Twenty years where a leaked key can't be taken back.
Cryptography engineer, hands-on across the full trust chain: HSM firmware, secure element programming and secure boot at the hardware layer; multi-party computation, threshold signing and PKI at the protocol layer; production key management and custody platforms above that.
I build the primitives other engineers depend on and stay accountable for how they hold up in practice.
Applied Cryptography
Key Management
MPC
Threshold Signatures
HSM
TEE
Secure Elements
Embedded Firmware
Secure Boot
PKI
Digital Asset Custody
Rust · C/C++ · Python · JS
Experience
Staff Software Engineer · Kraken
- Built Digital asset custody from scratch using HSM, MPC and Intel SGX.
- Lead the vault team, owning the custody architecture end to end.
- Designed the key establishment across the enclave boundary and wrote the framework.
- Developed custom cryptocurrency firmware for HSM in Rust and C, loaded and run inside HSM.
- Found a critical vulnerability in the HSM during security analysis; worked with the vendor through to a formal fix, shipped in a patch and all later releases for all of their customers.
- Authored and performed the key management ceremonies; provisioned the fleet.
- Took the system through external audit and approval.
Dec 2021 —
Present
Present
Senior Software Engineer · CPI Card Group
- Worked on EMV chip-encoding module and protocol for industrial smart-card personalization machines.
- Built a chip encoding system that encodes any ISO 7816 compatible chip with a high level language.
- Ran HSM operations and key management.
- Advised other teams on security and key management.
Mar 2020 —
Dec 2021
Dec 2021
Co-founder & CTO · PKI Co.
- Co-founded the company and led the engineering team.
- Created a public key appliance: a turnkey solution for banks and financial institutions to set up their own PKI and certificate authority.
- Built middleware for authentication, authorization and digital signatures.
- Built smart-card issuing systems for enterprise customers.
- Programmed HSMs for key management.
Sep 2012 —
Aug 2016
Aug 2016
Senior Software Engineer · Matiran
- Architected an ID card issuing system, and the protocols for the industrial machinery that issued and mailed the cards.
- Consulted on PKI design and deployment.
- Handled chip encoding for the national ID card program.
Feb 2010 —
Sep 2012
Sep 2012
Software Engineer · SG
- Built chip-encoding modules for industrial ICC issuing machines.
- Built a programming framework for HSMs, smart cards and secure elements, covering key management and certificate issuance.
- Worked on the national electronic passport program, built to ICAO standards.
- Ran key management and security evaluation for a fuel card program.
Jun 2005 —
Feb 2010
Feb 2010
Patents
USPTO provisional · Sep 2025
Scalable Threshold Wallet
Custody in Hardware Security Modules with Merkle Tree Integrity
USPTO provisional · Sep 2025
Ensuring State
Consistency Across Hardware Security Modules Using Hash Chains
USPTO provisional · Apr 2026
Non-Custodial Crypto
Wallet with Multi-Party Computation and HSM Integration
Independent R&D
Research & education
Ph.D., Computer & Information Systems Security
Dissertation: Improving the Security of Crypto Wallets in Blockchain
Technologies
University of Central
Florida
2016–2020
2016–2020
M.Sc., Computer Software Engineering
Thesis: Secure Bootstrapping for Personal Computers
Iran
2005–2008
2005–2008
B.Sc., Computer Hardware Engineering
Thesis: Efficient Implementation of an RSA Cryptography Engine and
PKCS#1
Iran
2001–2005
2001–2005
Selected peer-reviewed papers
Google ScholarMultilayered Defense-in-Depth Architecture for Cryptocurrency Wallet
H. Rezaeighaleh, C. Zou · IEEE 6th
International Conference on Computer and Communications (ICCC) · Chengdu, China
2020
Efficient Off-Chain Transaction to Avoid Inaccessible Coins in Cryptocurrencies
H. Rezaeighaleh, C. Zou · IEEE 19th
International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom) ·
Guangzhou, China
2020
New Secure Approach to Backup Cryptocurrency Wallets
H. Rezaeighaleh, C. Zou · IEEE Global
Communications Conference (GLOBECOM) · Hawaii, US
2019
Deterministic Sub-Wallet for Cryptocurrencies
H. Rezaeighaleh, C. Zou · IEEE International
Conference on Blockchain · Atlanta, US
2019
Using Disposable Domain Names to Detect Online Card Transaction Fraud
R. Laurens, H. Rezaeighaleh, C. Zou, J. Jusak
· IEEE International Conference on Communications (ICC) — Communication and Information Systems Security
Symposium · Shanghai, China
2019
Secure Smart Card Signing with Time-based Digital Signature
H. Rezaeighaleh, R. Laurens, C. Zou ·
International Conference on Computing, Networking and Communications (CNC) · Hawaii, US
2018
A New High-Performance Approach for Offline Replacement Attack Prevention in Trusted Clients
H. Rezaei Ghaleh, S. Khorsandi · IEEE
International Symposium on Trust, Security and Privacy for Pervasive Applications (TSP) · Macau SAR, China
2009
Improving Client Security using a Smart Card and Trusted Server
H. Rezaei Ghaleh, M. A. Doustari ·
International Conference on Security and Management (SAM), WORLDCOMP · Las Vegas, US
2009
A New Approach to Protect the OS from Off-line Attacks Using a Smart Card
H. Rezaei Ghaleh, S. Norouzi · Third
International Conference on Emerging Security Information, Systems and Technologies (SECURWARE) · Athens,
Greece
2009
A New Approach for a Secure and Portable OS
H. Rezaei Ghaleh, M. A. Doustari · Second
International Conference on Emerging Security Information, Systems and Technologies (SECURWARE) · Cap
Esterel, France
2008
Blogs
The Secubit Blog
All posts
AI Just Changed the Custody Threat Model — Here's How Secubit Was Built for It
Why frontier models break the old
software-security assumptions, and why trust belongs in hardware.
Security
10 min
10 min
Why HSM + MPC Is the Gold Standard for Institutional Crypto Custody
Removing single points of failure without
sacrificing key sovereignty.
Security
9 min
9 min
Comparing Four Approaches to Institutional Wallet Security
One question decides security and fit: where
do the keys live, and what controls a signature?
Comparison
8 min
8 min
Hardware-Grade Security Without the Hardware Burden
Real hardware assurance shouldn't require
becoming a hardware operator.
Comparison
7 min
7 min
On Medium
All postsIs the
New Trezor Safe 5 More Secure Than Previous Trezor Models?
Jun 2024
Beyond
Hot and Cold: Redefining Crypto Custody with Hardware Security Modules
Apr 2024
Self-Custody: The Good, The Bad and The Ugly
Mar 2024
The
Current Most Secure Crypto Wallet
Mar 2023
Crypto
Wallet Mechanics
Feb 2023