Digital assets in practice
14 modules for operations, risk, treasury and technology teams. Work through fictional decisions and control failures.
New to the subject? Start with wallets and transaction execution, then follow the three themes below. Each lesson states its prerequisites and difficulty.
Governance and custody
Designing a digital asset operating model
An operating model assigns decisions, execution and evidence across a service.
Digital asset custody: beyond key storage
Custody combines the authority to move assets with obligations to safeguard and account for them.
Multisig: policy, backups and recovery
A multisignature arrangement requires several signatures under a defined policy, such as two of three keys.
MPC wallets and threshold signing
Multi-party computation allows participants to calculate a result jointly without revealing their private inputs to one another.
HSMs and FIPS 140: what validation means
A hardware security module provides a controlled environment for cryptographic operations and key protection.
Transfers, assets and daily operations
Asset admission and network due diligence
Supporting a ticker is not the same as supporting every token with that name.
Withdrawal controls and beneficiary changes
A withdrawal joins client intent, asset availability and signing authority.
Crypto settlement and reconciliation
Settlement is the completion of the obligations created by a transaction.
Investigating reconciliation breaks
Reconciliation compares independent views of the same economic position at a defined time.
Treasury, fees and liquidity across networks
An asset balance is not the same as immediately usable liquidity.
Resilience and asset lifecycle
Operational controls for digital assets
An operational control should have a defined risk, owner, frequency, evidence and exception process.
Incident response and controlled recovery
An alert becomes an incident through investigation, not through its severity label alone.
Provider due diligence and exit planning
A provider assessment should follow the service dependency rather than its product name.
Tokenized securities across their lifecycle
Issuance is only the first event in a security’s life.