Posted by yurisvb
Aug 24, 2026/14:07 UTC
The recent preprint deposited on Zenodo addresses a critical aspect of security in self-custody systems, specifically focusing on the susceptibility to physical coercion or "wrench" attacks. The study presents a criterion for evaluating custody designs, emphasizing that such designs should not leave any feasible path for attackers or should decisively prevent them from accessing the assets before the holder can (read the full document). This criterion is crucial because, under duress, an attacker will evaluate whether they can access the asset faster than the holder rather than attempting to break the cryptographic security.
The paper outlines that the primary challenge in designing secure systems against such threats lies in the inherent difficulty of proving a negative—specifically, proving that one has forgotten certain information. Since it is possible to prove possession of knowledge through actions like signing a challenge, the absence of knowledge (or its inaccessibility) cannot be similarly demonstrated. This creates a vulnerability where, if an attacker believes the holder can still access the asset, the incentive to coerce remains.
Two main strategies are highlighted as effective in mitigating these risks. One approach involves eliminating any race conditions between the holder and the attacker by designing systems where the custody does not solely rely on the individual but involves a genuinely remote co-signer. This method has been implemented in existing solutions like time-lock-rescue vaults and collaborative custody models. These methods openly acknowledge their trade-offs in terms of individual control over assets, framing them not as flaws but as conscious design choices essential for security under the defined criterion.
However, the analysis also points out certain designs that fail to meet the proposed security standards. For instance, any system that allows the holder or someone physically close to intervene (like using a wallet-erase PIN or having a co-located friend as part of the rescue protocol) inherently leaves a slower, yet feasible, path for the attacker. Such designs provide a critical point of failure, as they rely on the holder being able to act under pressure, which may not be feasible during an attack.
Moreover, the empirical section of the study reviews 352 documented incidents of physical attacks, providing insights into the practical applications and limitations of various custody designs. The findings underscore the importance of designing systems that are not only technically sound but also practically robust against known threat vectors. The author advocates for transparency in security mechanisms, arguing that withholding information about how systems operate does not enhance security but rather leaves users ill-prepared to assess and mitigate risks effectively.
TLDR
We’ll email you summaries of the latest discussions from high signal bitcoin sources, like bitcoin-dev, lightning-dev, and Delving Bitcoin.
We'd love to hear your feedback on this project.
Give Feedback