself
2/ To protect yourself from yourself, you should either:

a) not go around signing transactions on unknown sites that you found in Discord

or

b) if you really must, do it from a burner address without a lot of NFTs in it
3/ But how do I mint my Mutant Apes (or whatever) w a mintpass

Move your mintpass (NFT) to an address without anything else in there and mint from there

That way, you can, at most, lost that NFT

The major projects have never rugged, just make sure you are on the right site
Read 5 tweets
Mar 23
[Fill in the blank]

"In the metaverse..."
[Fill in the blank]

"In the future..."
[Fill in the blank]

"We will seize..."
Read 5 tweets
Mar 22
Been kindof obsessed for months with these Image
Another one Image
Also, another one Image
Read 4 tweets
Mar 21
Well done @emilyxxie 👏👏👏 Image
Also Image
Also Image
Read 4 tweets
Mar 15
1/ So check out the @CozomoMedici thread below for an interesting example of how the golden age of "enlightened" punk management of, checks notes, 3 days ago, was mostly projection by punks holders, not reality

Part 1:
Read 7 tweets
Mar 12
1/ On Punks and Yuga

I have slept on it and my conclusions are were they were last night.

Going put to put them down for the historical record and we will see, in a 1 month, in a year, in a decade, how they age
2/ First some background (OGs can skip the next couple of tweets)

@larvalabs created the CryptoPunks, the Meebits and the Autoglyphs

The licensing regime to holders was basically non commercial use only, with very limited rights as noted below
3/ The rights to Meebits holders (and assumed to punk holders too) were:

✅Up to $100K per year
✅No digital collaboration (physical goods only)
✅No brand collaborations

They are, for an NFT, basically useless rights. Literally, you can make a hat.

meebits.larvalabs.com/meebits/termsa…
Read 63 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us on Twitter!

:(