Hey bhkien, great question, thanks. I will update the pre-proposal with this question and answer.
The plan is use a BIP32 HD set of addresses. This will allow the server to generate unique addresses for users, but ensure all funds flow into an offline hardware wallet, entirely separate from the...