How would you verify that the private key is unknown? I guess an auditable process in a black box to confirm the key is ever stored. But with $1B at stake, there’s some serious incentive to measure electrical output or something to snoop the key.
I guess you could send to a random address, but there’s an infinitesimal chance that someone in the future generates a key with that address, right?