Missing from the article - the hacker first compromised Resolv Lab's AWS account, took a private key from KMS that was used to control minting, then managed to extract $25 million into ETH before all protocol functions were suspended.
They used KMS to sign the minting operation, but they didn't "take" the key, AWS KMS doesn't let you extract keys.
There's no shortcut to MPC/multisig with 3+ keyholders.
Obviously.
> There's no shortcut to MPC/multisig with 3+ keyholders.
The whole concept of a stablecoin seems to be based on centralised trust. Ultimately there is some org that has the fiat bank account, that mints and redeems the coins.
A step by step breakdown of the attack Step 1. Gaining Access to Resolv’s AWS KMS Environment