15 Nov 2022, I wrote a little SN article titled: How I Got Hacked and STILL Didn't Lose my Bitcoin. How I reacted to the hack is to be honest a little embarrassing. Installing anti-virus while you have a virus has so many reasons to make the situation worse rather than better. The reason I shared that experience anyway, was to talk about multi-sig as a risk mitigation.
Cold card users right now are learning the dice rolling technique for mitigating the risk of bad entropy generation. They've lived bad entropy generation. Multi-vendor multi-sig, then mitigates the risk of any critical failure (intentional or accidental) on any one device at a time allowing you time to migrate to a new multi-sig setup without that vendor in the mix.
I mention all of this to demonstrate that CTV vaults are not the ONLY way to mitigate catastrophic risk. Now I would like to talk about how vaults make risk mitigation much more convenient for average users.
Creating a WalletCreating a Wallet
First and foremost, early into the CTV discussion there was some misunderstanding that a third party would be able to say something like "Make sure you have one of these predetermined addresses (somehow) or we won't send you your Bitcoin". This does happen with some wallets. They only let you send to other wallets that they trust in some way. Some exchanges may ask you where you're sending your Bitcoin, all without CTV. However, this dissuades people from using said wallets or exchanges, to the point that the average person doesn't even know about them.
Secondly, anyone who has created a multi-sig wallet, can easily imagine how creating a CTV (specially vault in this case) wallet would look like. You create your wallets on other devices, then bring the xpubs into one main software to combine it all with Bitcoin script to give you your addresses. When it comes to multi-sig, some companies like unchained are educating customers on how to do it, while others like bitkey are integrating it into their software such that the user, who in these cases don't even know how to back up their seed phrase to allow them to restore it later, have that risk mitigated by another means (two other keys spending to a new wallet in this case). You can easily imagine the same for CTV enabled vaults.
The ScenarioThe Scenario
If you're a cold card user, and you watched your Bitcoin leaving your wallet. You freak out, troubleshoot some software, and after a day or two you finally accept its gone. If you had the ability to say "No! get back here!" even to a hot wallet, you would (not that you should, but keeping the scenario real here).
In this alternate reality, your cold card is one signer in a CTV enabled vault. The other wallet is not able to spend the funds, but rather is a required path that funds must take when being spent under certain conditions. [1]
To keep it simple:
You're a cold card user. You have your funds in a CTV vault. You watch as your money gets drained. You remember that you set a timelock of 7 days (counted in blocks mined) to go submit a transaction that forces those funds to come back to another wallet you had set up. Even if that other wallet you had set up was a shitty wallet you installed from a phone app store (which is an extreme case, not a recommendation)
Why Rush CTV?Why Rush CTV?
Everytime I write another article about why CTV is so great, I will ultimately get the question, "Why rush it?" Annoyed, I'll type, I'm not rushing, I'm evaluating and sharing, but look, there is a good argument for more urgency around CTVs activation. If cold card users had access to vaults, they could have clawed their funds back. Not every user would have set it up, and vaults are not the only way to mitigate risk, but between the risk mitigation strategies told to users, you can see which ones get the "That's too complicated for normal people" treatment, and which ones get the "This seems good" treatment.
For my fellows who would also like to activate CTV, write software. We need demonstration software to show our fellow node runners what these CTV enabled experiences will be like. No amount of writing will convince users who don't understand what you're saying. Hands on experience is the best way to communicate such that it reduces that gap.
May the next critical flaw in the next signing device, be exciting, but ultimately of no consequence.
Thank you to Spark's article for helping me explain the vault process in better detail than magic wand hand waving ↩
Bunch of rubbish, the CC bad entropy would just have compromised your vault recovery key and you'd be in a RBF hope for the best situation just as they were anyway.
Covenants supporters talk out both sides of their mouths on this.
If this is true, then no one can ever trust Bitcoin they receive.
They respond, "Well you'd give buyers an unrestricted address"
So, an attacker would do the same.
More crypto-theater nonsense. Vaults are either useless, or make Bitcoin useless. Pick one. They are mutually exclusive outcomes.
I read what you're saying as: it opens another avenue to social engineering attacks where a service or peer will tell you: "look bro, we put your coin in a staging address
<not-the-addr-you-gave>, it's yours, you can take it out any time." Only to find that this coin cannot be taken out, that the counterparty lied, and they still fully control the coin.This will not happen often, simply because most people aren't scammers and the complexity of such a scam is high. But the practice of not getting delivery of coin into the spending script you specified will get somewhat normalized by a service that deploys it for some half-legit reason. People will get used to it. And then the "trust" built by that will be abused by scammers.
The worst thing that can happen is that some overeager control freak of a regulator, or FATF, will propose a scheme using this for onramps, and standardizes/enforces it. That's when the touch point between the Bitcoin and fiat economies gets ruined even more than it already is.
However, do we have a precedent? We do see the wrappers on CEXs. I guess they have wrappers for everything now, like Binance popularized at one point, so you can "withdraw" your sats into the wrapper they control, in fact, they used to recommend it over withdrawal. Hiding that these aren't your coins through opaque bullshit narratives; the illusion of control because they give you keys (to an IOU, not to sats.) I remember painfully needing to mansplain that the "withdraw to Binance Chain" option is not a good option on multiple occasions and that no, the Bitcoin in your Binance Wallet isn't Bitcoin until you managed to take it out.
The same could happen here but it will all depend on the wallet software you are using. If it does not clearly distinguish between coin you own and coin you maybe could own because it is sitting in a CTV utxo you didn't spec yourself, then your scenario of getting clawed back is realistic. It can be defended against but not everyone will understand that.
However, the main downside of vaults is that they are static and strict. So if I have coins sitting safely in a vault right now, but I fucked up the thawing address and that is now on a pregenerated watchlist, I will have a really complex obstacle to get it out. Everything becomes more static. Can of course thaw into a multisig but then what is the added value over just keeping it in a multisig? The security of the thawing address becomes an additional burden that combined with the added complexity makes the scheme somewhere between almost-as-risky and more-risky than juggling multisig keys to a single unconstrained script series.
For me personally, I'd probably use it. Segregate it properly though, not everything on a single path. From a selfish perspective, I'd not mind this going in. I'd not even mind any potential lasting onramp snafus or trickery from exchanges; they'll be tricking everyone anyway.
The only consideration for me to be cautious is others.
One would not accept the staging address as final payment in the same way that one would not accept a transaction in the mempool as final payment.
...You don't accept a transaction in the mempool as final payment..do you lurking reader?
covenants looks more like a honeypot for clueless for me than anything useful.
few things in bitcoin are really urgent and this is not one of them
Use often precedes understanding. There's absolutely no reason that Bitcoiners should be denied covenant functionality.
This is a perfect example of why I say we need demonstration software. So that our peers can stop making up fear mongered bullshit and talk about their actual experience of use with it instead.
I said a little more urgency. As in, stop sleeping on it, not as in activate next year while the broader community still feels like they don't understand it.
As I'm so intrigued by this upcoming eCash fork, all these additions can be bolted 🔩 onto it, like opCat, opVault etc etc
Then we'll see it as a testing ground, it either works or it doesn't
Of course there are nuances
But supporters of the lightning network for example, say that lightning is the best option we have, they don't say it's perfect in every way, so in that frame if the choice is between lightning and something else, they take lightning as the best we can do currently, which is a trade off
So others will be proponents for drivechains and those also have Trade-offs
Will be interesting to see how the future pans out
🤔