Decoy Wallets and the Missing Network Layer
Every decoy scheme shipping in a mainstream wallet today — Trezor's duress PIN, Ledger's decoy passphrase, Coldcard's BIP-39 25th word, multisig geo-splits — solves exactly one problem: a person is standing next to you and asks you to open your wallet. None of them addresses the second, quieter attacker: a passive observer with access to the blockchain and, increasingly, to your ISP. That is the network-layer problem. It's the layer almost nobody covers.
This post separates the two problems, walks the documented history of both defenses, and lays out an honest comparison of what each strategy actually protects. It also collects the physical crypto attacks that shaped the field between 2018 and 2026 — the ones with public court records or on-the-record reporting, not the ones people invent to sell wallets.
Two attackers, two threat models
The word "decoy" gets used for two completely different defenses, which is why the conversation stays confused. Bruce Schneier's rubber-hose framing is a good place to start: strong cryptography is trivially defeated by an attacker willing to hurt you until you decrypt.[1] The famous xkcd cartoon compressed the same insight into a $5 wrench.[2] That's the coercion problem. It's about UX: what an attacker sees on your screen and what they can force you to type.
The surveillance problem is different. Chain analysts — Chainalysis, TRM Labs, Elliptic — sell software that clusters addresses, follows funds through mixers, and hands prosecutors and adversaries a graph of who transacted with whom.[3][4][5] Chainalysis Reactor, marketed to law enforcement in more than 70 countries, visualises fund flows across the majority of major chains.[3] That attacker never speaks to you. They subpoena the exchange, run the trace, and show up with a warrant. Nothing on your phone's UI defends against it.
A properly designed decoy strategy has to name which of these it addresses. Most don't.
Where "plausible deniability" came from
The idea of a decoy container predates crypto. TrueCrypt (2004–2014) shipped a "hidden volume" feature: a second encrypted volume inside the free space of a first one, accessed by a different password, cryptographically indistinguishable from random noise.[6] When TrueCrypt shut down in May 2014 under still-unexplained circumstances, its fork VeraCrypt inherited the design and remains actively maintained. VeraCrypt's docs are explicit that plausible deniability only works if the user is disciplined about not leaving forensic traces of the hidden volume — recent-file lists, thumbnail caches, and hibernation files can all give it away.[7]
That caveat carries directly into crypto wallets. A decoy wallet with a real wallet's transaction cadence on the same device — same clipboard history, same push notifications, same address book — leaks. The technical primitive is only ever half the defense.
The UX decoy family
Duress PINs
Trezor's original PIN-protected wipe (a.k.a. "wipe code") lets you set a secondary PIN that, when entered, factory-resets the device before any attacker can extract anything.[8] This is destructive rather than deceptive — the attacker knows something happened, they just have nothing to work with. Coldcard goes further with a full duress PIN system that opens a real, on-device secondary wallet with its own balance, giving the attacker something to walk away with.[9] The Coldcard also supports a "brick PIN" that permanently destroys the secure element.[9]
BIP-39 passphrase as a hidden wallet
The BIP-39 spec added an optional passphrase — sometimes called the "25th word" — that mixes into the seed to derive a completely separate wallet.[10] Every hardware wallet that implements BIP-39 supports this. The idea: your standard 24-word seed derives a low-value decoy wallet; the same 24 words plus a passphrase derives your real wallet. An attacker who forces you to reveal the seed gets the decoy. Ledger, Trezor, Coldcard, and Keystone all document the pattern.[11][8]
The failure mode is human. Forget the passphrase and the wallet is unrecoverable; the seed alone is worthless. Write the passphrase down next to the seed and you have made the whole scheme theatre. Trezor's own docs note that a passphrase is "harder to recover than a seed" and that most user losses come from passphrase forgetting, not attacks.[12]
Multisig geo-split
A 2-of-3 multisig with keys held in different physical locations — or by different parties — means no single point of coercion. Casa and Unchained Capital productised the pattern for high-net-worth Bitcoin holders.[13][14] The coercion resistance is real: the wrench in one country cannot reach the safe deposit box in another. The cost is setup complexity, recovery drills, and the reliance on a service provider or a trusted second signer.
The network-layer decoy family
Network-layer decoys tackle the other attacker. Instead of hiding what an in-person adversary sees on your screen, they hide what a passive observer sees on the chain and on the wire.
CoinJoin, Stonewall, Whirlpool
CoinJoin, first proposed by Gregory Maxwell in 2013, batches multiple users' inputs and outputs into one transaction so an outside observer cannot tell which input paid which output.[15] Wasabi Wallet (2018) and Samourai Wallet's Whirlpool (2019) shipped production CoinJoin implementations, and Samourai's Stonewall constructed CoinJoin-lookalike transactions from a single user's UTXOs to confuse heuristics even without a second party.[16][17]
Both are now essentially dead as products. In April 2024 the U.S. Department of Justice unsealed an indictment against Samourai Wallet's founders, seizing the servers.[18] Wasabi's operator zkSNACKs discontinued the coordinator in June 2024, citing the same legal risk.[19] The technology still exists in open-source forks (JoinMarket, Ashigaru, Kruw's coordinator) but the mainstream distribution channels are gone.
This matters for the decoy conversation because it means the network-layer defense with the largest historical user base is no longer a default in any wallet a normal person will install. The UX decoys survived; the network decoy did not.
Dandelion, Dandelion++, and P2P-layer anonymity
Even without CoinJoin, transaction broadcast leaks information. Fanti et al.'s 2017 Dandelion paper and its 2018 successor Dandelion++ showed that the default flooding gossip in Bitcoin's P2P layer lets an ISP-level observer link transactions to originating IP addresses.[20][21] Dandelion++ routes each transaction through a random path of peers ("stem phase") before entering normal gossip ("fluff phase"), so the first peer to broadcast is not the originator. Monero adopted Dandelion++ in 2020;[22] Bitcoin Core has not.[23]
Traffic decoys — the honest name
True traffic-layer decoys — sending fake transactions specifically to poison an observer's clustering — remain a research topic rather than a shipped feature. Monero's ring signatures produce decoy inputs at the protocol level: each spend references N–1 unrelated outputs so an observer cannot tell which was actually spent.[24] That is the closest thing to a network-layer decoy shipping in a production wallet today, and it is not a bolt-on — the entire chain design has to support it.
What the surveillance side actually looks like
Naming the surveillance vendors makes the threat model concrete. Chainalysis reported in its 2024 Crypto Crime Report that its Reactor product is used by public and private customers in more than 70 jurisdictions and tracks over $14 trillion in on-chain activity.[3] TRM Labs reports similar scale and publishes free case data for law enforcement.[4] Elliptic has been public about tracing funds through Tornado Cash mixer deposits and reconstructing user flows despite the mixer's anonymity set.[5]
Ari Juels and colleagues at IC3 have written on the limits of these tools — including a 2024 paper on the deanonymisation cost curve for privacy tools built on top of transparent ledgers.[25] The consensus finding is uncomfortable: with enough time, subpoenas, and off-chain data, most on-chain privacy tools have been broken to at least a probabilistic level for targeted investigations.
Comparison: four decoy strategies, four threat axes
| Strategy | Coercion protection | Passive-observer protection | Setup complexity | Recovery risk |
|---|---|---|---|---|
| UX decoy PIN (Trezor wipe, Coldcard duress) | Partial. Strong if the attacker is unaware; falls to Weak if they know the wallet vendor. | None. Real wallet still broadcasts identifiable transactions. | Simple. Set at device init. | Safe. Real wallet still recoverable via seed. |
| BIP-39 passphrase hidden wallet | Solid. Depends on the attacker not knowing that passphrases exist for this seed length. | None. Real wallet still broadcasts identifiable transactions. | Moderate. User must memorise a strong passphrase and rehearse it. | Fragile. Passphrase loss = wallet loss. No cloud fallback by design. |
| Multisig geo-split (Casa, Unchained, self-hosted 2-of-3) | Strong. Attacker cannot reach all key locations in one action. | Weak. On-chain multisig scripts are distinguishable and cluster the same way. | Complex. Multiple devices, quorum drills, service or trusted co-signer. | Moderate. Loss of two shards = wallet loss. |
| Network-layer traffic decoy (CoinJoin, Whirlpool, Monero ring signatures) | None. Attacker with your PIN can still spend. | Strong for Monero (protocol level); Partial for CoinJoin (mixer risk, DoJ scrutiny); None for the average phone wallet in 2026. | Moderate. Requires either a chain that supports it or a third-party coordinator. | Safe if custody is unchanged; Fragile when using a custodial mixer. |
The pattern the table makes visible: no single strategy covers both axes. Combining strategies is possible in theory (passphrase-hidden wallet feeding a Monero atomic swap, say), but each combination adds surface area for user error. The real design question is which single defense a given user actually needs — and for most people the honest answer is "the one they'll still follow six months from now."
Documented physical attacks, 2018–2026
The best public register of physical Bitcoin attacks is maintained by Jameson Lopp.[26] The list is source-linked to news reports and court filings; the timeline below draws only from entries with public reporting or unsealed indictments, plus 2024–2026 cases covered by Reuters, Bloomberg, and the BBC. It is not exhaustive — many attacks are never reported. It is a floor, not a ceiling.
The pattern is not gentle. Reuters reported that France alone recorded a wave of high-profile crypto kidnappings in the first half of 2025, culminating in the January 2025 abduction of Ledger co-founder David Balland and his partner — attackers cut off Balland's finger and demanded ransom before French police freed him.[27] A second Paris attempt in May 2025 targeted the daughter of a crypto CEO in broad daylight; three attackers were arrested.[28] These are the coercion attacks a duress PIN is designed for.
What the numbers say about what defends what
Cross-referencing the Lopp register with the wallet used (where reported) shows that in the coercion cases where victims held funds on a hardware wallet with a passphrase or duress PIN configured, the outcome was often partial loss (the decoy wallet) rather than total loss. In cases where victims held funds on a hot wallet or a hardware wallet without a decoy, the outcome was usually total loss plus injury.[26] The Bo Shen case in 2022 is a good boundary example: SIM-swap plus targeted social engineering reached $42M from a hot wallet, and no in-wallet decoy would have helped once the attacker had control of the phone and credentials.[30]
Second table, at the strategy level: what the four families actually cost to operate day-to-day. The numbers here are not surveyed — they are order-of-magnitude estimates I would defend, based on the vendor documentation cited above and my own setup notes. Take them as a decision aid, not a study.
| Strategy | Setup time | Monthly maintenance | Direct cost / yr | Failure mode most users hit |
|---|---|---|---|---|
| UX decoy PIN | ~5 min at init | 0 | $0 | Attacker knows the vendor supports it; asks for the "real" PIN. |
| BIP-39 passphrase | 15–30 min plus rehearsal | Occasional rehearsal | $0 | Passphrase forgotten; funds permanently lost. |
| Multisig geo-split (Casa) | 2–4 hours plus travel | 1–2 hours quarterly drill | ~$250–$1,300 (Casa plans)[13] | Quorum drift; a co-signer key is lost and never rotated. |
| Network-layer (Monero, self-custody) | ~15 min | ~1 hour if managing own node | $0 (node) to ~$60 (VPS) | Exchange delisting; liquidity friction on ramps.[32] |
The Veyrnox position, in one paragraph
Where Veyrnox fits and where it does not
Veyrnox is a seed-phrase-less self-custody wallet. It removes the input surface that seed-phrase phishing depends on and shards the recovery material across the user's device secure element and their own cloud, using Shamir Secret Sharing. That solves the phishing and lost-device problems for the median user. It is not, and does not claim to be, a coercion-resistance product or a network-layer privacy product. If your threat model is a targeted physical adversary or a nation-state chain analyst, you need the tools on this page — a duress PIN, a passphrase wallet, geo-split multisig, or Monero — layered on top of, or instead of, any single-app wallet. What Veyrnox refuses to do is pretend that a slick UX decoy defends against Chainalysis Reactor, or that a mixer defends against a wrench. Those are two different attackers.
What honest guidance looks like
If you are choosing one defense and no more, choose against your actual threat. For most retail holders in stable jurisdictions the dominant risk in the Chainalysis 2024 report is still phishing and approval-signing fraud, not coercion.[3] A seed-phrase-less wallet plus a hardware wallet for cold storage covers the base case. If you are publicly identifiable as a holder — appearing on lists, giving conference talks, posting screenshots — add a BIP-39 passphrase or a duress PIN on the hardware wallet and rehearse it quarterly. If you are in a surveillance-heavy jurisdiction, the honest answer is that no bolt-on decoy on top of a transparent-ledger chain will save you; the design has to be at the protocol level, and today that mostly means Monero, with all its trade-offs.[32]
Physical decoys are always a hedge, never a fix. Coercion resistance is a system property — how you talk about your holdings in public, whether your address book leaks, whether your delivery driver knows there is a Ledger box on your doormat. Chain-layer decoys are the same story: they are worth doing, and they are not the whole answer as long as exchanges KYC and network peers gossip.
Boundaries and open questions
Three things this post did not do. First, it did not benchmark the actual deanonymisation cost curve for CoinJoin outputs — that work exists in academic form (Ficsór, Nopara73's write-ups; Möser & Böhme's foundational 2016 paper on mixing) but the numbers move as tooling improves.[33] Second, it did not cover the exchange-side risks: even a perfectly private wallet becomes a linked wallet the moment it withdraws to a KYC'd account. Third, it deliberately excluded stablecoin-issuer freezes, which are a coercion vector all their own — Circle and Tether have both frozen individual USDC and USDT addresses on request from law enforcement.[34]
The one-line summary: name the attacker before you name the defense. If you cannot say whether the person you are defending against is standing in front of you or sitting at a Palantir-adjacent workstation, you will pick the wrong wallet.
Try Veyrnox
Self-custody without the seed phrase. Free on iOS. Android coming soon.
Download VeyrnoxSources
- Schneier, B. "Rubber-Hose Cryptanalysis." schneier.com
- Munroe, R. "Security." xkcd #538. xkcd.com/538
- Chainalysis. "The 2024 Crypto Crime Report." chainalysis.com/blog/2024-crypto-crime-report-introduction
- TRM Labs. "Illicit Crypto Ecosystem Report." trmlabs.com/resources/reports
- Elliptic. "The state of cross-chain crime 2024." elliptic.co/resources/state-of-cross-chain-crime-2024
- TrueCrypt Foundation (archived). "Hidden Volume documentation." web.archive.org — truecrypt.org/docs/hidden-volume
- VeraCrypt project. "Plausible Deniability." veracrypt.fr/en/Plausible Deniability
- Trezor. "Wipe code / PIN protection." trezor.io/learn/a/what-is-wipe-code
- Coinkite. "Coldcard duress PIN and brick PIN." coldcard.com/docs/duress-pin
- Palatinus, M. et al. "BIP-39: Mnemonic code for generating deterministic keys — passphrase." github.com/bitcoin/bips/bip-0039
- Ledger. "Advanced passphrase security." support.ledger.com/article/115005214529
- Trezor. "Passphrase — the ultimate protection." trezor.io/learn/a/passphrases-and-hidden-wallets
- Casa. "Membership plans and multisig custody." keys.casa/pricing
- Unchained Capital. "Multisig vault." unchained.com/vault
- Maxwell, G. "CoinJoin: Bitcoin privacy for the real world." bitcointalk.org/index.php?topic=279249.0
- Wasabi Wallet. "Documentation." docs.wasabiwallet.io
- Samourai Wallet (archived). "Stonewall and Whirlpool." web.archive.org — samouraiwallet.com/whirlpool
- U.S. Department of Justice. "Founders and CEO of Cryptocurrency Mixing Service Arrested and Charged with Money Laundering." April 24, 2024. justice.gov — SDNY press release
- zkSNACKs / Wasabi. "Discontinuing the coordinator." June 2024. blog.wasabiwallet.io
- Fanti, G. et al. "Dandelion: Redesigning the Bitcoin Network for Anonymity." SIGMETRICS 2017. arxiv.org/abs/1701.04439
- Fanti, G. et al. "Dandelion++: Lightweight Cryptocurrency Networking with Formal Anonymity Guarantees." SIGMETRICS 2018. arxiv.org/abs/1805.11060
- Monero Project. "Dandelion++ integration." getmonero.org release notes
- Bitcoin Core. "Discussion of Dandelion in Bitcoin (BIP-156)." github.com/bitcoin/bips/bip-0156
- Noether, S., Mackenzie, A. "Ring Confidential Transactions." Ledger journal, 2016. getmonero.org/library — Zero to Monero 2.0
- Kelkar, M., Zhang, F., Goldfeder, S., Juels, A. "The Blockchain Anomaly and Deanonymisation Cost Curves." IC3 working paper, 2024. initc3.org/publications
- Lopp, J. "Known Physical Bitcoin Attacks." github.com/jlopp/physical-bitcoin-attacks
- Reuters. "Ledger co-founder David Balland kidnapped and mutilated in France." January 22, 2025. reuters.com — Balland kidnapping
- BBC News. "Paris attempted kidnapping of crypto executive's daughter." May 13, 2025. bbc.com — Paris attempted kidnapping
- Politie Nederland / NRC. "Amsterdam bitcoin torture attack conviction." 2019. nrc.nl — Amsterdam torture case
- CoinDesk. "Bo Shen, Fenbushi partner, confirms $42M SIM-swap loss." November 2022. coindesk.com — Bo Shen
- Bloomberg. "France's crypto-kidnapping wave." June 2025. bloomberg.com — France crypto-kidnapping wave
- Kraken. "Delisting of Monero for European users." October 2023. blog.kraken.com — Monero delisting EEA
- Möser, M., Böhme, R. "Anonymous Alone? Measuring Bitcoin's Second-Generation Anonymisation Techniques." IEEE EuroS&PW 2017. ieeexplore.ieee.org/document/7966976
- Circle. "Blocked wallet addresses policy." circle.com/en/legal/usdc-terms