Decision 1
Keep signing keys out of the public API
- Decision
- The internet-facing API holds no signing keys. It can only queue a withdrawal. A separate worker process, which the internet can't reach, checks the request again, signs it and sends it to the chain.
- Alternative
- Sign inside the API. One process, simpler to deploy.
- Why
- Then one break-in at the API would expose the keys. With the split, the API can ask for a payout but can't make one.
Engineer view
The API derives per-user deposit addresses from a public xpub, so it never needs a private key. Confirming a withdrawal writes a signing request to the database. The wallet workers re-validate it, sign and broadcast. The signer can run on AWS KMS, a dedicated hot-wallet key or a seed fallback, chosen by configuration.


