PressReader

ADVERTISEMENT 18+

Beta version
HOME
Artem Stopnevich, The Vault CEO

Kazakhstan needs a competitive technology market for digital assets | Artem Stopnevich, The Vault CEO

The development of the digital asset market depends not only on financial regulation. Kazakhstan needs to create conditions for competition among technology solution providers - from custody and AML services to accounting, auditing, and certification systems. In an interview on the sidelines of Astana Finance Days, The Vault CEO Artem Stopnevich explained how MPC cryptography protects keys and transactions, why large organizations need sovereign infrastructure, and how transaction confidentiality can be combined with regulatory requirements.

– Artem, tell us what The Vault does and in which jurisdictions the company operates.

– The Vault develops infrastructure for the institutional custody of digital assets and transactions involving them. The company’s headquarters and technology hub are located in Cyprus. It also has offices in Switzerland, the United Kingdom, and the United Arab Emirates.

We have obtained the necessary authorizations to work with crypto assets in Cyprus and Switzerland. The European part of our operations is structured in accordance with the requirements of MiCA, the European Union’s regulation on markets in crypto-assets.

– Your product was developed with European requirements in mind. How applicable is it in Kazakhstan and other Asian markets?

– We create infrastructure for the secure storage and protection of digital assets — crypto custody. From the outset, the product was developed to meet European Union requirements, including MiCA, as well as DORA, the regulation on digital operational resilience for financial organizations.

Kazakhstan, Central Asia, and Southeast Asia have their own rules, but many regulatory approaches draw on European experience. The architecture of our system allows it to be adapted to the requirements of different jurisdictions. In addition to the EU, we take into account practices in Switzerland, the UAE, and Central Asian markets.

– What tasks does The Vault platform address for banks, financial institutions, and large companies?

– The foundation of our infrastructure is custody, meaning the storage of digital assets. Blockchain wallets are created using multi-party computation (MPC) technology. The private key is initially generated as several separate parts and never exists or is stored in full in one place.

This technology distributes control over access to crypto wallets. A company can independently create wallets, store assets, and manage them in the interests of its end clients.

One of our key principles is infrastructure sovereignty. Many providers offer cloud-based solutions and store parts of the keys on their own servers in the country where they are registered. For government bodies, national institutions, and large companies, such dependence on an external provider is not always acceptable. The Vault can therefore deploy the technology entirely on the client’s equipment and servers. In this case, the organization itself controls all cryptographic material.

– What vulnerabilities most often lead to the loss of digital assets?

– The first group of risks is related to the choice of technology: unauthorized transaction signing must be prevented, and the locations where parts of the key are stored must be reliably protected. However, the most serious vulnerabilities often arise from the actions of internal administrators and insufficiently protected operational processes.

Even reliable cryptographic technology will not solve the problem if authority is distributed incorrectly within the company.

The system therefore includes approval policies, quorums, different access levels, and segregation of rights. No employee or external participant can make a unilateral decision to send a transaction.

Our model covers more than 45 threat scenarios, more than 30 of which are related to internal risks. According to our observations, a significant proportion of thefts are committed not by external hacking groups, but by people who already have access to the system or by those who infiltrate a company in advance in order to look for vulnerabilities.

– How does the system ensure transparency of actions and control over transactions?

– The platform maintains a full audit trail. Every action and every decision is recorded in logs that cannot be substituted or altered. It is possible to see who did what and when within the system, who approved an operation, where the assets were sent, and which addresses were used.

The blockchain itself is also transparent: a completed transaction can be verified in a publicly accessible ledger. Control therefore covers both users’ internal actions and the movement of assets on the network.

– Is it possible to protect commercially sensitive information while maintaining this level of transparency?

– The Travel Rule is used to identify senders and recipients — a mechanism for exchanging data about the parties to a transaction, comparable in logic to the SWIFT messaging system in traditional financial markets. It allows the regulator to track the direction of a transfer and identify addresses.

At the same time, banks and large organizations do not want to disclose their operating expenses, counterparties, and treasury positions to all network participants. Privacy protocols are used for this purpose: the information is hidden from public view but remains available in the audit system. During an inspection, the organization can provide it to the regulator or supervisory authority.

– What is currently lacking in Kazakhstan’s digital asset market for its further development?

– I would speak not so much about shortcomings as about the maturity of the market. When the number of participants is limited, they use similar technologies and work with the same circle of contractors. This constrains domestic competition.

The advantage of the European Union market lies in the large number of countries and companies. It is sufficiently saturated, so each segment has specialized providers and several competing solutions. Large companies in Kazakhstan still often prefer to build their entire technology infrastructure within their own organizations.

For Kazakhstan, it would be useful to create a legal framework not only for companies obtaining financial licenses for crypto-asset operations, but also for technology product providers. These include AML and custody providers, developers of back-office systems and wallet accounting solutions, as well as privacy, auditing, and certification solutions. Active competition among such companies stimulates technological development and improvements in product quality

Oasis Travel
Luck-Q YouTube
Maru Studio
Arangeni