Nass Eddequiouaq Profile picture
wallet security and regulatory compliance @BastionPlatform - prev. CISO @a16z crypto
May 8 21 tweets 4 min read
Vitalik just proposed EIP-7702 which directly impacts every wallet and EOA. Let's take a deep dive into the technical aspects of EIP-7702 and examine its implications, with a focus on costs, trust assumptions, and flexibility. 🧵

1/21 Image EIP-7702 introduces a new transaction type that temporarily sets an EOA's code to a contract code for the duration of the transaction execution. This aims to provide functionality similar to EIP-3074 but in a more forward-compatible manner.

2/21
Nov 13, 2022 9 tweets 2 min read
Really dangerous & deceptive marketing tactics out there on MPC-based key management solutions. Several companies pretend that "there's no private key" when using MPC.. 😖 Quite a few folks reached out to confirm so I'm taking some time to rebute all this: 1) This is obviously *FALSE* and is meant to make users feel like the danger suddenly evaporates. MPC key shares *ARE* cryptographic secrets that should be generated & stored securely in dedicated..
Nov 12, 2022 4 tweets 1 min read
Spitballing here but typically the source of these FTX withdraws can be:

1) direct raw key access (no idea how these were stored, this shouldn't be possible but given the behaviors from the team, I wouldn't bet on a secure setup 2) permissioned access to key management services

In that case, someone either had or gained access to a service that had the ability to move funds. That could be done easily by internal folks (probably it given the timing) or a more established organization.