# The Key You Can't Lose Because You Never Had One
*Published 27 July 2026*

Somewhere in your house there's a seed phrase. Written on paper, maybe stamped into steel, possibly split across two locations, and the arrangement exists for one reason: the thing that controls your money can be taken from you. Every security habit you've built sits downstream of that fact. The hardware wallet, the multisig you keep meaning to set up, the passphrase you won't type on a laptop. All of it is elaborate defence of a stealable object. Jose Caldera has built and exited three companies across thirty years, the last stretch of it in financial crime and identity, and his answer to that problem is the one nobody offers. Don't protect the secret better. Don't have one.
His company, Yanez, runs Subnet 54 on Bittensor. The product is called Proof of Humanhood and Uniqueness, it reaches users through an app called Yanez YID, and it's one of several products the company sells. It's the one product they're pushing now. Underneath it sits three separate claims about a person, and only two of them make it into the name. The space between them is where most of the confusion about digital identity lives.
## What Proof of Humanhood and Uniqueness actually proves
**Human.** There's a living person here, not a script, not a synthetic identity, not a model running in a data centre somewhere. This is the claim captchas were built to carry and stopped carrying years ago. Most systems still ask the question. Almost none of them still get an answer.
Yanez arrived at this from the other end, which is why they're worth listening to on it. The company started out selling synthetic identity data to banks, fake people convincing enough that a fraud system would swallow them whole, sold so those banks could find out whether their defences caught anything at all. Then the question turned itself around. As Jose tells it, they asked whether "if we're really good at generating synthetic identities, can we be really good then to say this is a human instead of a synthetic human?" Proving humanhood is partially the same skill as faking it, in reverse.
**Unique.** You're the same person the system met before, and there's only one of you. Jose draws the line sharply: humanhood says "I'm dealing with a living, breathing human being," while uniqueness says "this is the same human that I've seen before." That second one is what kills sybils. His example is governance, and it's the cleanest way to see it. You can create a hundred accounts if you like, and it changes nothing, "because at the end is about you. You can be only one person." One human, one vote, enforced by the body rather than by a document.
Proving there's a unique human here is not the same as proving who that human is, and Yanez refuses the second one on purpose. Jose says he doesn't need to prove that you're Jose or that you're Louise. He doesn't want to know.
Think about how strange our current arrangement is by comparison. To prove you're not a bot, you hand over a government document carrying your face, your date of birth and your address. You were asked whether there's a person here, and you answered a completely different question, which is precisely which person. We've fused those two things so tightly that most systems can't tell them apart, and the cost of that confusion lands on you every time you upload a driving licence to use something ordinary. Humanhood is the primitive sitting underneath identity verification, not a version of it, and pulling them apart is the whole design.
**Present.** You're here, now, authorising this. Not a photograph of you, not a recording of you from Tuesday, not a deepfake built from the footage of your face that's already out there. Presence is the one people forget, and it's the one that carries the actual weight.
You'll have thought of World by now, because everyone does. The difference that matters isn't philosophical, it's physical. World asks you to travel to a specialised orb; YanezID runs on the phone already in your pocket. Jose's own way of putting it is that you don't have to rely on "the weird iris scanner from World or something." Hardware agnostic reads like a dry engineering choice until you set it beside a queue for a chrome sphere.
## So what leaves your phone?
Nothing you'd recognise as you. The app reads your biometric signals, face for now with voice, fingerprint and behaviour to follow, and inside the phone's secure enclave turns those signals into a single value that is unique to you but cannot be run backwards. That value is the unique bio key, and it's what goes out. As Jose puts it, "if somebody got a hold of that, they cannot go back to your biometrics ever." The biometrics themselves stay on the device long enough to build the bio key, then they are destroyed. Alongside the key, the app generates public keys, and those go into a registry anyone can query to check that you signed something.
In every wallet you own there's a private key, and whoever holds it is you. Steal it and you don't impersonate the owner, you become them. Ask Jose what the equivalent attack looks like here and the answer is that the question doesn't apply:
"The private key is you."
There is no persistent private key anywhere in the system, because the thing that authorises is your live biometric signal and it's regenerated every time. "There's nothing to steal" is a sentence you can't say about anything else holding your money, and once you've heard it, the seed phrase in your drawer starts to look less like protection and more like a liability you've agreed to carry.
Jose is blunt about the theft question when it's put to him directly. "No one can steal your biometrics. It's that simple. There's no way."
## What it replaces
Syklo makes the abstract version concrete. The first project going live on it, a peer-to-peer exchange for people moving between local currencies and dollars across Latin America, and what they've done is take their wallet off private keys. The user's live biometrics authorise every transaction instead. Nothing to lose, nothing to phish, nothing to write on a bit of paper and forget about. Jose doesn't oversell what that achieves: "it doesn't prevent every security problem, but it really helps."
Where it sits right now, accurately: the app is live on both the Apple and Google stores, which was the gate holding up the first integrations, and Syklo user onboarding is the step after that rather than a finished one. So it's moved from a design you could only read about to something you can download, with the first users still ahead of it.
Notice what's actually being removed there. Not a weak password, not a careless habit. The seed phrase itself, the thing every guide you've ever read tells you to protect more carefully, treated as the vulnerability rather than the defence.
## Where it gets hard
Three problems sit underneath this, and the first two are Jose's own admissions. The third is mine.
**Nothing to steal also means nothing to inherit**. Every recovery mechanism in self-custody exists because the key is a portable object. The seed in the safe, the executor who knows where it is, the twelve words split between two family members. Remove the object and you remove the recovery with it, and Jose raises this himself, unprompted, which is not what founders usually do with the hole in their own product. "There is a real question about what happens if you die, what happens to your security in that."
His answer is that there isn't one yet, only the direction of one: multiple biometrics rather than a single signal, plus contractual arrangements naming someone to act for you. He calls them "real cases that we actually have to go and figure out how to deal with in the right way," and he's right that this is the standard objection to biometric identity rather than a failing peculiar to Yanez. No scheme in this category has shipped an answer to it. Which means the first generation of biometric-only wallets will produce a wave of permanently unreachable assets, and somebody will eventually have to build the inheritance layer that fixes it.
**The attack didn't vanish, it moved.** If there's nothing stored, theft stops mattering and injection starts. Record a face, feed it into the app, pass as the person. That's the whole game now, and it's why presence is doing the heavy lifting rather than sitting there as the third item on a list. This is also the answer to why any of this needs Bittensor. Defending a live moment against forgers who improve every week is not a thing you can hire, budget for, or finish.
Yanez's miners spend their days attacking the company's own system, "trying to fake biometrics and trying to inject biometrics," and getting paid when they succeed. A permanent, distributed, financially motivated red team is what an incentive mechanism buys you and what a hiring process cannot. Jose's read on how that contest ends is that it doesn't: "It's an arms race, and it will always be an arms race." That's the honest centre of the whole thing. Yanez isn't selling a solved problem, it's selling a machine for staying level with an adversary who never stops, and if that sounds like a weaker pitch than the alternative, notice that the alternative is a lie.
**A key that works everywhere can be followed everywhere.** For any of this to function, your key has to be the same key each time, because the product is a service being able to tell you're the person it met before. That sameness is the feature. It's also a trail. Use the same key on a governance vote, a payments app and a health portal, and all three have now seen it. None of them learns your name or your face, and any two of them could still work out that their user is the same person, if they ever compared notes. Yanez names an answer to this on its site, called contextual binding, which scopes the credential so each application gets its own version rather than the universal one. That's the right shape of fix, and it's the part of the design worth reading closely, because whether your uniqueness stays private turns entirely on how carefully it's built.
## Three questions to ask before you hand over a biometric
Does the biometric leave the device, or does it end up on somebody's server? Is the credential scoped to each application, or is it one universal key following you everywhere you use it? What happens when the body changes, and what happens when it stops?
## The bet underneath all of it
Jose's read is that most internet traffic is bots and agents already, and every system we built for telling the difference was designed back when it wasn't. That's the bet: that "is there a person here" becomes a question worth paying to answer properly, and that the answer has to be a primitive rather than a product bolted onto the side of one.
If they're right, the object you've spent years protecting stops being the point. There'll be nothing in the safe, and that will be the safest thing about it.
And it stops being about wallets fairly quickly. The same three claims sit underneath a governance vote, a payment an agent authorises on your behalf, a medical record, a byline, any place at all where what matters is whether there's a person on the other end and how many of them there are. The seed phrase in your drawer is just the version of the problem you happen to hold in your hand.
So what would you need to see before you'd let a machine vouch that you're a person?
---
https://www.yanez.ai
https://x.com/yanez__ai
https://x.com/josercaldera