Pool-key handling draws security scrutiny alongside a development announcement
A community security discussion focused on whether a pool operator had used the key-holding wallet directly on a server instead of a delegated Sentry wallet. An administrator said the owner had placed the key wallet's private key on a VPS. A participant separately suggested that a server compromise was the likely cause of exposure. The administrator's statement about key handling and the participant's intrusion hypothesis are different claims; the discussion does not supply a complete incident investigation.
A community security discussion focused on whether a pool operator had used the key-holding wallet directly on a server instead of a delegated Sentry wallet. An administrator said the owner had placed the key wallet's private key on a VPS. A participant separately suggested that a server compromise was the likely cause of exposure. The administrator's statement about key handling and the participant's intrusion hypothesis are different claims; the discussion does not supply a complete incident investigation.
A support message made a conditional distinction between assets held by contracts and a pool's ability to keep earning rewards if its operator stopped running the node. Later, an administrator described delegation as a way to use a separate Sentry wallet for operation and gas rather than exposing the key-holding wallet. These exchanges explain the operational concern. They are not an independent audit that all assets were safe, all permissions were harmless or no loss occurred.
Separately, Xai announced a partnership with Polychain Monsters aimed at bringing DN404 to its network. The accompanying community notice described an app countdown of approximately 48 hours before registration and related features became available. This records the announced development scope and onboarding plan, not a verified production deployment or adoption total. No Night Ash partnership or custody role follows from the announcement.