This Week in Custody #44
This Week in Custody is a newsletter covering technical and narrative developments in digital asset custody written for wallet engineers, digital asset operators, and security engineers.
Last Week’s Most Clicked
Nasdaq is working on custody for institutional clients.
Paradigm covers the recent hardware trends in the zkp space.
News
MPCH announces a recent fundraising round to build MPC wallets.
Gemini partners with Betterment.
Anchorage announces partnership with Aptos.
Robinhood debuts its non-custodial wallet.
Coinbase Cloud launches Node.
Stripe supports USDC payouts.
Tornado Cash is back on GitHub as a public archive.
Circle partners with Robinhood to support USDC.
Blowfish fundraising announcement. They are building a system to detect malicious transactions in real time.
MetaMask launches a portfolio application.
Telegram launches a P2P exchange with its @wallet bot.
Binance accounting error causes windfall for Helium holders.
Networks
The Zcash network is still being spammed from an actor broadcasting transactions containing large numbers of shielded outputs in each block. A cost estimate of the spam attack is $10/day.
Guides
Aleo Workshop is a guide for building applications on Aleo.
Applying “valves” to understanding flow control in Lightning Network.
The differences in smart contract development between Move and Rust.
Codex32 is an error-correcting code that can be computed without the use of electronic computers.
Fuzzing smart contracts.
BlockSec covers replay attacks happening on EthPoW.
Consensys covers IPFS vulnerabilities.
Vitalik on what a “Layer 3” might look like.
Tools & Software
Lightning Labs announces the alpha release of Taro.
BlockSec releases Phalcon: a transaction explorer for DeFi.
Trezor Suite adds coin control for Bitcoin.
A new tool for estimating the ABI for unverified contracts on Ethereum.
Flashbots has a new MEV-boost Dashboard.
Mockthereum: a new Ethereum mock node.
Zero knowledge modules in Rust to manage, compute and verify RLN zkSNARK proofs and RLN primitives.
Cryptography
Practically-exploitable Cryptographic Vulnerabilities in Matrix
Tweet thread on threat models against MPC & TSS.
Security
A set of recent dYdX npm packages are compromised.
The story of how a large sum of Bitcoin was stolen from the US government.
Purism introduces PureBoot Basic.
Releases
[Cosmos SDK] v0.46.2
[Algorand] Algorand 3.10.0
[Solana] Mainnet - v1.10.40
[Avalanche] Banff - Elastic Subnets
[Osmosis] Osmosis v12.1.0
Thanks for reading. Have a great weekend!