Which Wallet Controls Actually Prevent Losses
Ranked by what they stop. The delay on new destinations does more than everything else combined.
Business wallet products offer a long list of controls. Ranked by the losses they actually prevent, the list is short.
First: a delay on new withdrawal destinations
Almost every large corporate crypto theft followed the same sequence: an account compromised, a new destination added, funds sent within minutes. It is worth seeing what a business crypto wallet with enforced approvals enforces by default before deciding how much of this to build yourself.
A delay converts that from an immediate loss into an alert with time to respond.
It is also the control most frequently disabled, because it is inconvenient when a new supplier needs paying today. The correct response is to register destinations when a contract is signed rather than when an invoice arrives.
Second: notification to several people on configuration changes
An attacker controlling one account can suppress what that account sees. They cannot stop four colleagues receiving the same alert.
Notifications to a shared inbox nobody monitors are equivalent to none.
Third: approval separate from initiation
The only control addressing misuse of legitimate access, and the one that protects the individual as much as the company. Above a certain balance this stops being a wallet question and becomes one for a licensed digital asset custodian.
An organisation where one person can move funds alone cannot demonstrate that they did not.
Fourth: limits per period, not only per transaction
Limits applied per transaction are circumvented by splitting. Several providers apply them per transaction only and do not document it, which is worth testing rather than assuming.
Fifth: an audit trail including failed attempts
The rejected attempts are the signal. A run of rejected withdrawals is the clearest early sign of a compromised account, and a log recording only successes never shows it.
What matters less than advertised
The key management technology. Threshold signatures and secure computation are both defensible, and the operational controls around either matter more.
Certifications without scope. Ask what was assessed and over what period.
The test worth running
Configure your intended policy and then attempt to circumvent it: self-approve, use a new destination immediately, exceed a limit by splitting, change a setting without others being notified.
Anything that succeeds is a control that exists in the interface and not in practice. In most evaluations, at least one does. The part that only matters on a bad day is whether there is a support channel with a named contact, and that is worth testing before you need it.
Filed under: wallet, controls, risk