Skip to content

Verify CLI recovery identity before wallet import #30

Description

@BenWestgate

ms32 wallet could import recovered descriptors before the operator authenticated the recovered seed as the wallet they intended.

This is an accident-safety gate, not a malicious-share-tampering defense. A party able to replace a threshold of shares can already learn/spend the wallet and can deliberately manufacture human-scale identifiers.

Required restore evidence, strongest available first:

  1. Seed-keyed encrypted descriptor backup (wallet: Encrypted descriptor backup keyed by the seed #55): decrypt it with the recovered seed and require the recovered seed to match the backed-up single-sig descriptors before import. This is the first-class path and the separate malicious-tampering defense.
  2. Wallet record: accept a matching typed BIP32 master fingerprint and/or recorded single-sig descriptor checksum before import. These are human-scale second-class checks for wrong/mixed cards, miscorrection and transcription mistakes. wallet: Add checksummed recovery-record evidence #43 tracks checksummed/type-back record metadata.
  3. No wallet record: explicitly show the recovered fingerprint and codex32/Bails identifier result, warn that the wallet has not been independently identified, and require visual confirmation before import. This must work for older backups that have no fingerprint and for Bails/Bails-alpha identifier rules.

#57 implements the current release-gate subset for the CLI/library: typed fingerprint plus explicit no-record fallback, with the check enforced before wallet mutation. #28 is the GUI counterpart. #55 remains a separate issue so accident safety is not conflated with malicious-tampering resistance.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area: cliCommand-line interface behavior.area: securitySecurity invariants, hardening, and security-sensitive boundaries.area: wallet/coreWallet integration and Bitcoin Core boundaries.bugSomething isn't workinggate: adversarial reviewResolve, merge, or explicitly defer before the next full adversarial review.

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions