Close Menu
    • Digital Transformation
    • Open Banking
    • Funding
    • Remittance
    • Regtech
    • Hong Kong Fintech Report
    • HK Fintech Startup Listing
    • China
    • Taiwan
    • Submit Press Release
    Facebook LinkedIn X (Twitter) YouTube RSS
    • About
      • About Fintech News Network
      • Contact Us
      • Work With Us
    • FNN Media Kit
    • Fintech Newsletter
    • Submit Press Release
    • Submit
      • Submit Press Release
      • Submit Startup
      • Webinar Inquiry APAC
    • HK Fintech Startup Directory
    Fintech Hong Kong
    part of Fintech News Network

    Fintech News Network

    LinkedIn Facebook X (Twitter) Instagram YouTube TikTok RSS
    Free Newsletter
    • Payments
    • Blockchain
    • Wealthtech
    • Virtual Banking
    • InsurTech
    • Lending
    • Report
    • Fintech Events
    Fintech Hong Kong

    Fintech News Network

    Home»Security»Building Trust in Digital Asset Infrastructure with Hardware Roots of Trust
    Security Sponsored Post

    Building Trust in Digital Asset Infrastructure with Hardware Roots of Trust

    Richard Chiu from Thales notes that most breaches originate from compromised private keys rather than blockchain flaws, making hardware-backed Security essential.
    Izzat Najmi AbdullahIzzat Najmi AbdullahMarch 24, 20267 Mins Read
    LinkedIn Facebook Twitter Telegram Copy Link Email
    Share
    LinkedIn Facebook Twitter Telegram Copy Link Email
    Free Newsletter

    Get the hottest Fintech Hong Kong News once a month in your Inbox

    Digital assets were designed around decentralisation, yet the responsibility for securing them increasingly sits with institutions.

    Banks, fintechs, and specialised platforms now safeguard billions of dollars in cryptocurrencies, stablecoins, and tokenised assets on behalf of customers.

    As digital asset markets mature, conversation is shifting from innovation to infrastructure, and, more importantly, security.

    Yet the biggest risks rarely originate from the blockchain itself.

    Most major breaches stem not from flaws in blockchain protocols but from the surrounding infrastructure, particularly the systems responsible for managing private keys.

    Recent data illustrate the scale of the problem.

    According to Chainalysis, more than US$2.2 billion worth of cryptocurrency was stolen through hacks in 2024, a 21% increase from the previous year.

    Nearly 44% of those losses were linked to compromised private keys, making it the single largest attack vector in the industry.

    The trend continued into 2025.

    By mid-year, more than US$2.17 billion had already been stolen from crypto services, much of it tied to compromised wallets and infrastructure attacks.

    A separate analysis from CertiK found that US$1.71 billion in losses during the first half of 2025 resulted from wallet compromises.

    The reason is simple. In digital asset finance, the private key is the ultimate credential.

    Whoever controls the key controls the asset.

    As institutions increasingly hold those keys on behalf of clients, protecting them has become one of the most critical challenges in digital asset security.

    When the Weakest Link Is the Private Key

    Many high-profile crypto thefts share a common pattern.

    Attackers rarely break the blockchain itself. Instead, they gain access to the private keys that unlock them.

    Industry reports estimate that nearly half of digital asset losses are linked to private key compromises or insider threats, elevating key management from a technical concern to a board-level issue for financial institutions.

    Richard Chiu, Head of Sales Engineering (Hong Kong and Taiwan) at Thales, says the core problem often lies in where keys are stored and managed.

    Richard Chiu
    Richard Chiu

    “Nearly half of all digital asset losses result from private-key compromise or insider threats. A hardware root of trust moves the security boundary from vulnerable human-operated software to a hardened cryptographic environment where keys never exist in clear form.”

    Software-based environments remain exposed to common attack paths, including phishing, privilege abuse, and insider threats.

    Moving key operations into dedicated hardware changes that boundary entirely.

    Hardware Security Modules (HSMs) generate and store cryptographic keys within tamper-resistant hardware, ensuring they never appear in plain form outside the device.

    Richard says the design also addresses insider threats.

    “In the HSM environment, it mitigates insider threats through rigorous physical controls that offer a high standard of data access governance as well as multi-layer authentication.”

    Establishing a Hardware Root of Trust

    Institutional security rarely relies on a single control. Strong custody infrastructure combines multiple safeguards designed to eliminate single points of failure.

    HSM-based systems allow organisations to enforce strict governance over sensitive operations such as transaction signing or policy changes.

    Critical actions may adopt quorum-based authentication, meaning multiple authorised personnel must approve a request before it proceeds.

    “No single administrator can execute a critical operation. It requires a predefined quorum of personnel to proceed with the operation, with identity authenticated and authorized,” Richard explains.

    Some environments also require physical authentication devices, such as PED keys connected to dedicated PIN entry devices. These tokens provide an additional safeguard against stolen credentials.

    Together, these mechanisms shift trust away from passwords and administrative privileges toward hardware-enforced security policies.

    MPC Alone May Not Be Enough

    While hardware-based controls form the foundation of many custody architectures, institutions are also exploring additional cryptographic safeguards.

    Multi-Party Computation (MPC) has become one of the most widely discussed technologies in digital asset custody. By distributing key shares across multiple systems, MPC reduces the risk of a single point of compromise.

    However, purely software-based implementation introduces new operational concerns.

    “MPC in a purely software environment results in fragmented accountability. While mathematically sound, software-based MPC shares are still hosted on vulnerable servers and lack a verifiable audit trail.”

    Combining MPC with HSM infrastructure introduces a hardware-backed layer of assurance. Key shares anchored in HSMs benefit from secure storage, hardware isolation, and an auditable signing process, together with temper detection and resistance.

    “HSMs serve as the trusted foundation that transforms MPC into a tangible security standard capable of meeting the high-assurance expectations of regulators.”

    This hybrid approach allows institutions to maintain flexibility while meeting stricter expectations around governance and accountability.

    Security at the Speed of Modern Finance

    Beyond security architecture, digital asset infrastructure must also keep pace with the development of modern financial systems.

    Emerging use cases, including tokenised deposits, blockchain settlement networks, and digital securities now require ever-faster transaction processing than traditional custody models were designed to handle.

    Speed.

    Financial institutions must now maintain strict security controls while enabling near-instant transaction execution.

    “Authorised institutions can scale-out with performance demand by high-availability architectures using HSMs with load balancing and hardware-enforced partitioning,” Richard says.

    Even as transaction volumes rise, private keys remain confined within FIPS-certified tamper-resistant hardware, preserving security guarantees.

    Preparing for the Quantum Era

    Security planning is also beginning to consider longer-term threats.

    One growing concern is the “Harvest Now, Decrypt Later” scenario, where attackers collect encrypted data today in hopes of decrypting it once quantum computing becomes viable.

    Richard believes institutions managing long-term financial assets must prepare early.

    “With 61% of organisations citing ‘Harvest Now, Decrypt Later’ as a leading threat, any institution managing long-life assets has a fiduciary duty to protect that data against future quantum decryption.”

    The industry’s response lies in Post-Quantum Cryptography (PQC), a new set of algorithms designed to resist quantum attacks.

    HSM platforms that support PQC provide the cryptographic agility needed to introduce quantum-resistant signatures without replacing existing hardware.

    Early preparation helps ensure assets issued today remain secure in the future.

    The Convergence of Crypto and Banking Infrastructure

    As digital assets integrate with mainstream finance, the line between traditional banking systems and blockchain infrastructure continues to blur.

    Capabilities once considered specialised are increasingly becoming part of the core security stack used by financial institutions.

    Richard says the shift is already visible.

    “The convergence is already an operational reality. Blockchain-specific capabilities such as BIP32, SLIP-010, and support for curves like Ed25519 have transitioned from niche requirements to standard features in our HSMs.”

    Whether processing traditional payments, tokenised deposits, or stablecoins, the underlying requirement remains the same.

    Everyone needs to start protecting cryptographic keys.

    Hardware-based key protection therefore serves as a common security foundation for both conventional and blockchain-based financial systems.

    Protecting the Infrastructure Behind Digital Value

    Digital assets are steadily evolving from experimental technology into regulated financial infrastructure.

    Banks, fintech firms, and digital asset platforms now face the same challenge: safeguarding the keys that control billions of dollars in digital value.

    The focus has shifted from questioning whether digital assets should be part of financial services to figuring out how institutions can protect them efficiently on a larger scale.

    Solutions such as Thales Luna HSM aim to provide that foundation by combining tamper-resistant hardware, policy-driven transaction controls, and support for emerging cryptographic standards.

    In a financial system powered by cryptography, the private key remains the ultimate gatekeeper.

    Get it right, and the system works.

    Get it wrong, and the headlines write themselves.

    Featured image: Edited by Fintech News Hong Kong based on an image by Juan J. J. Labrador via Freepik.

    Thales
    Share. LinkedIn Facebook Twitter Telegram Copy Link Email

    Author

    Izzat Najmi
    Izzat Najmi Abdullah

    Izzat Najmi is a Senior Writer for Fintech News Hong Kong.

    Related Posts

    SFC Requires Brokers and Crypto Platforms to Stop Using OTPs for Client Login

    July 10, 2026

    LexisNexis Risk Solutions and Promon Partner to Strengthen Mobile Fraud Prevention

    June 30, 2026

    4 Ways Hong Kong Banks Fight Financial Crime Using AI, According to HKMA

    June 25, 2026

    Can You Trust AI Agents to Stay Within Your Intent?

    June 18, 2026

    The Psychology of Market Panics: How to Ride the Waves of the Fear and Greed Index

    June 16, 2026

    Why HSMs Are Becoming Essential for Digital Asset Key Security

    June 11, 2026

    Surging AI Fraud and Digital Scams Are Reshaping Consumer Behaviour Across APAC

    June 3, 2026

    Hong Kong Banks Urged to Upgrade Defenses for AI-Driven Cyberattacks

    June 3, 2026
    AIPayments

    Can You Trust AI Agents to Stay Within Your Intent?

    June 18, 2026
    Fintech Hong Kong Newsletter
    Subscribe to the most important Fintech Hong Kong News
    Follow Us
    • LinkedIn
    • Facebook
    • X / Twitter
    • Instagram
    • YouTube
    • TikTok
    Security Sponsored

    Surging AI Fraud and Digital Scams Are Reshaping Consumer Behaviour Across APAC

    Fintech News Hong KongJune 3, 2026
    Featured Fintech Webinar

    Featured Fintech Report

    Sumsub APAC Fraud Report

    Featured Fintech Whitepaper

    Digital-First by Design: How Asia is Redefining the Future of Payments

    Featured Fintech Programme

    Global FastTrack

    Featured Fintech Event

    Hong Kong FinTech Week and StartmeupHK

    Featured Fintech Videos

    Fime

    Tazapay

    Banks Are Not Ready for AI

    Featured Webinar Replay

    iProov webinar

    Hong Kong Fintech Report

    Hong Kong Fintech Report 2025

    Malaysia Fintech Report

    MY Fintech Report 2025

    Singapore Fintech Report

    SG Fintech Map 2025

    Indonesia Fintech Report

    Indonesia Fintech Report 2025

    UAE Fintech Report

    UAE Fintech Map 2024

    Whitepapers & E-Books
    Scammed and Changed: How Fraud Is Rewriting Trust in APAC
    Scammed and Changed: How Fraud Is Rewriting Trust in APAC
    LSEG Risk Intelligence
    APAC Fraud in 2026
    APAC Fraud in 2026
    Sumsub
    Upcoming Fintech Events
    Asia's Multi-Billion-Dollar Fraud Crisis: Can Fintechs Still Build Trust
    July 16, 2026
    Featured Online
    What Will The Bank of 2030 Look Like?
    August 4, 2026
    Featured Online
    Bitcoin Hong Kong 2026
    August 27, 2026
    -
    August 28, 2026
    Hong Kong
    Taiwan Innotech Expo 2026
    September 17, 2026
    -
    September 19, 2026
    Taiwan
    -
    Taipei
    FinTech B2B Marketing Hong Kong Conference 2026
    September 22, 2026
    Hong Kong
    Promote Event View More
    FINTECH RESOURCES

    Navigations
    • About Fintech News Network
    • Contact Us
    • Media Kit
    • Work With Us
    • Fintech Hong Kong Newsletter
    • Submit a Fintech Hong Kong Press Release
    • Fintech Events Hong Kong & China
    • Fintech HK Startup Report
    • Submit Your HK Fintech Startup
    • Privacy Policy / Disclaimer
    Other Fintech News Network Publications
    Fintech News Hong Kong
    Fintech News Singapore
    Fintech News Malaysia
    Fintech News Philippines
    Fintech News Network Indonesia
    Fintech News Network Australia
    Fintech News Switzerland
    Fintech News Baltic
    Fintech News Nordics
    Fintech News America
    Fintech News Middle East
    Fintech News Africa
    Get Informed

    Subscribe to Updates

    Subscribe to the most important Fintech Hong Kong News

    LinkedIn Facebook X (Twitter) YouTube RSS
    • About Fintech News Network
    • Contact Us
    • Media Kit
    • Work With Us
    • Fintech Hong Kong Newsletter
    • Submit a Fintech Hong Kong Press Release
    • Fintech Events Hong Kong & China
    • Fintech HK Startup Report
    • Submit Your HK Fintech Startup
    • Privacy Policy / Disclaimer
    © 2015 - 2026 Copyright Finanzpro GmbH. All Rights reserved.

    Type above and press Enter to search. Press Esc to cancel.