New Bitcoin proposal rescues locked multisig wallets – At a hidden cost
Bitcoin's BIP138 wallet-backup proposal was merged into the Bitcoin Improvement Proposals repository on Sept. 21, but the specification remains Draft. It aims to preserve information that a seed phrase may not restore in...
Watchlist
Published in the last two hours. A tracked entity is involved.
Bitcoin's BIP138 wallet-backup proposal was merged into the Bitcoin Improvement Proposals repository on Sept. 21, but the specification remains Draft. It aims to preserve information that a seed phrase may not restore in a complex wallet. The tradeoff is that a third party could read that information if it already holds an eligible extended public key, or xpub, and obtains a copy of the encrypted backup.
A multisignature wallet requires more than one signer. Its descriptor records the public keys and spending rules that tell wallet software how to reconstruct the account and find its coins. A seed phrase can regenerate one signer's private keys, but losing the descriptor can still leave a multisig or miniscript script impossible to reconstruct from that seed alone.
The proposal describes another failure: a wallet designed to survive the loss of one seed may also lose that signer's public key. The remaining signers can then lack a piece of the script needed to recover the coins. These are risks for wallets whose spending setup depends on information beyond a seed, not a claim that every Bitcoin wallet needs this backup.
Related Reading A flaw in Coldcard seed generation lets attackers recreate private keys from the press of a buttonBIP138's answer is an encrypted file holding descriptors, wallet policies or other non-seed metadata. Private key material must be removed before encryption. A holder of an eligible xpub from the backed-up wallet can decrypt a copy without the wallet's seed. That reveals public keys and script structure needed for recovery, while the xpub alone does not give the holder the private keys required to sign.
The draft sets limits on who can decrypt. Public keys that appear directly in a script, and xpub roots that could be exposed by spending, are excluded as recovery keys. If a cosigner's key is excluded, that person cannot use it to open the file. Those limits keep an on-chain public key from becoming a key to the off-chain backup.
The privacy warning concerns an xpub disclosed before the multisig wallet was made. If a wallet-service server already knows an account xpub and that same xpub is reused as an eligible multisig key, the server could decrypt the backup if it gets a copy. It could learn the wallet metadata inside, though this would not itself give it spending authority. The BIP describes a conditional exposure, not a reported breach.
Related Reading Bitcoin’s newest mobile privacy feature can make your incoming money completely invisibleA public Rust implementation with command-line build instructions exists. The BIP says Liana, a Bitcoin wallet, uses an earlier backup format that is incompatible with the current BIP138 file. The proposal's merge therefore establishes a published draft, not a Bitcoin network change or a guarantee that today's wallets can create and restore this format.
Related Reading Popular Bitcoin wallets risk losing support for new hardware devices as critical security bridge stops accepting new devicesThe post New Bitcoin proposal rescues locked multisig wallets – At a hidden cost appeared first on CryptoSlate.
Why this matters
Bitcoin is showing up inside the Security Incidents theme, so this story is worth tracking for follow-through rather than treating it as a one-off headline.
Original source
Read on CryptoSlateRelated market context
US Charges Man After Crypto Scam Wallets Received More Than $53M
TL;DR U.S. prosecutors have charged a Vietnamese national with money laundering tied to alleged cryptocurrency “pig butchering” sc...
Bitget Halts Withdrawals After $351.6M Hot Wallet Incident Hits Crypto Exchange
Key Takeaways: Bitget reported unauthorized transactions of about $351.6 million that occurred in a portion of its hot & warm wall...
Bitget Confirms $351.6M Hot Wallet Breach And Pauses Withdrawals
Bitget says unauthorized transfers affected approximately $351.6 million held across parts of its hot and warm wallet infrastructu...
Crypto Hacks: Three Projects Hacked in One Day as Losses Hit Over $11M
Three crypto projects were attacked on September 24, suffering combined losses of more than $11M. Attackers drained around $1.8M f...
Washington has $114 billion reasons to want Tether around
Not that long ago, Washington fined Tether for misleading people about the dollars behind its tokens. Today, the company's insatia...
Ledger Opens 24/7 Tokenized Stocks to Millions With xStocks Integration
Key Takeaways: Ledger and a new partnership with Payward have brought xStocks to the Ledger wallet ecosystem. Eligible Ledger hold...