log
- 009
2026-09-10
FIPS 140-2 vs 140-3: what actually changed
A FIPS 140-2 certificate issued on 31 July 2026 expires on 21 September. What 140-3 changed on paper, and what 778 certificates say changed in practice.
- 008
2026-09-01
FIPS 140-3 levels 1 to 4: what each level actually requires
Level 1 is software, Level 3 is the HSM tier, Level 4 is empty: none of 773 FIPS 140-3 certificates as of September 2026. What each level actually requires.
- 007
2026-08-19
The ECDSA tax: a field guide to threshold signing
Every MPC wallet pays a price set by one line of algebra. GG18/GG20, CGGMP, DKLs and FROST: who ships them, who audited what, which broke. Benchmarked.
- 006
2026-08-15
The key that never exists: a threshold signing ceremony in your browser interactive
Three keyholders run a real 2-of-3 key generation and FROST signing session on this page, every message shown byte for byte. Zig to WebAssembly, no server.
- 005
2026-08-05
FIPS 140-3 is not a security guarantee, and auditors know it
Validated modules shipped ROCA, EUCLEAK and a YubiKey flaw caused by FIPS self-tests. What the certificate attests, what FIPS mode costs, where auditors look.
- 004
2026-08-02
Coldcard's seed bug: the right RNG was in every binary, never called
A five-year Coldcard firmware bug cut seed entropy from 128 bits to about 40. Why no audit could catch it afterwards, and what it means for anyone making keys.
- 003
2026-06-12
Fireblocks Recovery Utility: what verify mode actually checks
I read the verify path in both Fireblocks recovery tools. What a Verified! line proves about your backup, and the three things it takes on trust.
- 002
2026-06-05
What a DORA reviewer wants in a custody exit plan
DORA Article 28(8) wants a documented, tested exit plan for every critical ICT provider. For MPC custody the exit is signing capability, not data.
- 001
2026-05-29
A custody recovery drill that never exposes a key
A recovery drill for MPC custody produces four numbers and a deviation log, and touches no private key. Most of what it finds is not cryptography.