Keys to Nowhere: The Cryptography Revolution Thwarting Nation-State Hackers
- By Winston Thomas
- March 24, 2025

When Chinese hackers infiltrated at least eight major U.S. telecommunications companies in 2024, they didn’t just breach a few systems, they established what intelligence officials describe as persistent, sprawling access across America’s communications infrastructure. Months later, investigators still can’t determine the full extent of the damage.
The breach exposed an uncomfortable truth: traditional cybersecurity approaches have failed but large critical infrastructure players are slow to act on it. Even so-called "zero-trust" architectures — the gold standard in enterprise security — proved inadequate against determined state actors armed with stolen credentials and unlimited patience.
But what if the next evolution in cybersecurity renders such breaches meaningless? What if we designed systems that assume hackers will get in — and ensure they still walk away empty-handed?
Mike Loewy, chief executive officer of Tide Foundation, believes that’s exactly what’s needed. His company’s approach, called “ineffable cryptography,” could represent the most significant paradigm shift in data protection since encryption itself.
“Traditional cybersecurity relies on safeguarding static encryption keys—often stored in vaults or held by privileged admins — which creates single points of failure,” Loewy explains. “If an attacker steals or leaks those keys, they can decrypt data and bypass defenses, effectively ‘owning’ the system.”
The breach-assumed paradigm
TideCloak’s approach (which is a Tide product) starts with a counterintuitive premise: not just assuming that the worst will happen but has already happened.
“TideCloak’s ‘breach-assumed’ paradigm flips this model by actually assuming attackers will penetrate defenses and designing security accordingly,” says Loewy. “Instead of central keys, it uses ineffable cryptography: keys are never stored whole but are split into fragments across a network of independent nodes. No single machine or administrator ever holds a complete key.”
This isn’t just theoretical. In real-world deployments, Loewy has seen the approach neutralize attacks that would have been catastrophic under traditional security models.
“In a TideCloak-protected system, a compromised admin account yields no usable keys or credentials—the attacker would only obtain meaningless key fragments insufficient to unlock any data,” he notes.
Dr. Matthew Skerritt of RMIT University, an early adopter of the technology, likened it to how the brain stores information: “No single neuron has the whole thought, so grabbing a few neurons reveals nothing.” Similarly, TideCloak's decentralized key management means an attacker cannot assemble a secret by breaching one server or admin — the ‘idea’ isn’t in one place, adds Loewy.
Math as defense
The mathematical foundation behind TideCloak feels formidable. It combines nested Shamir Secret Sharing, non-interactive threshold cryptography, multi-party computation, and zero-knowledge proofs — cutting-edge cryptographic principles that have undergone rigorous peer reviews from multiple universities.

What makes this approach different from conventional encryption is that it doesn’t just lock data away. Instead, it fundamentally changes how authentication and authorization work.
“Even if an attacker gains a foothold in the network or compromises a privileged account, they still cannot escalate to mass data theft,” says Loewy. “The breaches at major telcos have a common theme: attackers found a single weakness and leveraged it to gain expansive access. With TideCloak, there are literally no keys to the kingdom to be found.”
This approach has shown remarkable results in high-stakes environments, including critical infrastructure protection.
“During a simulated nation-grade attack, adversaries who penetrated a facility's network still couldn’t manipulate pump controls or valve settings — the commands remained locked behind TideCloak’s distributed key network, impervious to tampering,” Loewy recounts from a water utility deployment.
Breaches that yield nothing
Perhaps the most compelling about TideCloak’s approach is how it changes the economics of hacking. When breaches yield nothing of value, attacks become pointless.
“A breach that once yielded an attacker millions of customer records now might yield them nothing of value,” explains Loewy. “Even worst-case intrusions are contained to trivial fragments that don’t compromise the whole.”
This appears to be true even against the most sophisticated threats — the kind nation-states deploy. In multiple red-team simulations, TideCloak prevented "100% of unauthorized data access attempts by a simulated rogue administrator, whereas a standard zero-trust setup allowed certain critical files to be accessed when the team used valid (but stolen) admin tokens."
The implications of the recent Chinese hacking campaign are clear. Had the telecom companies been protected by a system like TideCloak, the attackers might have gained access to systems but would have been unable to extract meaningful data or credentials.
The insider threat solution
TideCloak’s ability to defang nation-state hackers can also be used to address insider threats — historically one of the hardest security problems to solve.
“TideCloak tackles insider threats by removing unilateral power — no single person, not even a senior administrator, can access protected data or encryption keys on their own,” says Loewy. “Not even us at Tide.”
Instead, the system implements what Loewy calls a “T-of-N authority model,” similar to nuclear launch codes: “For example, if an admin wants to grant themselves access to a vault of customer data, the system would require cryptographic token approvals from two or three other independent admins before the data is decrypted.”
This dramatically reduces the risk posed by compromised credentials. Even if a hacker steals an admin’s account, they’d still need to convince multiple other administrators to approve suspicious access requests.
A democratized defense
Unlike many advanced security technologies, TideCloak isn’t just for Fortune 500 companies with unlimited cybersecurity budgets.
“TideCloak was intentionally designed with unlimited scalability and global accessibility in mind,” Loewy says. “Small and mid-sized firms stand to gain enormously because they level the security playing field between them and the giant enterprises."
The technology is delivered as an API that developers can integrate with minimal disruption. "It’s just an API call away," as Loewy puts it.
This accessibility could prove critical as Chinese hacking campaigns continue to target not just large telecom providers but companies of all sizes throughout the supply chain. It also helps to harden security at the small and mid-sized companies that are often targets for supply chain attacks.
The future of cybersecurity
As the U.S. government urges companies to address the cybersecurity gaps that enabled the Chinese telecom breaches, solutions like TideCloak represent a potential path forward that goes beyond just patching the latest vulnerabilities.
“From a CISO perspective, TideCloak offers a radically diminished attack surface,” argues Loewy. “Breaches that have made headlines, where intruders navigated to crown-jewel data undetected, simply don’t have an easy analog in TideCloak’s world."
While no security technology is perfect, TideCloak’s approach represents a fundamental rethinking of how we protect critical data. By assuming breach from the start and designing systems that remain resilient even when compromised, it could render even the most sophisticated state-sponsored attacks ineffective.
Such an approach may not stop all nation-state attackers, hell-bent on cyberespionage, disruption, and degrading critical infrastructures as seen in Ukraine cyberattacks. But it exposes them as they no longer can hide behind other hackers motivated by finance and data theft or work in grey areas where profit-motivated hacking groups align with nation-states cyberespionage teams, offering the latter plausible deniability and legal cover.
As Loewy puts it: “In cybersecurity, you win when your adversary decides the effort isn’t worth the payoff, and TideCloak is built to tilt that equation in defenders’ favor.”
For telecommunications companies and other critical infrastructure providers still reeling from the recent Chinese attacks, that’s a compelling proposition.
Image credit: iStockphoto/Nattapon Kongbunmee
Winston Thomas
Winston Thomas is the editor-in-chief of CDOTrends. He likes to piece together the weird and wondering tech puzzle for readers and identify groundbreaking business models led by tech while waiting for the singularity.