Case Study - Ankr: Secure key management for Ethereum liquid staking (2024)

To secure their validator setup, Ankr transitioned to the CubeSigner hardware-backed key management system. Stanley was initially interested in CubeSigner because it protects keys both at rest and during signing. In contrast, traditional remote signers like Web3Signer pull validator keys out of secure hardware—and potentially into an attacker’s clutches—with every single attestation.

CubeSigner onboarding included a key export ceremony to ensure that Ankr can recover keys at any time, without involving Cubist. First, Ankr stakeholders registered a set of secure hardware tokens to keep in the coldest of storage. Then, they did a test decryption, showing that the configured threshold of hardware tokens was sufficient for key recovery. Now, each time CubeSigner generates or imports a key, it securely encrypts that key to the hardware tokens so that Ankr stakeholders can recover it in an emergency. “So many vendors share key exports using zip files or other methods that don’t give me confidence that they don’t just have our keys lying around in plaintext,” noted Stanley. “With Cubist’s export protocol, our keys are encrypted to our own hardware tokens that are stored in different physical locations. It’s good to know the backups are safe, and are there if we need them.”

Once onboarding was complete, Stanley and his team used CubeSigner to generate new keys—and, since Ankr has thousands of existing validators, they also imported existing keys directly into CubeSigner’s secure hardware. Once the keys were safely ensconced within CubeSigner, no one—not Stanley, not his team, and certainly not Cubist—could directly access raw secrets. Instead, Stanley granted the team (and validator machines!) revocable privileges that allowed them to request signatures; in an emergency, Stanley could revoke those privileges to prevent the team and the infrastructure from signing anything at all.

Next, Stanley and his team used CubeSigner’s configurable policies to protect the different pieces of the staking workflow. CubeSigner implements automatic, global anti-slashing policies following EIP-3076. As a result, the system refuses to sign two conflicting messages, even if those messages come from completely different validator clients. Similarly, Stanley and his team used CubeSigner policies to protect their staking and unstaking workflows. They configured CubeSigner to only sign deposits on behalf of Ankr’s pre-generated validator keys, and limited the number of unstakes allowed per day.

Finally, Stanley’s team used CubeSigner’s EIP-3030 compatible sidecar with their existing validator setup; they also found deposits easier to automate thanks to CubeSigner’s built-in staking endpoint. Throughout the integration, the Cubist team gave tailored configuration and security guidance. “From day one to project completion, Cubist was able to anticipate Ankr’s needs, provide a clear project roadmap, and deliver their solution without hang-ups,” said Stanley. Before going live, Ankr also worked with Cubist’s preferred audit partner, Veridise, to audit their CubeSigner integration. Veridise’s deep understanding of the CubeSigner codebase gave Ankr additional confidence in the audit report.

Case Study - Ankr: Secure key management for Ethereum liquid staking (2024)
Top Articles
Can you Buy Ethereum on Cash App (2023) | Ethereum Guides | CryptoRank.io
4 Best Dirks: Modern Versions Of The Historic Knife
Mchoul Funeral Home Of Fishkill Inc. Services
#ridwork guides | fountainpenguin
Shoe Game Lit Svg
Practical Magic 123Movies
Derpixon Kemono
Savage X Fenty Wiki
12 Best Craigslist Apps for Android and iOS (2024)
Napa Autocare Locator
Northeastern Nupath
Www Craigslist Milwaukee Wi
Jalapeno Grill Ponca City Menu
Ibukunore
Accident On 215
Okc Body Rub
Accuweather Minneapolis Radar
Fiona Shaw on Ireland: ‘It is one of the most successful countries in the world. It wasn’t when I left it’
Tuw Academic Calendar
Bra Size Calculator & Conversion Chart: Measure Bust & Convert Sizes
Buhl Park Summer Concert Series 2023 Schedule
Joann Fabrics Lexington Sc
Cinema | Düsseldorfer Filmkunstkinos
Bj's Tires Near Me
Mawal Gameroom Download
Imagetrend Elite Delaware
Isablove
How often should you visit your Barber?
Mark Ronchetti Daughters
Alima Becker
Star News Mugshots
Missing 2023 Showtimes Near Mjr Southgate
Grand Teton Pellet Stove Control Board
World History Kazwire
Hebrew Bible: Torah, Prophets and Writings | My Jewish Learning
Überblick zum Barotrauma - Überblick zum Barotrauma - MSD Manual Profi-Ausgabe
South Bend Tribune Online
Gravel Racing
10 Rarest and Most Valuable Milk Glass Pieces: Value Guide
Emily Tosta Butt
Kutty Movie Net
Ghareeb Nawaz Texas Menu
M&T Bank
Iupui Course Search
Matt Brickman Wikipedia
Large Pawn Shops Near Me
Rise Meadville Reviews
Fredatmcd.read.inkling.com
Vcuapi
Jesus Calling Oct 6
Generator für Fantasie-Ortsnamen: Finden Sie den perfekten Namen
Códigos SWIFT/BIC para bancos de USA
Latest Posts
Article information

Author: Francesca Jacobs Ret

Last Updated:

Views: 5916

Rating: 4.8 / 5 (48 voted)

Reviews: 87% of readers found this page helpful

Author information

Name: Francesca Jacobs Ret

Birthday: 1996-12-09

Address: Apt. 141 1406 Mitch Summit, New Teganshire, UT 82655-0699

Phone: +2296092334654

Job: Technology Architect

Hobby: Snowboarding, Scouting, Foreign language learning, Dowsing, Baton twirling, Sculpting, Cabaret

Introduction: My name is Francesca Jacobs Ret, I am a innocent, super, beautiful, charming, lucky, gentle, clever person who loves writing and wants to share my knowledge and understanding with you.