Twenty years where key compromise is unrecoverable.

Cryptography engineer, hands-on across the full trust chain: HSM firmware, secure element programming and secure boot at the hardware layer; multi-party computation, threshold signing and PKI at the protocol layer; production key management and custody platforms above that.

I build the primitives other engineers depend on and stay accountable for how they hold up in practice.

Applied Cryptography Key Management MPC Threshold Signatures HSM TEE Secure Elements Embedded Firmware Secure Boot PKI Digital Asset Custody Rust · C/C++ · Python · JS

Experience

Staff Software Engineer · Kraken

  • Lead the vault team, owning the crypto custody vault architecture end to end.
  • Cryptocurrency firmware for hardware security modules, in Rust.
  • MPC and threshold signature schemes in production.
  • Secure-element and key-handling guidance for partner teams.
Dec 2021 —
Present

Senior Software Engineer · CPI Card Group

  • Chip-encoding module and protocol for industrial smart-card personalization machines.
  • Cryptographic key and certificate operations backed by HSMs.
Mar 2020 —
Dec 2021

Co-founder & CTO · PKI Co.

  • Co-founded the company and led engineering through six years of growth.
  • Complete PKI platform, from certificate authority to client tooling.
  • Secure-element and smart-card issuing systems for enterprise customers.
  • HSM programming for key generation, storage and certificate signing.
Sep 2012 —
Aug 2016

Senior Software Engineer · Matiran

  • Architected an ID card issuing system and the protocols for industrial issuing and mailing machinery.
  • Consulted on PKI design and deployment.
Feb 2010 —
Sep 2012

Software Engineer · SG

  • Secure element programming on Java Cards and ICC chips.
  • Chip-encoding modules for industrial ICC issuing machines.
  • Cryptography libraries, a scripting language and an IDE for chip encoding.
Jun 2005 —
Feb 2010

Patents

USPTO provisional · Sep 2025
Scalable Threshold Wallet Custody in Hardware Security Modules with Merkle Tree Integrity
USPTO provisional · Sep 2025
Ensuring State Consistency Across Hardware Security Modules Using Hash Chains
USPTO provisional · Apr 2026
Non-Custodial Crypto Wallet with Multi-Party Computation and HSM Integration

Independent R&D

Secubit

github.com/secubit-io

YubiShard

github.com/hosseinpro/yubishard

BitaWallet

github.com/hosseinpro/BitaWalletCard

Gozar

github.com/gozar-io

Research & education

Ph.D., Computer & Information Systems Security

Dissertation: Improving the Security of Crypto Wallets in Blockchain Technologies
University of Central Florida
2016–2020

M.Sc., Computer Software Engineering

Thesis: Secure Bootstrapping for Personal Computers
Iran
2005–2008

B.Sc., Computer Hardware Engineering

Thesis: Efficient Implementation of an RSA Cryptography Engine and PKCS#1
Iran
2001–2005

Selected peer-reviewed papers

Google Scholar

Multilayered Defense-in-Depth Architecture for Cryptocurrency Wallet

H. Rezaeighaleh, C. Zou · IEEE 6th International Conference on Computer and Communications (ICCC) · Chengdu, China
2020

Efficient Off-Chain Transaction to Avoid Inaccessible Coins in Cryptocurrencies

H. Rezaeighaleh, C. Zou · IEEE 19th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom) · Guangzhou, China
2020

New Secure Approach to Backup Cryptocurrency Wallets

H. Rezaeighaleh, C. Zou · IEEE Global Communications Conference (GLOBECOM) · Hawaii, US
2019

Deterministic Sub-Wallet for Cryptocurrencies

H. Rezaeighaleh, C. Zou · IEEE International Conference on Blockchain · Atlanta, US
2019

Using Disposable Domain Names to Detect Online Card Transaction Fraud

R. Laurens, H. Rezaeighaleh, C. Zou, J. Jusak · IEEE International Conference on Communications (ICC) — Communication and Information Systems Security Symposium · Shanghai, China
2019

Secure Smart Card Signing with Time-based Digital Signature

H. Rezaeighaleh, R. Laurens, C. Zou · International Conference on Computing, Networking and Communications (CNC) · Hawaii, US
2018

A New High-Performance Approach for Offline Replacement Attack Prevention in Trusted Clients

H. Rezaei Ghaleh, S. Khorsandi · IEEE International Symposium on Trust, Security and Privacy for Pervasive Applications (TSP) · Macau SAR, China
2009

Improving Client Security using a Smart Card and Trusted Server

H. Rezaei Ghaleh, M. A. Doustari · International Conference on Security and Management (SAM), WORLDCOMP · Las Vegas, US
2009

A New Approach to Protect the OS from Off-line Attacks Using a Smart Card

H. Rezaei Ghaleh, S. Norouzi · Third International Conference on Emerging Security Information, Systems and Technologies (SECURWARE) · Athens, Greece
2009

A New Approach for a Secure and Portable OS

H. Rezaei Ghaleh, M. A. Doustari · Second International Conference on Emerging Security Information, Systems and Technologies (SECURWARE) · Cap Esterel, France
2008

Blogs

The Secubit Blog

All posts
AI Just Changed the Custody Threat Model — Here's How Secubit Was Built for It
Why frontier models break the old software-security assumptions, and why trust belongs in hardware.
Security
10 min
Why HSM + MPC Is the Gold Standard for Institutional Crypto Custody
Removing single points of failure without sacrificing key sovereignty.
Security
9 min
Comparing Four Approaches to Institutional Wallet Security
One question decides security and fit: where do the keys live, and what controls a signature?
Comparison
8 min
Hardware-Grade Security Without the Hardware Burden
Real hardware assurance shouldn't require becoming a hardware operator.
Comparison
7 min

On Medium

All posts
Is the New Trezor Safe 5 More Secure Than Previous Trezor Models?
Jun 2024
Beyond Hot and Cold: Redefining Crypto Custody with Hardware Security Modules
Apr 2024
Self-Custody: The Good, The Bad and The Ugly
Mar 2024
The Current Most Secure Crypto Wallet
Mar 2023
Crypto Wallet Mechanics
Feb 2023