# FIDO2 / vault handshake method note

**Author:** Elena Vance, Limit Ledgers  
**As of:** 2026-08-31  
**Canonical:** https://limitledgers.com/elena/fido2-handshake.md  
**About:** https://limitledgers.com/en/about/#elena-vance

This is a custody checklist, not insurance and not a penetration test. A six-figure casino balance is a receivable at a counterparty. The question is whether a stolen cookie can empty the ledger without a second factor the thief does not have.

## What we look for

1. **Roaming authenticator** (FIDO2 / WebAuthn, e.g. YubiKey) for login **and** for moving funds out of a player Vault — SMS 2FA fails this row
2. **Vault segmentation:** idle balance cannot be wagered or withdrawn until a second ceremony (hardware or Multi-Sig)
3. **Operator cold vs hot:** majority of player crypto in air-gapped Multi-Sig; hot wallet is a refill buffer. A $2M cashout that waits 30–60 minutes is often that refill — if cold exists
4. **Recovery path:** threshold KYC or a signed message from the deposit key. Pure no-KYC with no host and no chain signature is a custody Fail even when the payout rail is unlimited

Spec reference: [FIDO2](https://fidoalliance.org/fido2/).

## What this note does not do

- It does not claim Stake (or any Pass row) insures stolen funds
- It does not treat a padlock icon as Multi-Sig
- It does not score “Privacy Index” or other unnamed trademarks

Parent: https://limitledgers.com/en/pillar/casino-security-infrastructure-audit/
