Item 1B. Unresolved Staff Comments
ITEM 1B. UNRESOLVED STAFF COMMENTS
Not applicable.
ITEM 1C. CYBERSECURITY
We are a special purpose acquisition company with no business operations. Since our Initial Public Offering, our sole business activity has been identifying and evaluating suitable acquisition transaction candidates. Therefore, we do not consider that we face significant cybersecurity risk. As of the date of this report, we have not encountered any cybersecurity incidents since our Initial Public Offering.
Currently, we have not adopted any cybersecurity risk management program or formal processes for assessing cybersecurity risk. Our management is generally responsible for assessing and managing any cybersecurity threats. If and when any reportable cybersecurity incident arises, our management shall promptly report such matters to our board of directors for further actions, including regarding the appropriate disclosure, mitigation, or other response or actions that the board deems appropriate to take .
However, following the consummation of the proposed Business Combination, the Combined Company may face increased cybersecurity risk. See “ Risk Factors – The Combined Company will face risks relating to the custody of its CRO, including the loss or destruction of private keys required to access the Combined Company’s CRO and cyberattacks or other data loss relating to its CRO. If the Combined Company or its third-party service providers, including Crypto.com Custody, experience a security breach or cyberattack and unauthorized parties obtain access to the Combined Company’s CRO, or if the Combined Company’s private keys are lost or destroyed, or other similar circumstances or events occur, including the ability to reverse engineer private keys, the Combined Company may lose some or all of its CRO and the Combined Company’s financial condition and results of operations could be materially adversely affected .”
Following the closing of the proposed Business Combination, the Combined Company is expected to implement controls and compliance frameworks appropriate for a public company with significant digital asset holdings, including policies and procedures relating to cybersecurity and validator operations. The Combined Company intends to enter into a Crypto Services Agreement (the “Crypto Services Agreement”), with Foris DAX Trust Company, LLC, a New Hampshire-chartered trust company and digital asset custodian servicing institutions (“Crypto.com Custody”), under which it expects to hold substantially all of its CRO with Crypto.com Custody. Crypto.com Custody leverages the institutional and crypto-native experience of Crypto.com and maintains crime and specie insurance coverage to cover assets held in cold storage. The Combined Company may engage additional custodians over time to diversify counterparty exposure and custody arrangements, subject to customary diligence, legal and security considerations.
The Combined Company is also expected to implement controls and procedures designed to safeguard private keys and to support secure deposit, withdrawal and staking operations. All of the private keys associated with the Combined Company’s CRO holdings are expected to be maintained in cold storage. The Combined Company may in the future use hot storage for temporary periods of time for the purpose of executing certain transactions to monetize CRO.
Private keys are expected to be secured by a proprietary secure distributed key management system and the private keys will be securely fragmented and distributed to dedicated devices with the proprietary application. Access to the Combined Company’s recovery of the private keys will require mutual consent from “m of n” private key holders using the proprietary mobile applications.
With respect to cold wallets, Crypto.com Custody employs a two-tier security model to mitigate operational and security risks. Tier 1 encapsulates the quorum-based approvals workflow, providing a flexible, customizable option of approval rules in accordance with the policies and procedures the Combined Company is expected to adopt governing approvals of network transactions. Tier 2 secures the private keys to access digital assets using advanced cryptography known as multiparty computation (MPC). MPC allows multiple parties with fragmented dedicated devices to participate in a transaction signing in a distributed manner, ensuring that a private key never exists on an individual device or in one place at any point in time. Accordingly, gaining access to only a single device at a given time should not compromise the security of the original private key, thereby preventing any individual from being able to take possession or transfer digital assets from such cold wallets unilaterally.
71
Table of Contents
ITEM 2. PROPERTY
We currently maintain our executive offices at 1012 Springfield Avenue, Mountainside, New Jersey 07092. We consider our current office space adequate for our current operations.
ITEM 3. LEGAL PROCEEDINGS
None.
ITEM 4. MINE SAFETY DISCLOSURES
Not applicable.
72
Table of Contents
PART II