Posted by shinobi
Jul 24, 2026/00:40 UTC
The email presents a detailed discussion on enhancing the security measures for cryptocurrency transactions and recovery mechanisms to protect coins by their rightful owners. The sender proposes multiple recovery schemes that work additively to ensure comprehensive coverage across all address types, provided the owners still possess their private keys. These schemes include new additive encumbrances requiring proof of secret knowledge alongside a signature from a private key, and commit-reveal schemes that necessitate a certain number of blockchain confirmations before a transaction becomes valid.
One of the primary strategies highlighted is the use of Xpub derivation-based recovery, which is applicable to any BIP 32 based wallet regardless of the derivation path used. This approach would cover addresses created using both legacy and newer derivation paths that secure public keys through protocols like Electrum. For hashed-address types such as P2PKH, P2SH, P2WPKH, and P2WSH, the derivation proof alone would suffice for recovery, addressing the vulnerability without requiring proactive measures from users prior to implementing a fork.
The sender also discusses stateful timestamped proofs, which involve a signature over a new public key/authentication mechanism coupled with a timestamp. This method aims to confirm the authenticity of the attestation before a predetermined deadline, tailored to preempt the emergence of viable quantum computing threats. Although these proofs demand proactive action and could be large in size, their potential efficiency in terms of block space makes them an appealing option compared to more complex Zero-Knowledge Proofs (ZKPs).
Furthermore, the commit-reveal migration scheme is revisited, which requires an encrypted commitment to a transaction to be confirmed in the blockchain for a predefined period before the transaction in plaintext can be deemed consensus valid. This method ensures the continued secrecy of public keys, even for coins in legacy derived addresses and is considered valid for P2TR keyspends if an internal key forms part of the additional validity requirements.
In conclusion, the sender believes that by combining these mechanisms, it is possible to achieve 100% recovery coverage for all network address types, excluding P2PK outputs and custom bare scripts, with the main new security assumption being the maintenance of public key secrecy. This could potentially be implemented seamlessly behind the scenes for users, thus avoiding the need for generating new master keys or migrating funds across different seeds. The sender seeks feedback on any possible oversights or important details that might have been missed in this proposal.
TLDR
We’ll email you summaries of the latest discussions from high signal bitcoin sources, like bitcoin-dev, lightning-dev, and Delving Bitcoin.
We'd love to hear your feedback on this project.
Give Feedback