Twenty years where a leaked key can't be taken back.

Cryptography engineer, hands-on across the full trust chain: HSM firmware, secure element programming and secure boot at the hardware layer; multi-party computation, threshold signing and PKI at the protocol layer; production key management and custody platforms above that.

I build the primitives other engineers depend on and stay accountable for how they hold up in practice.

Applied Cryptography Key Management MPC Threshold Signatures HSM TEE Secure Elements Embedded Firmware Secure Boot PKI Digital Asset Custody Rust · C/C++ · Python · JS

Experience

Staff Software Engineer · Kraken

  • Built Digital asset custody from scratch using HSM, MPC and Intel SGX.
  • Lead the vault team, owning the custody architecture end to end.
  • Designed the key establishment across the enclave boundary and wrote the framework.
  • Developed custom cryptocurrency firmware for HSM in Rust and C, loaded and run inside HSM.
  • Found a critical vulnerability in the HSM during security analysis; worked with the vendor through to a formal fix, shipped in a patch and all later releases for all of their customers.
  • Authored and performed the key management ceremonies; provisioned the fleet.
  • Took the system through external audit and approval.
Dec 2021 —
Present

Senior Software Engineer · CPI Card Group

  • Worked on EMV chip-encoding module and protocol for industrial smart-card personalization machines.
  • Built a chip encoding system that encodes any ISO 7816 compatible chip with a high level language.
  • Ran HSM operations and key management.
  • Advised other teams on security and key management.
Mar 2020 —
Dec 2021

Co-founder & CTO · PKI Co.

  • Co-founded the company and led the engineering team.
  • Created a public key appliance: a turnkey solution for banks and financial institutions to set up their own PKI and certificate authority.
  • Built middleware for authentication, authorization and digital signatures.
  • Built smart-card issuing systems for enterprise customers.
  • Programmed HSMs for key management.
Sep 2012 —
Aug 2016

Senior Software Engineer · Matiran

  • Architected an ID card issuing system, and the protocols for the industrial machinery that issued and mailed the cards.
  • Consulted on PKI design and deployment.
  • Handled chip encoding for the national ID card program.
Feb 2010 —
Sep 2012

Software Engineer · SG

  • Built chip-encoding modules for industrial ICC issuing machines.
  • Built a programming framework for HSMs, smart cards and secure elements, covering key management and certificate issuance.
  • Worked on the national electronic passport program, built to ICAO standards.
  • Ran key management and security evaluation for a fuel card program.
Jun 2005 —
Feb 2010

Patents

USPTO provisional · Sep 2025
Scalable Threshold Wallet Custody in Hardware Security Modules with Merkle Tree Integrity
USPTO provisional · Sep 2025
Ensuring State Consistency Across Hardware Security Modules Using Hash Chains
USPTO provisional · Apr 2026
Non-Custodial Crypto Wallet with Multi-Party Computation and HSM Integration

Independent R&D

Secubit

Private repo

BitaWallet

Public repo
github.com/hosseinpro/BitaWalletCard

Gozar

Private repo
github.com/gozar-io

Research & education

Ph.D., Computer & Information Systems Security

Dissertation: Improving the Security of Crypto Wallets in Blockchain Technologies
University of Central Florida
2016–2020

M.Sc., Computer Software Engineering

Thesis: Secure Bootstrapping for Personal Computers
Iran
2005–2008

B.Sc., Computer Hardware Engineering

Thesis: Efficient Implementation of an RSA Cryptography Engine and PKCS#1
Iran
2001–2005

Selected peer-reviewed papers

Google Scholar

Multilayered Defense-in-Depth Architecture for Cryptocurrency Wallet

H. Rezaeighaleh, C. Zou · IEEE 6th International Conference on Computer and Communications (ICCC) · Chengdu, China
2020

Efficient Off-Chain Transaction to Avoid Inaccessible Coins in Cryptocurrencies

H. Rezaeighaleh, C. Zou · IEEE 19th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom) · Guangzhou, China
2020

New Secure Approach to Backup Cryptocurrency Wallets

H. Rezaeighaleh, C. Zou · IEEE Global Communications Conference (GLOBECOM) · Hawaii, US
2019

Deterministic Sub-Wallet for Cryptocurrencies

H. Rezaeighaleh, C. Zou · IEEE International Conference on Blockchain · Atlanta, US
2019

Using Disposable Domain Names to Detect Online Card Transaction Fraud

R. Laurens, H. Rezaeighaleh, C. Zou, J. Jusak · IEEE International Conference on Communications (ICC) — Communication and Information Systems Security Symposium · Shanghai, China
2019

Secure Smart Card Signing with Time-based Digital Signature

H. Rezaeighaleh, R. Laurens, C. Zou · International Conference on Computing, Networking and Communications (CNC) · Hawaii, US
2018

A New High-Performance Approach for Offline Replacement Attack Prevention in Trusted Clients

H. Rezaei Ghaleh, S. Khorsandi · IEEE International Symposium on Trust, Security and Privacy for Pervasive Applications (TSP) · Macau SAR, China
2009

Improving Client Security using a Smart Card and Trusted Server

H. Rezaei Ghaleh, M. A. Doustari · International Conference on Security and Management (SAM), WORLDCOMP · Las Vegas, US
2009

A New Approach to Protect the OS from Off-line Attacks Using a Smart Card

H. Rezaei Ghaleh, S. Norouzi · Third International Conference on Emerging Security Information, Systems and Technologies (SECURWARE) · Athens, Greece
2009

A New Approach for a Secure and Portable OS

H. Rezaei Ghaleh, M. A. Doustari · Second International Conference on Emerging Security Information, Systems and Technologies (SECURWARE) · Cap Esterel, France
2008

Blogs

The Secubit Blog

All posts
AI Just Changed the Custody Threat Model — Here's How Secubit Was Built for It
Why frontier models break the old software-security assumptions, and why trust belongs in hardware.
Security
10 min
Why HSM + MPC Is the Gold Standard for Institutional Crypto Custody
Removing single points of failure without sacrificing key sovereignty.
Security
9 min
Comparing Four Approaches to Institutional Wallet Security
One question decides security and fit: where do the keys live, and what controls a signature?
Comparison
8 min
Hardware-Grade Security Without the Hardware Burden
Real hardware assurance shouldn't require becoming a hardware operator.
Comparison
7 min

On Medium

All posts
Is the New Trezor Safe 5 More Secure Than Previous Trezor Models?
Jun 2024
Beyond Hot and Cold: Redefining Crypto Custody with Hardware Security Modules
Apr 2024
Self-Custody: The Good, The Bad and The Ugly
Mar 2024
The Current Most Secure Crypto Wallet
Mar 2023
Crypto Wallet Mechanics
Feb 2023