Four questions about your self-custody arrangement


You already have an arrangement: hardware wallet, passphrase, multisig, maybe a decoy, maybe an inheritance plan. The question isn't whether it's good. It's against what.

This audit answers four questions about the arrangement you already have, and delivers the answers in writing.

I never ask for your keys

First, because it's the part that matters.

I don't ask for your seed, your balances, your addresses or where you live. The audit works on the shape of your arrangement, not its contents. If a question can only be answered by you telling me what you hold, that question is out of scope.

This isn't courtesy. An auditor of coercion resistance who collected holder data would be assembling precisely the list my papers condemn. And data that was never with me cannot be seized from me.

The four questions

  1. Is your security based on a secret trick? Does it depend on the attacker not knowing what you do, and how you do it? If it does, the mechanism is obscurity, and obscurity has a catalogue number (CWE-656) in every domain that isn't bitcoin custody.
  2. Once your devices and secrets are seized, could the attacker spend right away, or only eventually? "Eventually" means you are still a competing racer for the same balance, and a race with a competitor within arm's reach puts a price on removing you.
  3. Is your custody strictly individual? Can anyone else do something that stops you reaching your own coins? Delegating is a legitimate answer. Delegating without noticing isn't, and neither is meeting the delegate for the first time on the worst day of your life.
  4. Does it depend on particular objects in particular places? A safe, a vault, a relative's house, a jurisdiction. And do you own those places? Every one of them is an address someone can reach, and a place you don't own is a place someone else can close.

What you get

A closed report, PDF. One section per question. Each answered not with yes or no, but with the specific place in your arrangement where it fails or holds, how bad it is, and the cheapest change that fixes it.

Turnaround and fee depend on how much arrangement there is to read, so both are quoted before anything starts.

What I don't do

I don't build decoys with denial training. It's the most requested service and the only one I refuse, for the whole argument of The Denial Spiral: a denial's credibility is a common resource, and selling fluency in denying depletes that resource for everyone, including people who never bought anything.

I don't promise security either. The report says what fails and what holds. There's no seal of approval here, and be suspicious of anyone offering one.

And I don't sell software. Great Wall, BTC-D20, BIP-450 and the papers are MIT or Apache-2.0, and that doesn't change: no "pro" version, no feature unlocked by payment, no priority queue for donors. It's written down in the support repository, and it's written there because a promise in an article is worth nothing and a promise in git has a date. What I sell is time.

The Great Wall implementation is a prototype. Don't put your savings behind it yet. When that changes it will be written down, with a date, in DELIVERED.md.

The most common outcome

In most audits the recommendation is to adjust what you already have. In some the verdict is that it's reasonable, and you get that in writing.

Starting

yuri@t3infosecurity.com

Tell me roughly what kind of arrangement you use. No numbers, no addresses, no keys.