|

New Bitcoin proposal rescues locked multisig wallets – At a hidden cost

BIP138 draft infographic showing why a seed may not restore a multisig wallet without its descriptor, how an eligible xpub can decrypt an encrypted metadata backup, and the three conditions for a server to read it.

Bitcoin’s BIP138 wallet-backup proposal was merged into the Bitcoin Improvement Proposals repository on Sept. 21, however the specification stays Draft. It goals to protect info that a seed phrase might not restore in a advanced pockets. The tradeoff is that a third get together might learn that info if it already holds an eligible prolonged public key, or xpub, and obtains a copy of the encrypted backup.

A multisignature pockets requires multiple signer. Its descriptor data the general public keys and spending guidelines that inform pockets software program the best way to reconstruct the account and discover its cash. A seed phrase can regenerate one signer’s non-public keys, however shedding the descriptor can nonetheless go away a multisig or miniscript script unimaginable to reconstruct from that seed alone.

The proposal describes one other failure: a pockets designed to outlive the lack of one seed might also lose that signer’s public key. The remaining signers can then lack a piece of the script wanted to get better the cash. These are dangers for wallets whose spending setup depends upon info past a seed, not a declare that each Bitcoin pockets wants this backup.

Related Reading

A flaw in Coldcard seed generation lets attackers recreate private keys from the press of a button


BIP138’s reply is an encrypted file holding descriptors, pockets insurance policies or different non-seed metadata. Private key materials should be eliminated earlier than encryption. A holder of an eligible xpub from the backed-up pockets can decrypt a copy with out the pockets’s seed. That reveals public keys and script construction wanted for restoration, whereas the xpub alone doesn’t give the holder the non-public keys required to signal.

The draft units limits on who can decrypt. Public keys that seem instantly in a script, and xpub roots that might be uncovered by spending, are excluded as restoration keys. If a cosigner’s key’s excluded, that particular person can’t use it to open the file. Those limits preserve an on-chain public key from changing into a key to the off-chain backup.

BIP138 draft infographic showing why a seed may not restore a multisig wallet without its descriptor, how an eligible xpub can decrypt an encrypted metadata backup, and the three conditions for a server to read it.

The privacy warning considerations an xpub disclosed earlier than the multisig pockets was made. If a wallet-service server already is aware of an account xpub and that very same xpub is reused as an eligible multisig key, the server might decrypt the backup if it will get a copy. It might be taught the pockets metadata inside, although this is able to not itself give it spending authority. The BIP describes a conditional publicity, not a reported breach.

Related Reading

Bitcoin’s newest mobile privacy feature can make your incoming money completely invisible


A public Rust implementation with command-line build instructions exists. The BIP says Liana, a Bitcoin wallet, makes use of an earlier backup format that’s incompatible with the present BIP138 file. The proposal’s merge due to this fact establishes a revealed draft, not a Bitcoin community change or a assure that at present’s wallets can create and restore this format.

Related Reading

Popular Bitcoin wallets risk losing support for new hardware devices as critical security bridge stops accepting new devices


The submit New Bitcoin proposal rescues locked multisig wallets – At a hidden cost appeared first on CryptoSlate.

Similar Posts