The Resolv hack: How one compromised key printed $23M

https://www.chainalysis.com/blog/lessons-from-the-resolv-hack/

The Resolv Hack: How One Compromised Key Printed $23 Million

Web3 security lessons from the Resolv hack: how a compromised key enabled a $23M exploit, what went wrong, and how DeFi protocols can prevent similar attacks.

Chainalysis
You shouldn't have a key that controls millions/billions of dollars on a cloud service. It should be on an airgapped laptop that was purchased anonymously, has never been connected to the Internet, and only runs software that has been vetted and loaded onto it via a CD-ROM or some other comparable method.

If their coin requires a web service to process each transaction, then an offline key isn't very useful.

You can criticize their design, but you can't have a dude burning a CD-ROM every time someone wants some coins.