← Kyeson Utley

Sole custody is a story: what I learned tracing stolen crypto

By Kyeson Blake Utley, founder of GhostKey Development · October 2026

Before I founded GhostKey, I spent years on the other end of crypto theft: tracing funds for victims after the money was already gone. Each case looked different on the surface, whether a romance scam, a fake exchange or a compromised wallet. Underneath, the same pattern showed up again and again.

The cryptography almost never failed. The custody did.

One key, one point of failure

"Only we hold the keys" is a reassuring line in a pitch deck. Operationally, it means one person, one device or one secret can move everything. A key one person can extract is a key that one phishing page, one coerced employee, one subpoena or one bad night can extract too.

The on-chain trail of a theft is permanent and public. The moment of compromise usually isn't. When we worked backward, it was rarely an exotic exploit. It was a seed phrase typed into the wrong page, a hot wallet with too much in it, or an approval granted to a contract nobody had read.

What actually holds up

Threshold the key. Split signing authority across parties and hardware with multi-signature or threshold signatures (MPC), so no single compromise moves funds.

Separate hot from cold, and mean it. The hot wallet should hold what you can afford to lose today, not what's convenient.

Make approvals legible. Most drains are signed by the victim. If a person can't understand what a transaction will do before signing it, the interface is part of the attack surface.

Test the humans. Social engineering is how attackers get past strong technical controls. Authorized phishing and pretext tests belong in every serious custody review.

Design for the bad day

Good custody design assumes something will eventually go wrong: a lost device, a departing employee, a compromised laptop. It makes sure no single one of those events is fatal. That's the standard we hold GhostKey's own systems to, and the one we test clients against.