A design bar for coercion-resistant custody, and where duressfeatures land against it

Aug 24 - Aug 26, 2026

  • The recent study published as a preprint on Zenodo delves into the vulnerabilities of self-custody systems to physical coercion, commonly known as "wrench" attacks.

The research introduces a specific criterion for evaluating the security of custody designs, which necessitates that these systems either completely eliminate any feasible path for attackers or decisively prevent them from accessing assets before the holder can. The study is accessible in full at Zenodo and emphasizes the importance of designing secure systems by considering the speed at which an attacker versus the asset holder can gain access, rather than merely focusing on cryptographic strength.

The primary challenge identified in creating such secure systems is the difficulty in proving a negative — specifically, proving that one has forgotten certain critical information. Since it's possible to demonstrate knowledge possession through actions like signing a document, the inability to show the inaccessibility or forgetting of information creates a significant vulnerability. If an attacker believes the holder can still access the asset, the motivation to exert force remains high. To counter this, the paper suggests strategies including the use of remote co-signers and time-lock-rescue vaults, which shift some control from individuals to more secure mechanisms, thus reducing the risk of coercive attacks.

Additionally, the paper critiques certain custody designs that allow for physical intervention, such as the use of a wallet-erase PIN or involving a physically co-located friend in the rescue protocol. These options are deemed less secure because they provide slower yet feasible paths for attackers, highlighting a crucial point of failure when the holder is under pressure and might not act effectively. The empirical analysis within the study reviews 352 documented incidents of physical attacks, shedding light on the practical strengths and weaknesses of various custody models and emphasizing the need for transparency in how security mechanisms function.

The study concludes by comparing the risks associated with the self-custody of cryptocurrencies to those involving jewelry, drawing on data available at GitHub. This comparison indicates that the actuarial costs related to Bitcoin self-custody are higher than those for jewelry, suggesting that reliance on obscure or flawed security methods could be particularly detrimental. The findings advocate for tailored security approaches depending on the user’s specific risk profile and asset value, and suggest incorporating sections that clearly define who each type of self-custody solution is suitable for, thereby enhancing understanding and application of effective protective measures.

Link to Raw Post
Bitcoin Logo

TLDR

Join Our Newsletter

We’ll email you summaries of the latest discussions from high signal bitcoin sources, like bitcoin-dev, lightning-dev, and Delving Bitcoin.

Explore all Products

ChatBTC imageBitcoin searchBitcoin TranscriptsSaving SatoshiDecoding BitcoinWarnet
Built with 🧡 by the Bitcoin Dev Project
View our public visitor count

We'd love to hear your feedback on this project.

Give Feedback