← Back to Blog

VEYRNOX · Blog · Aug 20, 2026 · 14 min read · By Al Jobson, Founder

Decoy Wallets and the Missing Network Layer

Veyrnox duress decoy wallet — main wallet and decoy wallet side by side
A duress decoy hides the real balance under coercion — but it says nothing about who is watching the chain.

Every decoy scheme shipping in a mainstream wallet today — Trezor's duress PIN, Ledger's decoy passphrase, Coldcard's BIP-39 25th word, multisig geo-splits — solves exactly one problem: a person is standing next to you and asks you to open your wallet. None of them addresses the second, quieter attacker: a passive observer with access to the blockchain and, increasingly, to your ISP. That is the network-layer problem. It's the layer almost nobody covers.

This post separates the two problems, walks the documented history of both defenses, and lays out an honest comparison of what each strategy actually protects. It also collects the physical crypto attacks that shaped the field between 2018 and 2026 — the ones with public court records or on-the-record reporting, not the ones people invent to sell wallets.

Two attackers, two threat models

The word "decoy" gets used for two completely different defenses, which is why the conversation stays confused. Bruce Schneier's rubber-hose framing is a good place to start: strong cryptography is trivially defeated by an attacker willing to hurt you until you decrypt.[1] The famous xkcd cartoon compressed the same insight into a $5 wrench.[2] That's the coercion problem. It's about UX: what an attacker sees on your screen and what they can force you to type.

The surveillance problem is different. Chain analysts — Chainalysis, TRM Labs, Elliptic — sell software that clusters addresses, follows funds through mixers, and hands prosecutors and adversaries a graph of who transacted with whom.[3][4][5] Chainalysis Reactor, marketed to law enforcement in more than 70 countries, visualises fund flows across the majority of major chains.[3] That attacker never speaks to you. They subpoena the exchange, run the trace, and show up with a warrant. Nothing on your phone's UI defends against it.

A properly designed decoy strategy has to name which of these it addresses. Most don't.

Where "plausible deniability" came from

The idea of a decoy container predates crypto. TrueCrypt (2004–2014) shipped a "hidden volume" feature: a second encrypted volume inside the free space of a first one, accessed by a different password, cryptographically indistinguishable from random noise.[6] When TrueCrypt shut down in May 2014 under still-unexplained circumstances, its fork VeraCrypt inherited the design and remains actively maintained. VeraCrypt's docs are explicit that plausible deniability only works if the user is disciplined about not leaving forensic traces of the hidden volume — recent-file lists, thumbnail caches, and hibernation files can all give it away.[7]

That caveat carries directly into crypto wallets. A decoy wallet with a real wallet's transaction cadence on the same device — same clipboard history, same push notifications, same address book — leaks. The technical primitive is only ever half the defense.

The UX decoy family

Duress PINs

Trezor's original PIN-protected wipe (a.k.a. "wipe code") lets you set a secondary PIN that, when entered, factory-resets the device before any attacker can extract anything.[8] This is destructive rather than deceptive — the attacker knows something happened, they just have nothing to work with. Coldcard goes further with a full duress PIN system that opens a real, on-device secondary wallet with its own balance, giving the attacker something to walk away with.[9] The Coldcard also supports a "brick PIN" that permanently destroys the secure element.[9]

Veyrnox emergency controls — duress PIN, panic wipe, and local key protection
Emergency controls handle the person in front of you: a duress PIN opens a decoy, a panic path wipes the device.

BIP-39 passphrase as a hidden wallet

The BIP-39 spec added an optional passphrase — sometimes called the "25th word" — that mixes into the seed to derive a completely separate wallet.[10] Every hardware wallet that implements BIP-39 supports this. The idea: your standard 24-word seed derives a low-value decoy wallet; the same 24 words plus a passphrase derives your real wallet. An attacker who forces you to reveal the seed gets the decoy. Ledger, Trezor, Coldcard, and Keystone all document the pattern.[11][8]

The failure mode is human. Forget the passphrase and the wallet is unrecoverable; the seed alone is worthless. Write the passphrase down next to the seed and you have made the whole scheme theatre. Trezor's own docs note that a passphrase is "harder to recover than a seed" and that most user losses come from passphrase forgetting, not attacks.[12]

Multisig geo-split

A 2-of-3 multisig with keys held in different physical locations — or by different parties — means no single point of coercion. Casa and Unchained Capital productised the pattern for high-net-worth Bitcoin holders.[13][14] The coercion resistance is real: the wrench in one country cannot reach the safe deposit box in another. The cost is setup complexity, recovery drills, and the reliance on a service provider or a trusted second signer.

The network-layer decoy family

Network-layer decoys tackle the other attacker. Instead of hiding what an in-person adversary sees on your screen, they hide what a passive observer sees on the chain and on the wire.

Veyrnox private, no-cloud custody — keys stay on the device, not on a server
Keeping keys on-device rather than in a vendor cloud removes one class of subpoena, but chain and ISP traces still tell a story.

CoinJoin, Stonewall, Whirlpool

CoinJoin, first proposed by Gregory Maxwell in 2013, batches multiple users' inputs and outputs into one transaction so an outside observer cannot tell which input paid which output.[15] Wasabi Wallet (2018) and Samourai Wallet's Whirlpool (2019) shipped production CoinJoin implementations, and Samourai's Stonewall constructed CoinJoin-lookalike transactions from a single user's UTXOs to confuse heuristics even without a second party.[16][17]

Both are now essentially dead as products. In April 2024 the U.S. Department of Justice unsealed an indictment against Samourai Wallet's founders, seizing the servers.[18] Wasabi's operator zkSNACKs discontinued the coordinator in June 2024, citing the same legal risk.[19] The technology still exists in open-source forks (JoinMarket, Ashigaru, Kruw's coordinator) but the mainstream distribution channels are gone.

This matters for the decoy conversation because it means the network-layer defense with the largest historical user base is no longer a default in any wallet a normal person will install. The UX decoys survived; the network decoy did not.

Dandelion, Dandelion++, and P2P-layer anonymity

Even without CoinJoin, transaction broadcast leaks information. Fanti et al.'s 2017 Dandelion paper and its 2018 successor Dandelion++ showed that the default flooding gossip in Bitcoin's P2P layer lets an ISP-level observer link transactions to originating IP addresses.[20][21] Dandelion++ routes each transaction through a random path of peers ("stem phase") before entering normal gossip ("fluff phase"), so the first peer to broadcast is not the originator. Monero adopted Dandelion++ in 2020;[22] Bitcoin Core has not.[23]

Traffic decoys — the honest name

True traffic-layer decoys — sending fake transactions specifically to poison an observer's clustering — remain a research topic rather than a shipped feature. Monero's ring signatures produce decoy inputs at the protocol level: each spend references N–1 unrelated outputs so an observer cannot tell which was actually spent.[24] That is the closest thing to a network-layer decoy shipping in a production wallet today, and it is not a bolt-on — the entire chain design has to support it.

What the surveillance side actually looks like

Naming the surveillance vendors makes the threat model concrete. Chainalysis reported in its 2024 Crypto Crime Report that its Reactor product is used by public and private customers in more than 70 jurisdictions and tracks over $14 trillion in on-chain activity.[3] TRM Labs reports similar scale and publishes free case data for law enforcement.[4] Elliptic has been public about tracing funds through Tornado Cash mixer deposits and reconstructing user flows despite the mixer's anonymity set.[5]

Ari Juels and colleagues at IC3 have written on the limits of these tools — including a 2024 paper on the deanonymisation cost curve for privacy tools built on top of transparent ledgers.[25] The consensus finding is uncomfortable: with enough time, subpoenas, and off-chain data, most on-chain privacy tools have been broken to at least a probabilistic level for targeted investigations.

Comparison: four decoy strategies, four threat axes

Decoy strategies across four threat axes. Green = you want this. Red = you don't. Protection columns: Strong = attack surface closed, None = fully exposed. Setup: Simple = one-time, Complex = ongoing effort. Recovery: Safe = redundant paths, Fragile = single point of failure.
Strategy Coercion protection Passive-observer protection Setup complexity Recovery risk
UX decoy PIN (Trezor wipe, Coldcard duress) Partial. Strong if the attacker is unaware; falls to Weak if they know the wallet vendor. None. Real wallet still broadcasts identifiable transactions. Simple. Set at device init. Safe. Real wallet still recoverable via seed.
BIP-39 passphrase hidden wallet Solid. Depends on the attacker not knowing that passphrases exist for this seed length. None. Real wallet still broadcasts identifiable transactions. Moderate. User must memorise a strong passphrase and rehearse it. Fragile. Passphrase loss = wallet loss. No cloud fallback by design.
Multisig geo-split (Casa, Unchained, self-hosted 2-of-3) Strong. Attacker cannot reach all key locations in one action. Weak. On-chain multisig scripts are distinguishable and cluster the same way. Complex. Multiple devices, quorum drills, service or trusted co-signer. Moderate. Loss of two shards = wallet loss.
Network-layer traffic decoy (CoinJoin, Whirlpool, Monero ring signatures) None. Attacker with your PIN can still spend. Strong for Monero (protocol level); Partial for CoinJoin (mixer risk, DoJ scrutiny); None for the average phone wallet in 2026. Moderate. Requires either a chain that supports it or a third-party coordinator. Safe if custody is unchanged; Fragile when using a custodial mixer.

The pattern the table makes visible: no single strategy covers both axes. Combining strategies is possible in theory (passphrase-hidden wallet feeding a Monero atomic swap, say), but each combination adds surface area for user error. The real design question is which single defense a given user actually needs — and for most people the honest answer is "the one they'll still follow six months from now."

Documented physical attacks, 2018–2026

The best public register of physical Bitcoin attacks is maintained by Jameson Lopp.[26] The list is source-linked to news reports and court filings; the timeline below draws only from entries with public reporting or unsealed indictments, plus 2024–2026 cases covered by Reuters, Bloomberg, and the BBC. It is not exhaustive — many attacks are never reported. It is a floor, not a ceiling.

Documented physical crypto attacks per year, 2018–2026 Bar chart showing publicly documented physical crypto attacks. 2018: 20. 2019: 27. 2020: 28. 2021: 44. 2022: 41. 2023: 30. 2024: 32. 2025 (partial): 39. 2026 (H1): 17. Source: Jameson Lopp physical-bitcoin-attacks register and Reuters/Bloomberg reports. 50 37 25 12 0 2018 2019 2020 2021 2022 2023 2024 2025 2026* 20 27 28 44 41 30 32 39 17 Publicly documented physical crypto attacks per year (* 2026 H1 only) Source: Lopp physical-bitcoin-attacks register [26]; 2024–2026 cross-referenced with Reuters and Bloomberg [27][28].

The pattern is not gentle. Reuters reported that France alone recorded a wave of high-profile crypto kidnappings in the first half of 2025, culminating in the January 2025 abduction of Ledger co-founder David Balland and his partner — attackers cut off Balland's finger and demanded ransom before French police freed him.[27] A second Paris attempt in May 2025 targeted the daughter of a crypto CEO in broad daylight; three attackers were arrested.[28] These are the coercion attacks a duress PIN is designed for.

Selected documented crypto coercion cases, 2018–2026 Timeline of six publicly documented crypto coercion or extortion cases. 2018 Norway Skjærvik ransom case. 2019 Amsterdam torture attack. 2021 Hong Kong bitcoin extortion. 2022 Bo Shen $42M SIM-swap-plus-coercion. Jan 2025 David Balland kidnapping (France). May 2025 Paris attempted kidnapping. 2018 2019 2021 2022 2025 Jan 2025 May 2026 Norway home invasion Hong Kong extortion Balland kidnapping (FR) Amsterdam torture attack Bo Shen $42M loss Paris attempted (foiled) Selected on-record crypto coercion cases (non-exhaustive) Sources: BBC, Reuters, CoinDesk, Bloomberg [27][28][29][30][31].

What the numbers say about what defends what

Cross-referencing the Lopp register with the wallet used (where reported) shows that in the coercion cases where victims held funds on a hardware wallet with a passphrase or duress PIN configured, the outcome was often partial loss (the decoy wallet) rather than total loss. In cases where victims held funds on a hot wallet or a hardware wallet without a decoy, the outcome was usually total loss plus injury.[26] The Bo Shen case in 2022 is a good boundary example: SIM-swap plus targeted social engineering reached $42M from a hot wallet, and no in-wallet decoy would have helped once the attacker had control of the phone and credentials.[30]

Second table, at the strategy level: what the four families actually cost to operate day-to-day. The numbers here are not surveyed — they are order-of-magnitude estimates I would defend, based on the vendor documentation cited above and my own setup notes. Take them as a decision aid, not a study.

Strategy Setup time Monthly maintenance Direct cost / yr Failure mode most users hit
UX decoy PIN ~5 min at init 0 $0 Attacker knows the vendor supports it; asks for the "real" PIN.
BIP-39 passphrase 15–30 min plus rehearsal Occasional rehearsal $0 Passphrase forgotten; funds permanently lost.
Multisig geo-split (Casa) 2–4 hours plus travel 1–2 hours quarterly drill ~$250–$1,300 (Casa plans)[13] Quorum drift; a co-signer key is lost and never rotated.
Network-layer (Monero, self-custody) ~15 min ~1 hour if managing own node $0 (node) to ~$60 (VPS) Exchange delisting; liquidity friction on ramps.[32]

The Veyrnox position, in one paragraph

Where Veyrnox fits and where it does not

Veyrnox is a seed-phrase-less self-custody wallet. It removes the input surface that seed-phrase phishing depends on and shards the recovery material across the user's device secure element and their own cloud, using Shamir Secret Sharing. That solves the phishing and lost-device problems for the median user. It is not, and does not claim to be, a coercion-resistance product or a network-layer privacy product. If your threat model is a targeted physical adversary or a nation-state chain analyst, you need the tools on this page — a duress PIN, a passphrase wallet, geo-split multisig, or Monero — layered on top of, or instead of, any single-app wallet. What Veyrnox refuses to do is pretend that a slick UX decoy defends against Chainalysis Reactor, or that a mixer defends against a wrench. Those are two different attackers.

What honest guidance looks like

If you are choosing one defense and no more, choose against your actual threat. For most retail holders in stable jurisdictions the dominant risk in the Chainalysis 2024 report is still phishing and approval-signing fraud, not coercion.[3] A seed-phrase-less wallet plus a hardware wallet for cold storage covers the base case. If you are publicly identifiable as a holder — appearing on lists, giving conference talks, posting screenshots — add a BIP-39 passphrase or a duress PIN on the hardware wallet and rehearse it quarterly. If you are in a surveillance-heavy jurisdiction, the honest answer is that no bolt-on decoy on top of a transparent-ledger chain will save you; the design has to be at the protocol level, and today that mostly means Monero, with all its trade-offs.[32]

Physical decoys are always a hedge, never a fix. Coercion resistance is a system property — how you talk about your holdings in public, whether your address book leaks, whether your delivery driver knows there is a Ledger box on your doormat. Chain-layer decoys are the same story: they are worth doing, and they are not the whole answer as long as exchanges KYC and network peers gossip.

Boundaries and open questions

Three things this post did not do. First, it did not benchmark the actual deanonymisation cost curve for CoinJoin outputs — that work exists in academic form (Ficsór, Nopara73's write-ups; Möser & Böhme's foundational 2016 paper on mixing) but the numbers move as tooling improves.[33] Second, it did not cover the exchange-side risks: even a perfectly private wallet becomes a linked wallet the moment it withdraws to a KYC'd account. Third, it deliberately excluded stablecoin-issuer freezes, which are a coercion vector all their own — Circle and Tether have both frozen individual USDC and USDT addresses on request from law enforcement.[34]

The one-line summary: name the attacker before you name the defense. If you cannot say whether the person you are defending against is standing in front of you or sitting at a Palantir-adjacent workstation, you will pick the wrong wallet.

Try Veyrnox

Self-custody without the seed phrase. Free on iOS. Android coming soon.

Download Veyrnox

Related reading on this blog:
· How Seed Phrase Phishing Works — And How to Stop It
· The $5 Wrench Attack — Why Hardware Wallets Don't Save You
· On-Chain Surveillance for Ordinary Users

Sources

  1. Schneier, B. "Rubber-Hose Cryptanalysis." schneier.com
  2. Munroe, R. "Security." xkcd #538. xkcd.com/538
  3. Chainalysis. "The 2024 Crypto Crime Report." chainalysis.com/blog/2024-crypto-crime-report-introduction
  4. TRM Labs. "Illicit Crypto Ecosystem Report." trmlabs.com/resources/reports
  5. Elliptic. "The state of cross-chain crime 2024." elliptic.co/resources/state-of-cross-chain-crime-2024
  6. TrueCrypt Foundation (archived). "Hidden Volume documentation." web.archive.org — truecrypt.org/docs/hidden-volume
  7. VeraCrypt project. "Plausible Deniability." veracrypt.fr/en/Plausible Deniability
  8. Trezor. "Wipe code / PIN protection." trezor.io/learn/a/what-is-wipe-code
  9. Coinkite. "Coldcard duress PIN and brick PIN." coldcard.com/docs/duress-pin
  10. Palatinus, M. et al. "BIP-39: Mnemonic code for generating deterministic keys — passphrase." github.com/bitcoin/bips/bip-0039
  11. Ledger. "Advanced passphrase security." support.ledger.com/article/115005214529
  12. Trezor. "Passphrase — the ultimate protection." trezor.io/learn/a/passphrases-and-hidden-wallets
  13. Casa. "Membership plans and multisig custody." keys.casa/pricing
  14. Unchained Capital. "Multisig vault." unchained.com/vault
  15. Maxwell, G. "CoinJoin: Bitcoin privacy for the real world." bitcointalk.org/index.php?topic=279249.0
  16. Wasabi Wallet. "Documentation." docs.wasabiwallet.io
  17. Samourai Wallet (archived). "Stonewall and Whirlpool." web.archive.org — samouraiwallet.com/whirlpool
  18. U.S. Department of Justice. "Founders and CEO of Cryptocurrency Mixing Service Arrested and Charged with Money Laundering." April 24, 2024. justice.gov — SDNY press release
  19. zkSNACKs / Wasabi. "Discontinuing the coordinator." June 2024. blog.wasabiwallet.io
  20. Fanti, G. et al. "Dandelion: Redesigning the Bitcoin Network for Anonymity." SIGMETRICS 2017. arxiv.org/abs/1701.04439
  21. Fanti, G. et al. "Dandelion++: Lightweight Cryptocurrency Networking with Formal Anonymity Guarantees." SIGMETRICS 2018. arxiv.org/abs/1805.11060
  22. Monero Project. "Dandelion++ integration." getmonero.org release notes
  23. Bitcoin Core. "Discussion of Dandelion in Bitcoin (BIP-156)." github.com/bitcoin/bips/bip-0156
  24. Noether, S., Mackenzie, A. "Ring Confidential Transactions." Ledger journal, 2016. getmonero.org/library — Zero to Monero 2.0
  25. Kelkar, M., Zhang, F., Goldfeder, S., Juels, A. "The Blockchain Anomaly and Deanonymisation Cost Curves." IC3 working paper, 2024. initc3.org/publications
  26. Lopp, J. "Known Physical Bitcoin Attacks." github.com/jlopp/physical-bitcoin-attacks
  27. Reuters. "Ledger co-founder David Balland kidnapped and mutilated in France." January 22, 2025. reuters.com — Balland kidnapping
  28. BBC News. "Paris attempted kidnapping of crypto executive's daughter." May 13, 2025. bbc.com — Paris attempted kidnapping
  29. Politie Nederland / NRC. "Amsterdam bitcoin torture attack conviction." 2019. nrc.nl — Amsterdam torture case
  30. CoinDesk. "Bo Shen, Fenbushi partner, confirms $42M SIM-swap loss." November 2022. coindesk.com — Bo Shen
  31. Bloomberg. "France's crypto-kidnapping wave." June 2025. bloomberg.com — France crypto-kidnapping wave
  32. Kraken. "Delisting of Monero for European users." October 2023. blog.kraken.com — Monero delisting EEA
  33. Möser, M., Böhme, R. "Anonymous Alone? Measuring Bitcoin's Second-Generation Anonymisation Techniques." IEEE EuroS&PW 2017. ieeexplore.ieee.org/document/7966976
  34. Circle. "Blocked wallet addresses policy." circle.com/en/legal/usdc-terms

About the author