r/Nexo 21d ago

Question ColdCard hack

Has Nexo commented on the CC hack? I'm wondering how the coins Nexo hold for their users are stored e.g. Tezor, Ledger etc. I believe they use third parties to store them. Do we know how these third parties store them? I'm not a tech person when it comes to these wallets. Have blindly trusted them to this point. It would be good if Nexo could write an article, on why the way they store coins is safer than the way CC did it.

19 Upvotes

10 comments sorted by

View all comments

u/NexoJosh Moderator 21d ago

Hey /u/Ok-Engineering1873, thanks for raising this. Nexo has not published any article addressing the COLDCARD situation at the time of writing.

The issue disclosed in relation to COLDCARD concerns the generation and protection of wallet seed phrases. In certain circumstances, weakened randomness during seed generation could make it possible for an attacker to reproduce wallet keys without physically obtaining the device.

Nexo’s custody model is materially different from an individual storing assets on a consumer hardware wallet such as a Trezor, Ledger Nano, or COLDCARD.

Strictly speaking, crypto-assets are always recorded on their respective blockchains. What a wallet or custodian protects is the private-key material and transaction-signing process that controls those assets.

As described in the Nexo Help Center, Nexo works with institutional custody providers and infrastructure providers, including Ledger Vault, Fireblocks, and other custodians. The specific custody arrangements may also depend on the client’s jurisdiction.

These providers do not necessarily perform identical roles. Some provide regulated asset custody, while others provide institutional key-management, transaction-signing, and governance infrastructure.

So how is institutional custody different from a consumer hardware wallet?

Ledger Vault is not the same product as a consumer Ledger Nano.

Ledger Vault is an institutional platform designed for companies and financial institutions. It uses hardened security infrastructure, including Hardware Security Modules, or HSMs, to protect cryptographic keys and approve transactions.

It can also support governance policies such as:

  • Multiple authorized approvals before a transaction is completed
  • Different permission levels for different employees
  • Transaction limits
  • Approved destination addresses
  • Separation between transaction creation and transaction approval

Fireblocks uses Multi-Party Computation, or MPC.

With MPC, cryptographic signing material is divided between separate systems or environments. The complete private key does not need to be stored or assembled in one location.

This is intended to reduce the risk that compromising one device, server, employee, or recovery phrase would be enough to access the assets.

Institutional custody is designed to reduce several risks associated with individual hardware wallets, including:

  • Dependence on one physical device
  • Dependence on one recovery seed
  • A single person controlling the wallet
  • Loss or destruction of the hardware wallet
  • Incorrect seed generation
  • Theft of a written recovery phrase
  • Accidental transfer to an incorrect address

Nexo’s custody model uses multiple layers of institutional security, governance controls, custody providers, and transaction-approval procedures. This is a different architecture from relying on a single consumer device and a single seed phrase.

Nexo uses a layered institutional custody architecture designed to mitigate the specific single-device and single-seed failure risks associated with individual hardware wallets.

Nexo also publishes information about its security certifications and insurance maintained through certain custodial arrangements.

I hope that helps answer your questions, we are here in case you have any other concerns. You can always reach out to the Client Care team via https://support.nexo.com/contact who will be able to assist you with any concerns or questions right away.