New Bitcoin proposal rescues locked multisig wallets

New Bitcoin proposal rescues locked multisig wallets


Bitcoin’s BIP138 wallet-backup proposal was merged into the Bitcoin Improvement Proposals repository on Sept. 21, but the specification remains Draft. It aims to preserve information that a seed phrase may not restore in a complex wallet. The tradeoff is that a third party could read that information if it already holds an eligible extended public key, or xpub, and obtains a copy of the encrypted backup.

A multisignature wallet requires more than one signer. Its descriptor records the public keys and spending rules that tell wallet software how to reconstruct the account and find its coins. A seed phrase can regenerate one signer’s private keys, but losing the descriptor can still leave a multisig or miniscript script impossible to reconstruct from that seed alone.

The proposal describes another failure: a wallet designed to survive the loss of one seed may also lose that signer’s public key. The remaining signers can then lack a piece of the script needed to recover the coins. These are risks for wallets whose spending setup depends on information beyond a seed, not a claim that every Bitcoin wallet needs this backup.

Related Reading

okex

A flaw in Coldcard seed generation lets attackers recreate private keys from the press of a button

BIP138’s answer is an encrypted file holding descriptors, wallet policies or other non-seed metadata. Private key material must be removed before encryption. A holder of an eligible xpub from the backed-up wallet can decrypt a copy without the wallet’s seed. That reveals public keys and script structure needed for recovery, while the xpub alone does not give the holder the private keys required to sign.

The draft sets limits on who can decrypt. Public keys that appear directly in a script, and xpub roots that could be exposed by spending, are excluded as recovery keys. If a cosigner’s key is excluded, that person cannot use it to open the file. Those limits keep an on-chain public key from becoming a key to the off-chain backup.

The Catalyst

What’s moving crypto. Why it matters.

Get CryptoSlate’s essential stories and what to watch next.

Published on Substack

Seven days a week. Unsubscribe anytime.

Whoops, looks like there was a problem. Please try again.

BIP138 draft infographic showing why a seed may not restore a multisig wallet without its descriptor, how an eligible xpub can decrypt an encrypted metadata backup, and the three conditions for a server to read it.

The privacy warning concerns an xpub disclosed before the multisig wallet was made. If a wallet-service server already knows an account xpub and that same xpub is reused as an eligible multisig key, the server could decrypt the backup if it gets a copy. It could learn the wallet metadata inside, though this would not itself give it spending authority. The BIP describes a conditional exposure, not a reported breach.

Related Reading

Bitcoin’s newest mobile privacy feature can make your incoming money completely invisible

A public Rust implementation with command-line build instructions exists. The BIP says Liana, a Bitcoin wallet, uses an earlier backup format that is incompatible with the current BIP138 file. The proposal’s merge therefore establishes a published draft, not a Bitcoin network change or a guarantee that today’s wallets can create and restore this format.

Related Reading

Popular Bitcoin wallets risk losing support for new hardware devices as critical security bridge stops accepting new devices



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *

Pin It on Pinterest