The Twitter space delved into the realm of crypto wallet security, shedding light on the guardian system and the imperative of safeguarding private keys. Discussions elaborated on the dual public key setup for verification purposes and the involvement of trusted cosigners in off-chain interactions. Emphasis was placed on the significance of on-chain security measures in handling transactions and managing guardian states efficiently. The discourse also touched upon the prevalent risks posed by hackers and scammers in the crypto space, advocating for collaborative efforts towards bolstering security. Varied perspectives on web3 compromises and the mitigation of social engineering threats were key topics of consideration, underscoring the paramount importance of vigilance in combating malicious activities.


Q: What was the main focus of the discussion?
A: The main focus was on crypto wallet security and the guardian system.

Q: How does the guardian system work in terms of public keys?
A: The guardian system involves two public keys for different verification purposes.

Q: What off-chain interactions are involved in guardians with trusted cosigners?
A: Off-chain interactions include providing two-factor codes for transaction cosigning.

Q: Why is on-chain security important in transaction handling?
A: On-chain security is crucial for managing transactions and guardian activation.

Q: How are guardian public keys stored to handle different states?
A: Guardian public keys are stored on-chain to manage various guardian states effectively.

Q: What is the significance of an on-chain security approach?
A: The on-chain approach enhances security measures and safeguards transactions.

Q: What risks were highlighted regarding hackers and scammers?
A: Potential risks from malicious actors in the crypto space were acknowledged.

Q: What collaborative efforts were emphasized for space protection?
A: Collaborative efforts for improving security and defending against malicious actors were underscored.

Q: What opinions were discussed regarding web3 compromises?
A: Varied opinions were addressed, focusing on mitigating social engineering and phishing threats.

Q: How were social engineering threats exemplified in the discussion?
A: Social engineering threats, such as misleading DMs leading to compromised links, were highlighted.


Time: 00:00:43
Introduction to the Space Discussion

Time: 00:05:47
Discussing Free Speech on Social Media

Time: 00:08:44
Impact of Global Events on Personal Views

Time: 00:10:34
Technological Influences in Modern Communication

Time: 00:11:37
Personal Stories and Broader Social Issues

Time: 00:12:38
Debating Online Moderation and Free Speech

Time: 00:13:08
Transparency and Governance Concerns

Time: 00:13:49
Comparing Historical Events to Present Tensions

Time: 00:14:35
Role of Big Tech in Modern Discourse

Time: 00:15:57
Justice System Narratives and Public Reaction

Time: 00:16:46
Conclusion and Final Thoughts

Key Takeaways

  • The discussion focused on the security aspects of crypto wallets
  • emphasizing the need for robust protection of private keys.
  • A guardian system was explained
  • where two public keys serve different verification purposes.
  • Guardians with trusted cosigners involve off-chain interactions
  • like providing two-factor codes for transaction cosigning.
  • The importance of on-chain security in handling transactions and guardian activation was highlighted.
  • The significance of storing guardian public keys on-chain to manage different guardian states was discussed.
  • The strength of the on-chain approach for security measures was emphasized.
  • The potential risks posed by hackers and scammers in the crypto space were acknowledged.
  • The importance of collaborative efforts in improving security and countering malicious actors was underscored.
  • Varied opinions on web3 compromises were addressed
  • focusing on mitigating social engineering and phishing threats.
  • Social engineering threats
  • like misleading DMs leading to compromised links
  • were highlighted.

Behind the Mic

It. Thank you everyone for coming and joining us today. It's a pleasure. I'm going to let Ernesto take the mic, he's set up some crates and has some cool things to share. Ernesto, you there? Yes, hey everyone. All right, we have a little bit of a delay, it seems, and maybe somebody wants to start? Sure, we can start. I'm going to just walk through the issue real quick. So the primary article, actually I'll just start with the question of the article, is who is responsible for holding our private keys? Raise your hand if you have ever shared your private key with anyone. Your seed phrase, no matter how well trusted they are. Don't worry, we all get scammed. We all make mistakes, but still, has anyone ever shared their private key? I'd hope to see no hands raised. OK, good. So with this article, it really brings to mind, right? The importance of what Ernesto is sharing with all of us and all the cool tech going on with Guardian. Safe and the Elrond tech. Elrond, Multiverse X. Things like that to help solve these big problems. Go ahead, keep it going. Awesome, thanks Andre. So I mean, fundamentally there's a ton of different solutions in place, right, in the market currently. While I admit that we are probably all aware that Elrond stands out, that's not to say we're unaware of the hurdles faced by the other chains and platforms as well. So Ernesto's coming on stage, Ernesto. Give us just a bit of background on you and what you're working on. Hey, thanks Andre, thanks for the introduction. Yeah, I just don't know if I'm coming through clearly or not, but I joined earlier this year. I'm a senior product manager at Arda Labs and have been working with the engineering team. It we're merging some security solutions. I'm constantly in talks with various solution providers, seeing what we can do together to advance the industry. Some things are more public, some are currently under NDA, but we strive to make things secure for everyone, honestly. Great, great. How about Andre, you share in more detail on that point? Definitely no problem. In this space, of course there's different ways to tackle key management. We see the rise of NPC custody solutions as well as wallet based solutions. And then there is an hybrid approach like Ernesto mentioned. An MPC, multi-party computation, you don't just give your key and your key never leaves your hands. That's one approach that Guardian uses in conjunction with Multiverse X. But also on the wallet side, you have the likes of Ledger or Trevor allowing transactions to be safely signed. But when it comes to MPC solutions like Guardian, once a threshold is met, the key signing can happen off-chain. But yeah, there's a lot going on. Agree with the MPC angle. Guardian has made strides here and we've combined our technology with some patenting Mitra technology. Very glad you mentioned front-running and sandwich attacks. We're doing some interesting things in that spot. Andre, please continue, and thanks for this perspective. Sure thing. You know, Ernesto, many have been bit by fatal hacks. Security can't be understatement in this space. By the way, mention of hacks made me think of Wildgar and Dan. Mm-hm? Message to you, sir? I'm here. I'm up on stage. Alright. I've heard such amazing things about Wildgar, not only from Andre but from the community as well. How are we keeping people's wallets safe? Thanks, thanks for having me, really an honor to be here. So yeah, with Wildgar, we're striving to move towards secure, no third-party, non-custodial solution. When I say non-custodial, it means users have full control of their private keys at all times with proper on-chain functionalities. I wanted to address this comment real quick and then return to current efforts. User Dave asked in the chat why Guardian wouldn't just use their private key? And the answer being, we don't have access. We design for privacy, autonomy, and security. Can I comment there too, Wildgar? Go ahead. We need to emphasize the importance of hardware solutions as well. Think of Ledger, Trezor. Not your keys, not your crypto. I agree, 100%. We've aligned ourselves with those principles. If we could inject a little humor, Andre, you there? Ha-ha, always. The age-old saga of slap a hardware wallet on a post-it note, right? Never goes out of style. OK, back to Wildgar. User Dave mentions that in Guardian, signatures trigger directly and some transactions propagate, correct? Yeah, thank you, Andre. For clarity, essentially two public keys exist, one guardian and one user. These hierarchical guarantees styled overseer guardian layer functions have kept attacks at bay. Let me recap briefly. We'll make sure to integrate, of course. Go ahead. Was going to elaborate on the mitigation of attacks, scenarios of minimal off-chain dependency. Because for complex mechanisms like call centers validating codes, it's vital the back-end secure network manages and verifies trust in real-time. User keys directly interact and apply trusting cryptography methods. The one public key is your address. The other public key is the public key used to verify the Guardian signature. The other guardian, the normal guardian, the one with the trusted cosigner, is like 99% on chain. The only off chain part is where you go to the trusted call center, give him the two factor code and say, hey, yes, this is me, and now go cosign my transaction phase. And the only off chain part here is the fact that you send the code to the trusted cosigner and if the code is valid, if the trusted cosigner says yep, that code is the same code I have generated right now, then it will go ahead and cosign your transaction. The actual guardian stuff again here is the same the account of the trusted cosigner will go ahead and cosign the transaction. The transaction, how transactions work have actually been changed to work like this. And the accounts themselves have been adapted to enable the guardians to be able to store the public key of the guardian to handle the different states a guardian can be in, because when you first create the guardian you have to wait 20 days before it activates and so forth. This is all 100% on chain. There is no bit that is wallet based. This is 100% on chain and this is what makes it so strong. Anyone? Yeah, Wildgar can chime in anytime. There's honestly no reason to have wallet-based signatures inherently, especially with the flexibility provided by a protocol integrated key management system. I want to underscore this. All this key aliasing ardently enforced on flagging, Wildgar ensures no single operator can control on three axes layered systems. We've done analysis in detail in the community GitBook within dedicated sections. Similarly, Andre, elaborate your proven mode facts? Definitely exploring codes and persistence angles balancing emphasizing protocols enrich the setups along application layers will be secure. Yeah, absolutely critical to ensure every line of defense is optimized. Thank you Andre. Thrilled to highlight key integrity when developing security measures. Wildgar, follow up? Has everyone heard about key rotation handling? Anyone curious? Key rotation became streamlined because signatures can evolve given entropy worsens with hardware lifecycle, valid Troy Co. Cosign approaches. See, the guardian after a 24 cycle renewal makes new signatures aptible to avoid complexity in user experience. Ernesto leaned into detailing earlier community involvements. Andre, please discuss viability checks here relevant? Sure, developing front-line resistance tactics pertinent illustrates network robustness. So quick follow up Ernesto's contribution. Getting feedback from community inputs for our lifecycle helps. Absolutely pivotal. 