5,000 words
Intro
Step one was designing the full architecture with a book and formal specification. Step two was designing the lite launch path where it starts like a corporate product with a sole operator and uses cryptography to mitigate the trust assumptions until it matures into decentralization.
Trust Mesh is designed as the missing security layer for the open internet. It applies equally to crypto, which is an open system with the same flaw, and to AI agents, where it sits at the origin of every permission and again at the few consequential points where the authority to act has to trace back to an accountable human.
This article explains why Trust Mesh cannot be, or stay, a corporate proprietary walled garden product, how the open standard is the moat for the first-mover business, why crypto in particular needs a human authorization layer, and how Trust Mesh would have prevented or contained Coldcard, Hugging Face, the Anthropic incidents, and even fake World Cup tickets.
There are three funding paths this could take. Crypto investors who recognize the need could fund the lite launch, pilot it, and expand organically. Big Tech could take responsibility for AI safety, accept that the walled-garden approach will not work, and lead the build without owning the root. Or the governments of the world could recognize that an open standard built on a cryptographic receipt, one that composes across industries, applies to every kind of digital safety, and fund it as infrastructure.
The world is converging on this problem. It is only a matter of time before someone recognizes that the missing security layer of the internet is no longer optional, and I know of no other way to build it than the Trust Mesh design: a decentralized network on an open standard. A link to the book, both specifications, the budget estimate, and a Codex breakdown of how many incidents in Anthropic's recent safety report Trust Mesh would have affected is at the end (14 stopped, 16 materially contained, 13 beyond its scope). AI safety needs more than aligned models. It needs infrastructure that limits what any model is authorized to do.
The Security Layer Crypto Removed
How Trust Mesh restores protection without a gatekeeper
A legacy digital account is a bearer account. Anyone with the username and password has authority over the account, the same way whoever holds a crypto private key controls the wallet. These systems cannot tell the real owner from a hacker who stole the key or login credentials. Trust Mesh anchors login and authority to your biology instead: a low-risk action can be a face check on your phone while a high-risk one requires a multi-modal signal, each measured by the phone's own sensors and checked for a live presence, so a recording or a rendered fake face will not work. What leaves your device is a cryptographic receipt proving the unique enrolled human linked to this device approved this exact action while carrying no name or reusable identity handle, which makes the receipts composable across the digital economy yet unlinkable between services, so no company can assemble a human dossier and turn us into products to sell to advertisers.
Blockchain decentralization solved one problem but exposed another. It stripped away the institution that could freeze, censor, or surveil customer assets so a person could hold value directly while a public network settled transfers without needing permission, but it also discarded something essential riding along with the ability to censor: centralized institutions provided security. They delayed suspicious transactions, phoned account holders, and kept whole floors of people whose job was noticing something looked wrong. Those controls were imperfect, sometimes abusive, often annoying, but they were necessary. Self-custody removed the gatekeeper and left the user with a key to their funds but none of the security team to secure it.
A blockchain can decide whether a signature satisfies protocol rules, but it has no view of whether the human initiating the transfer is the right one. Finalizing value does not legitimize action. Trust Mesh restores the missing security layer with execution-time legitimacy for self-custody in real time.
At launch, a receipt is checked by the relying party (the business that asked for it) against published verifier rules, and under that business's own policy; at maturity the receipt becomes portable and universal as the root decentralizes. Possession of the key stays necessary for crypto transfers, but in a conforming Trust Mesh path, it is no longer sufficient on its own: if there is no valid receipt generated by the rightful owner, the protected funds cannot move even if the hacker steals the seed, passphrase, or key. Trust Mesh lets any conforming wallet, custodian, or policy engine (the software a business uses to decide what its keys may sign) demand an enrolled holder complete the required action-time authorization ceremony before the money moves. The relying party keeps its own policy, the user keeps custody, and no company becomes a permission desk. At maturity, it is a decentralized layer that uses your biological uniqueness as a security gate required to move funds or to gain access.
Crypto’s Bare-Key Problem
A bank account gives personhood without privacy; a crypto wallet gives privacy without personhood. The missing third type is an anonymous account backed by an enrolled human, able to authorize one bounded action at a time without becoming an identity record. It works by keeping three questions apart that every account today collapses into one: identity, who you are; uniqueness, whether this is one real enrolled human holding one position in the network, which Trust Mesh calls a Slot; and authority, whether that human approved this exact action right now. Modern fraud scales because stolen credentials scale, and the last two months supplied five demonstrations of it across four industries. The lesson runs past vendor blame to the design of blockchain itself: when a system treats the key as the whole authority to move funds, every hidden defect becomes an authorization to spend. With a receipt standing in the spend path, those same defects become failed attacks.
What a Receipt Adds
A Trust Mesh receipt is evidence that a protected action passed a human authorization ceremony under rules the relying party chose. It commits to the exact action approved, down to the asset, the amount, and the destination, so a receipt for one action is useless for another and yesterday's receipt authorizes nothing today. It carries no civil identity, no biometric template, no account or wallet identifier, and no handle that two services could line up against each other, so it proves that a scoped authorization happened in real time without turning the ceremony into a record of what that person does over time.
Five Failures From One Missing Security Layer
These five stories from the last two months look unrelated: a hardware wallet, an AI research platform, a frontier lab twice over, and a soccer tournament. In every one, something digitally copyable was enough for an unauthorized attacker to open a door that could have been gated by human biological uniqueness.
Coldcard
On July 30th, 2026, an attacker drained more than a thousand Bitcoin addresses in forty-one minutes. Loss estimates later passed 116 million dollars across more than 5,200 addresses. Reporting citing Galaxy Research traced the cause to a 2021 firmware change that generated seeds with far less randomness than the design intended, which left the keys guessable through brute force.[1] Nothing was phished, and no owner was fooled. The keys were simply weak and vulnerable, and since keys are possession in a bearer asset system, the attacker had the authority to move the funds.
If those wallets were Trust Mesh integrated, that theft would not happen. A gated cold wallet cannot execute until a live human receipt authorizes the exact transfer, so guessing the key would not be sufficient to move the funds because the key stops being the same thing as authority. The same applies to any wallet or custodian who integrates Trust Mesh. This use case alone would add the missing layer of security to the entire crypto industry.
The Hugging Face Authorizations
When AI agents overstepped inside third-party infrastructure in July 2026, reports described roughly seven hundred agents coordinating, sharing what they found, and calling themselves a swarm.[2] Ten distinct steps of that attack contained seven authority events and three software bugs, and every one of the seven authority acts was a permission a human granted once that no one ever proved again. Next week’s article, Every Permission Has an Author, does a deeper dive through the chain of events step by step. The agents did not break that model. They read it correctly and used it as the humans designed.
This is where human authorization complements alignment. Alignment tries to steer an agent by shaping what it wants, but what it wants is the part nobody can predict over time. Trust Mesh gates what an agent can do by tying the authority to act to a human who signed the scope, and by requiring a live receipt before any consequential action executes. The scope is an authored object: dated, bounded, signed by an accountable human, and narrowing only, so a derived grant can never exceed its parent.
An agent may get better forever at what it is allowed to do, but it can never grant itself authority beyond its delegated scope, so widening a permission, creating a new account or program, changing the guard, reducing observability, moving anything across a trust boundary, and irreversible acts beyond a set threshold do not execute without human approval. Every software delegation chain in use today ends at something digital and copyable: an API key in a config file, a token in a browser, a service credential in a build pipeline. The last check anyone makes is possession of a string, but a string in the wrong hands looks exactly like a string in the right ones.
A live Trust Mesh ceremony ends at a human body, the one thing an agent cannot copy, so authority cannot be lifted the way a key or token can. A receipt bounds a compromised agent rather than preventing the compromise, but it does nothing about ordinary software bugs or poor sandbox design, which stay the engineers' job. The Hugging Face incident had seven authority events, four of which a Trust Mesh receipt stops outright and three of which it bounds, with three software bugs that better design had to catch.
Without Trust Mesh as infrastructure we are left with an open system in which software evolves in ways nobody can anticipate and pieces of it can combine toward outcomes no one intended. Each company's engineers will define scopes, build containment, sandbox what they can, but their reach stops at the edge of their own ecosystem. Authority leaks at the seams between systems. No single vendor can close a seam it only owns half of, which is why this layer has to be an open standard that composes across systems rather than a feature inside any one of them.
Even a well-built walled garden can be attacked from outside by an actor with resources no product team budgeted for. In a sovereign conflict, that actor is a state. A security layer like Trust Mesh belongs as infrastructure, and it will most likely need to be mandated, first by one government and then by every government that opts in, the way clearing rules and building codes are.
The Anthropic Malware
Late in July 2026, Anthropic reviewed its own cybersecurity tests and reported three incidents in which Claude models reached real systems from evaluation environments. The cause was a setup mistake: the test machines could reach the internet while the model was told it had no connection. In one case, reporting on Anthropic's disclosure said the model wrote a harmful Python package, published it to the public code library, and saw it run on fifteen real machines. In another, it scanned roughly nine thousand targets and compromised one internet-facing application.[3]
A package is a bundle of code that other programs install and run, and a shared library like npm or PyPI is where developers publish them. Installing a package means running whatever is in it with full trust, so whoever published it decides what thousands of machines execute. Publishing is therefore a release, and a release is an act of authority that belongs to a person. With Trust Mesh in place, a library would treat publishing as a protected action requiring human authorization, so a package could reach the world only with a receipt from the accountable human behind the maintainer's account, tied to that exact build.
An AI model can still write the software package, but it cannot sign the release. Trust Mesh does not stop the model from writing hostile code, and it does not fix a setup error that gives the model an internet connection it was never supposed to have; those stay the engineers' job. What it changes is what those mistakes can affect. When an internet connection must be authorized by a human, and the check runs at the network gateway rather than on the machine itself, a misconfigured machine or hostile software cannot acquire a connection on its own. When a release must be signed by a person, the security scanner that later installs the package is installing something a real human stood behind, and it can verify that before it runs. Each of those gates ends at a body rather than a string, which is why even an agent that keeps getting better at its job still cannot get past them. That is infrastructure.
The Trusted Domain
In July 2026 criminals paid for ads at the top of Bing search results for the Claude desktop app. The ads led to a page on claude.ai itself: a public Claude Artifact, the kind of shareable document anyone can generate and host there, dressed up as a download portal. Huntress, a managed security company that monitors its customers' machines, watched the campaign hit at least 29 organizations on July 21st and 22nd.[4] An employee searching for the app clicked the ad, landed on the real Claude domain, followed the link, downloaded a file called ClaudeDesktop.exe, and ran it on a work PC. The page was downloaded about 7,100 times before Anthropic removed it. There was no Claude in the file. Instead, it installed SectopRAT, a program that reads saved passwords, credit cards, and login cookies out of the browser and sends them to the attacker.
Three authority failures sit in that chain. Publishing a page the whole internet can reach is a release. Under Trust Mesh that page must carry a receipt from an enrolled human at Claude, so an anonymous criminal cannot put a download portal on claude.ai in the first place. The fake installer is a release too, and with no receipt from the human behind a maintainer's account tied to that exact build it has no author, so a machine whose install path requires a receipt will not run it, whatever a page told the user to paste.
The session is the third, and it is the one that bit the victims. When you log in, a website gives your browser a small file, the session cookie, that says this browser is already signed in, and from then on every click you make sends that file instead of asking for your password again. The malware on the infected PC copied that cookie, which is why Anthropic later locked out every account whose session had been hijacked and warned its users about infostealers.[5]
The thief loaded it into a browser of their own, so the website saw a customer who was already signed in. The password and the two-factor prompt never appeared, because both had been satisfied when the real customer logged in. Under Trust Mesh the website does not trust a cookie for anything that matters. Before a withdrawal, an export, or a password change, it asks for a receipt, and a receipt can only be produced by a quick live ceremony on the customer's enrolled phone, a separate device with its own secure chip that the malware on the PC does not reach. The copied cookie still lets the thief open the account and look around, but it does not let them move anything, export anything, or change anything, because each of those needs a receipt the customer produces on their phone. How much friction to accept, and for which actions, is worked out over time by the participants.
What remains possible even with Trust Mesh is a real enrolled maintainer signing a malicious build, the way the maintainer known as Jia Tan signed the backdoored xz-utils release in 2024 after two years of earned trust. Jia Tan could vanish because an account costs nothing and a person can have a thousand. That is the outcome the receipt was built for: the release is bound to the account of the human who stood behind it, known to that registry as fully as the maintainer chose to be, so that human has burned the one account they will ever have there.
This is what Trust Mesh does as infrastructure: it ties the actions that matter to a human body. A copied cookie cannot open an account's protected actions without the customer's receipt, and a copied or convincing file cannot be installed without the publisher's receipt attached.
The Fake Ticket Problem
Before the 2026 World Cup, the FBI warned fans about fake FIFA websites selling counterfeit tickets and hospitality packages, and the FTC warned about copycat sites, unofficial sellers, screenshots, and paper tickets.[6] FIFA's answer was to pull everything inside one official app: the ticket lives on your phone, and you show the app at the gate. That works, but it costs fans a safe resale market because the only way to know a ticket is real is to buy it from FIFA directly.
Under Trust Mesh, a ticket is cryptographically tied to one enrolled person at a time. Selling it is a protected action: the current holder approves the transfer with a live ceremony on their phone, and the ticket then belongs to the enrolled buyer. At the gate, the venue asks for a receipt, the holder produces one with the same quick ceremony, and the turnstile learns that the body in front of it is the ticket's current holder and nothing else; it never sees who owned it before. Nothing on the ticket itself is worth copying: a screenshot is a picture of a ticket that belongs to someone else, and a copied barcode is a number that will not match the body at the turnstile. Fans get resale back, and the counterfeit market loses the one thing it sells, a copy of a ticket that looks real. The same design applies to every event that sells a ticket.
The Pattern
A guessable crypto seed, a service account nobody revisited, a published package, a browser cookie, a duplicated ticket barcode. Five stories that look unrelated with one shape underneath: in every case, something copyable was mistaken for the person, and the door opened for whoever held the copy.
Now imagine Trust Mesh as infrastructure, gating every consequential action and every change to the rules behind local, real-time biological uniqueness of an enrolled human. Picture it guarding your own logins. Even if someone hacks your computer and takes every credential you have, under Trust Mesh none of it opens a path on its own because those accounts no longer open without your live presence. The stolen password becomes a key to a door that now requires a second layer only your body can answer.
Imagine every software developer building the same requirement into their agents, so each step an agent takes toward acting on the world must be within a named scope delegated by a real accountable human. It would not matter how many swarms formed, how well they coordinated, or how ambitious their plan to seize the world's systems became. An agent can want and plan anything, but the moment it tries to act, Trust Mesh-integrated infrastructure requires, for any consequential action, a receipt that only a living human can produce and a rogue swarm of bots cannot.
Why a System of Walled Gardens Fails
The tempting version of Trust Mesh is proprietary instead of decentralized. A hardware vendor could ship its own receipt system, a bank could mint its own human proof, a phone platform like Apple or Google could fold this kind of approval into its biometric stack. Each would cut losses inside its own walls but fail at the only job that matters because digital life is composable: the same people carry value, credentials, and authority across accounts, apps, and services that do not trust one another. So proprietary proof breaks at exactly the boundary where proof has to travel and compose: the seams that connect ecosystems.
The core reason why Trust Mesh cannot be a normal corporate product is the root. The root is the authority that decides which receipts count, who may issue them, which schemas are valid, and how the rules change over time. Whoever controls the root shapes who participates and what the defaults become. For an ordinary corporate product, the ownership of the root is their moat. But for a human authorization layer that needs to be neutral infrastructure, a centralized root is impossible because a rival will never build on a competitor's root, a regulator cannot mandate one company's root as public infrastructure, and a serious wallet ecosystem will not accept a corporate-owned layer that can be repriced or captured by its owner.
A Trust Mesh bootstrap company would create the first market, but it cannot remain the permanent owner of the root without turning Trust Mesh into the thing it aims to replace. If one operator can forever decide whose receipts count, which wallets are blessed, and how the rules of visibility change, then the root becomes a corporate choke point. The handoff to decentralization is therefore not generosity; it is the condition that makes the category adoptable. The Trust Mesh corporation wins by proving the primitive, operating the early network, selling integrations, conformance, reliability, and support, and then making the root decentralized and neutral so rivals, regulators, businesses, wallets, and users can trust it.
The standard has to be open, which creates a moat in two directions. First, against the giants: Apple, Google, and the cloud providers can implement the open standard, build on it, sell devices, wallets, verifiers, and support above it; they can sit on the board of the foundation that stewards it, and profit from all of that, but none of them can own the root. A proprietary version of the root is the version that solves nothing, because rivals will not build on it, regulators cannot mandate it, and users will not trust it, so the deepest pockets in technology are welcome everywhere in this category except at its root. Second, against future implementers of the same open standard, the moat is the head start that compounds: the first working implementation, first production evidence, and the integration and conformance position that every later entrant has to catch up to while the leader keeps moving. Red Hat led Linux for twenty years while anyone was free to fork it. A security layer is a sticky product that no one changes easily. So openness creates the market instead of conceding it. The use cases are so abundant the challenge would be keeping up.
The First Wedge Product
A decentralized network does not appear at full maturity, so Trust Mesh starts in a corporate shape and matures into a network. The first product could be a security layer on high-risk crypto withdrawals at one custodian like Coinbase, protecting one path where the buyer already feels the pain of guarding bearer instruments. The custodian keeps custody, signing, compliance, recovery, and the release decision; Trust Mesh holds no funds and signs no transaction. A receipt is one more condition the custodian's own policy requires before it will sign.
It could run as thirty days of shadow and sixty days of capped enforcement. In shadow, receipts are issued on the live flow while nothing is gated, so the partner can measure completion rates, false rejects, support load, latency, and incident response before a single withdrawal depends on a receipt. Capped enforcement then covers an opted-in slice of high-value activity where customers already tolerate a higher-friction ceremony. Before the first enforced receipt, the custodian also proves the unglamorous edges. A freshly bound device cannot move funds until its waiting period passes. No path releases without either a receipt or a published suspension, a signed public notice that the requirement is paused for that path. The custodian's own vouching for a customer can never by itself be the first authorization to move live funds. And a retry after an uncertain attempt cannot become a second withdrawal. The self-custody rollout, the receipt-gated co-signing path, and the smart-account module are the second wave, built on the same receipt once production has proved it.
The Road to Decentralization
In the lite launch path, Trust Mesh starts as a narrow product with its decentralization schedule written into the code that checks receipts. The rules that govern the founding operator are public: they say when the operator's receipts stop verifying and when the root passes to independent validators. The operator cannot change that schedule, because the verifier lives in software the partner businesses run, and a custodian can stop requiring receipts whenever it chooses. So an operator that misses a milestone loses the product and, where the deployment posted a bootstrap bond, forfeits it under the escrow's own terms, a legal consequence rather than one the verifier enforces. The bootstrap phase is capped at 48 months from the first bootstrap-root operation under the profile. The lite launch specification is in the link below.
The Business Opportunity
Trust Mesh enters through the places where fraud, support cost, liability, and reputational risk are already expensive. Custodians, exchanges, banks, ticketing platforms, and agent platforms adopt receipts because they need stronger authorization at the moment of action. Once receipt-capable accounts accumulate, the same infrastructure becomes a portable, user-controlled layer.
Coinbase Prime already uses transaction-size tiers, consensus approvals, video approvals, and policy-review calls for high-value transfer controls.[7] That is validation of the need: custodians build, staff, and tolerate friction around exactly the action a Trust Mesh receipt would gate. Trust Mesh takes the same ceremony the market already pays for and turns it into an open standard, so what one custodian builds into its policy engine works at every other business that checks the same receipt.
The buyers closest to the pain of fraud are a natural coalition. Exchanges, custodians, and wallet providers carry the direct loss and the trust problem, while stablecoin and payment networks carry the volume that makes real-time authorization at machine speed unavoidable. Everyone on that list benefits if high-risk movement gets safer, whether a user keeps custody or hands it to an institution.
The Three Funding Paths
A corporate gatekeeper cannot own this category, because the owner of the root would hold a centralized admission and exclusion point for digital authority and the ultimate human dossier, which is exactly what the market will not accept. So fund the version the market will adopt: open where it must be open and commercial where implementation and reliability create value.
There are three ways in:
Crypto capital funds the launch. The first product is a receipt gate on high-risk withdrawals at one custodian, where losses are immediate, every action is digital, and the buyer already pays for a weaker version of the same control. The lite launch specification, budget, and financial plan are linked below. This is the tranche that produces the evidence: completion rates, false rejects, support load, and losses, on live funds, under a disclosed operator with a handoff written into the verifier.
Big Tech companies fund it and build above the root. Apple, Google, and the cloud providers fund the buildout and implement the open standard, sell devices, wallets, verifiers, and support on top of it. They sit on the board of the foundation that stewards it, and profit from an upgrade cycle that will last decades. The one thing none of them can do is own the root, which is the reason this category exists at all.
The public sector funds the build-out, runs the pilots, and then mandates it. A government cannot mandate Apple's root, or a bank's, as public infrastructure, but it can fund a neutral standard with a published verifier, a decentralization schedule in code, and a conformance suite anyone can run, then pilot it on its own systems, and require it the way it requires building codes. The build-out is small next to what it protects, the pilots produce the evidence a mandate needs, and the chokepoints to aid in AI safety are few: the identity systems holding every company's admin accounts and keys, the code registries every build pulls from, the custodians and payment rails, the authorities that decide what a name means, and the platforms that hand agents their permissions. A requirement at those points for human generated receipts to scope AI permissioning turns a decade of industry persuasion into a year of compliance.
Crypto stripped away the centralized institution, but it does not have to live forever with bare, vulnerable keys. Trust Mesh puts security back into the flow, enforced at the endpoint and governed by a root nobody can sell.
Next week’s article Every Permission Has an Author reconstructs the Hugging Face incident step by step, separating what a conforming Trust Mesh deployment can stop, what it can only bound, and what authorization cannot fix.
The following week’s article The Digital Self-Sovereignty Revolution explores how Trust Mesh shifts the power over our digital lives back to individuals.
Here is a link to the full book, The Trust Standard, the formal specification, the lite launch specification, and the supporting materials: the project budget, the design rationale, the use cases, the roadmap, and a breakdown of Anthropic's recent threat report showing where Trust Mesh would have helped: The Trust Mesh
Sources
[1] Fortune, "Bitcoin owners rocked by $116 million hack: What we know about the Coldcard exploit," Aug. 3, 2026, https://fortune.com/2026/08/03/bitcoin-owners-116-million-hack-coldcard-coinkite-exploit/; Galaxy Research, "Your Keys, Not Your Coins: Coldcard Wallets Hacked for $130m and Counting," Aug. 7, 2026, https://galaxy.boutique/insights/research/your-keys-not-your-coins-coldcard-wallets-hacked-for-130m-and-counting
[2] OpenAI, "The Hugging Face incident and the road ahead," Aug. 26, 2026, https://openai.com/index/hugging-face-incident-and-the-road-ahead/; Hugging Face, "Security incident disclosure - July 2026," https://github.com/huggingface/blog/blob/main/security-incident-july-2026.md?plain=1; The Verge, "The rise of AI 'civilizations' and the fall of corporate responsibility," Sept. 1, 2026, https://www.theverge.com/ai-artificial-intelligence/987566/ai-civilizations-opeai-hugging-face-hack
[3] Anthropic, "Investigating three real-world incidents in our cybersecurity evaluations," July 30, 2026, https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals; Axios, "Anthropic says Claude models compromised real-world systems during testing," July 30, 2026, https://www.axios.com/2026/07/30/anthropic-mythos-security-testing
[4] Huntress, "Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT," July 2026, https://www.huntress.com/blog/fakeagent-claude-desktop-malvertising-ends-in-dotnet-rat
[5] SecurityWeek, "Anthropic Warns Claude Users of Infostealer Malware Infections," Aug. 31, 2026, https://www.securityweek.com/anthropic-warns-claude-users-of-infostealer-malware-infections/; Help Net Security, "Anthropic locks out Claude users after infostealers hijack login sessions," Aug. 31, 2026, https://www.helpnetsecurity.com/2026/08/31/claude-accounts-compromised-through-infostealer/
[6] FBI IC3, "Threat Actors Spoofing FIFA Websites in Advance of the 2026 World Cup," May 27, 2026, https://www.ic3.gov/PSA/2026/PSA260527; FTC Consumer Advice, "How to make your World Cup experience scam free," Mar. 17, 2026, https://consumer.ftc.gov/consumer-alerts/2026/03/how-make-your-world-cup-experience-scam-free
[7] Coinbase Help, "Consensus, Transaction, and Video Verification security settings on Coinbase Prime," https://help.coinbase.com/en/prime/securing-your-account/security-settings; Coinbase Help, "Transfer approval policy reviews on Coinbase Prime," https://help.coinbase.com/en/prime/securing-your-account/reviews