Loading market data...

Veda CEO: Key Management, Not Code, Is the Real Threat to Onchain Vaults

Veda CEO: Key Management, Not Code, Is the Real Threat to Onchain Vaults

Veda's chief executive said the biggest risk to onchain vaults isn't a bug in the smart contract but how the keys are managed. The CEO argued that human and operational errors now outweigh code vulnerabilities as the primary threat, and that the industry needs to rethink its approach to access control.

The shift from code to people

For years, the assumption was that the code was the weak link. If a vault was exploited, the blame usually fell on a flaw in the contract. But Veda's CEO says that's no longer the case. The real danger, he said, comes from the people and processes around the keys — who has access, how they're stored, and what happens when someone makes a mistake.

That shift doesn't mean smart contract bugs are irrelevant. It means they're no longer the most likely point of failure. The CEO pointed to the growing complexity of operational setups, where multiple signers, custody arrangements, and recovery procedures create more opportunities for something to go wrong.

Why access control matters

If human and operational risks are the main threat, then access control becomes the critical defense. Veda's CEO stressed that robust access control measures are essential to protect onchain vaults. That means not just having strong keys, but also having clear policies for who can use them, how they're rotated, and what happens in an emergency.

The CEO's comments come as more institutions move assets onchain, bringing with them the same operational habits that work in traditional finance but may not translate well to a decentralized environment. The message is that the technology is only as secure as the people running it.

What operators should do

For teams managing onchain vaults, the takeaway is to audit their own processes as carefully as they audit their code. Key management isn't a one-time setup; it's an ongoing discipline. The CEO's warning suggests that the next big breach might not be a clever exploit but a simple mistake — a lost key, a misconfigured signer, or an insider with too much access.

That's a harder problem to solve than patching a contract. It requires training, procedures, and a culture that treats keys as the most valuable asset in the system.

The conversation around vault security is shifting, and Veda's CEO is pushing it in a direction that many in the industry have been slow to accept. The question now is whether operators will listen before the next incident proves the point.