- Role
- Led the build · owned the crypto core
- Company
- SkyLab Group
- Period
- 2025
- Stack
- Multi-chain / EVM, ERC-20, USDC, Privy
Overview
The problem
Lumicap turns real-world assets, starting with GPU and compute capacity, into on-chain investment funds. Its investors are not crypto-native. They need to see what they hold, what it is worth, and where their money moved, without learning how a blockchain works.
The insight: in a fund the hard product is trust. Keys that never sit in a database, and money that needs more than one person to move.
- assets under management
- $635M
- distributions paid
- $2M
- active investors
- 17
- active funds
- 5
Source: lumicap.io public website. Company-published figures, not my personal outcomes. The product I led has 6 investor-facing modules (my CV).
My role
What I owned
I led the build and owned the crypto core. That is the part where a mistake loses money, so it was also the part I wanted legible to people outside the team.
The crypto core, and who it serves
- CustodyMultisig wallets
- LedgerOn/off-chain, USDC settlement
- Fund managementNAV tracking, history
- Investor flowsTokenisation made legible
Custody
Custody: no single person moves a fund
Deploying a fund contract is the highest-stakes action on the platform. The design makes it a : two of three approvers must sign off, each through two-factor authentication. Play approver one and see what each approval does, and does not, change.
The detail that matters is what the database holds. Approvals are stored as plain records. The signing keys sit in HashiCorp Vault and are fetched only at the moment of execution; the quorum is verified inside Privy's trusted execution environment; the signature is never persisted. Even a breach of the application database yields no ability to sign.
The decision
Who can move a fund?
Two of three approvers sign, each with two-factor authentication. The keys sit in a vault and are fetched only at execution; the signature is never stored.
Cost I accepted: Every deployment waits for a second approver.
Source: Luminet, How it Works (January 2026), p.8 and p.9.
Ledger
Ledger: one history, two kinds of record
An investor deposits dollars, then holds tokens. The ledger has to carry both, on and off chain, and the investor-facing product has to show one coherent story. Step through the seven stages and watch where the record changes hands.
Fund lifecycle
Funds run on different clocks
A fund's life, closed-end or open-end
Safety
Safety: plan for the bad day
Security features are easy to list. The one worth designing carefully is the emergency pause: it has to be fast to use, hard to misuse, and slow to reverse.
Where it stands
Outcome
The platform shipped in a pre-launch state. The public site now shows live funds and the company figures above; those are the company's results, and I do not claim them as mine. What I can point to is the design: a custody flow with no single point of failure, and an investor journey that makes tokenisation readable.
What shipped
- investor-facing modules I led the build ofMy CV
- 6
- Custody: two-of-three approval, with signing keys kept out of the application database
- Ledger and investor journey across seven stages, on and off chain
- Fund lifecycle for closed-end and open-end funds
- An emergency pause, designed to be fast to use and slow to reverse
Source: Thao's CV (SkyLab, Lumicap); Luminet decks (January 2026). The platform shipped in a pre-launch state. The company's own figures sit above and are not claimed as mine.



