Repository navigation
Verify CLI recovery identity before wallet import #30
Description
Activity
- added a parent issue
on Sep 22, 2026 - addedgate: adversarial reviewResolve, merge, or explicitly defer before the next full adversarial review.Resolve, merge, or explicitly defer before the next full adversarial review.duplicateThis issue or pull request already existsThis issue or pull request already exists
on Sep 24, 2026 - added a commit that references this issue
on Sep 24, 2026 First class:
The user has already selected their descriptor.gpg, they can decrypt and verify their bip85 derived signature on that to give full assurance the proper wallet this seed can sign for is restored.Second class:
The user has their wallet record and manually types in the fingerprint, they also reentry ceremony confirmed the fingerprint during creation as it's recovery metadata.This doesn't protect it against damage in storage however, so I still want to checksum it.
Here the wallet would not be restored until the user typed in their fp.Under some circumstances we can skip validation and warn the wallet may not belong to them and to verify addresses, history, fingerprint, policy, balances.
If possible we can sign and encrypt the descriptor using Bitcoin Core's sign message feature. That would avoid some GPG dependency maybe.
Simple authenticated encryption may work as well for single user descriptors, GPG is most useful when coordinators need to send the finished descriptor back to the user.
- addedenhancementNew feature or requestNew feature or requesthelp wantedExtra attention is neededExtra attention is neededquestionFurther information is requestedFurther information is requestedwontfixThis will not be worked onThis will not be worked on
on Sep 24, 2026 - removedduplicateThis issue or pull request already existsThis issue or pull request already existsenhancementNew feature or requestNew feature or requesthelp wantedExtra attention is neededExtra attention is neededquestionFurther information is requestedFurther information is requested
on Sep 25, 2026 21 remaining items
- added 13 commits that reference this issue
on Oct 1, 2026 Fixed on
reviewability-v1by #57 (1eed32c, "Fixes #30"). The stronger descriptor-authentication work stays in #55.
Generated by Claude Code
ms32 walletcould import recovered descriptors before the operator authenticated the recovered seed as the wallet they intended.This is an accident-safety gate, not a malicious-share-tampering defense. A party able to replace a threshold of shares can already learn/spend the wallet and can deliberately manufacture human-scale identifiers.
Required restore evidence, strongest available first:
#57 implements the current release-gate subset for the CLI/library: typed fingerprint plus explicit no-record fallback, with the check enforced before wallet mutation. #81 strengthens
ms32 create --existingby making that wallet-record/no-record decision immediately after the existing seed is parsed and before any new share ceremony or output; Ctrl-C/EOF at that early gate preserves the existing recovery cards as valid. #105/#80/#95 are the reviewed stack follow-ups needed on the same frozen runtime tip. #118 is the focused clean GUI counterpart; historical #28 duplicates obsolete library history and must not be used as the final GUI candidate. #55 remains a separate issue so accident safety is not conflated with malicious-tampering resistance.Current remaining library/CLI order is #57 → #105 → #99 → #80 → #81 → #95. Every current head now has a current-head Codex release-gate ACK and green exact-head Python-package CI; the applicable restore/Core heads also have green Bitcoin Core fixture runs. No automated/code-review gap remains on this CLI finding. Keep this issue open through human integration of that stack and final frozen-candidate qualification.