The truth is, DIY coins are not as appealing as maker funded coins. Most collectors like to collect due to the potential upside in value of the pieces. DIY coins don't trade well since you have to trust the buyer who generated the private key instead of just the maker of the coin.
Yogg destroyed a coldkey collection worth over a million dollars for the $15k he has stolen so far. I suspect there will be more cases like this especially since a lot of new makers are entering the space and the price of BTC will rise
I'm happy to see smoothie taking initiative in finding a solution and I hope a solution that involves 2 trusted makers to work together can happen. Maybe smoothie and Kialara can work together and do what Ballet have done:
"To improve the security of Ballet Wallet private keys, the keys are encrypted – the key is generated and printed in China, while the required passphrase is generated and printed in the USA."
here is the deal with that - many of the coins are not actually "funded" by the maker. The maker has the buyer send funds to an address prior to shipment and then calls these "maker funded" and then they sell "buyer funded" where the buyer funds it when the receive it. There is no difference between these two scenarios - the buyer in both cases is directly funding the coin/collectible.
I do understand that not everyone wants to do their own keys though - so having a more secure way is a great idea.
Makers need to stop saving/keeping copies of the keys - use a system that puts the keys in RAM so when the machine is shut off the keys are gone - I have heard from some that do this.
Me personally, I dont save the fiile that comes out of the generator - I run the program copy the keys to a QR generator, copy that to a document and then print it - once done I close the document without saving, I close the programs without saving - essentially whatever I printed is all there is. I do typically do 2-3 of each address/key pair for in the situation I fuck up a holo. once the project is done, all remaining keys (good and peeled ones) are cross shredded and then burned. My system is airgapped - the wifi and bluetooth modules removed. I use disposable usb drives (made from paper) to update the laptop periodically - these are also cross shredded and burned after use and never ever go back to the online system. I also periodically replace the hard drive, drill it and burn it.
is there a chance that one time I could keep a key or two - sure. But my face is known by many here - my name is known and my address is known.
There is not enough money in the world that would entice me - doing so would make me a marked man - I have too many kids and grandkids to go on the run lol
But I do get that this fear can still be there for some people. and a split key process or BIP38 or 2FA - something else would make it more secure.
It also makes the process longer and harder. Is it worth it? and does it remove all the need to have trust? hard to say...