Research question: What is the biggest unsolved security gap in self-custody under physical coercion?
I'm researching a specific question about crypto security:
If someone physically coerces the legitimate owner into authorizing a transaction, what protection does the owner actually have?
I'm less interested in theoretical attacks and more interested in how people with meaningful crypto holdings actually structure their security today.
For example:
- Multisig
- Hardware wallets
- Passphrases / hidden wallets
- Duress or decoy wallets
- Timelocks
- Spending limits
- Geographically separated keys
- Trusted third parties / guardians
- Keeping only a small amount readily accessible
My main research question is:
What is the biggest weakness or failure mode of the approaches above when the attacker has physical control of the owner?
And a second question:
Is there any setup today that makes it technically impossible for a coerced owner to immediately move their long-term holdings to a new address?
I'm interested in real-world setups and experiences, not product recommendations.
If you've thought seriously about this threat model, I'd be especially interested in what you currently do — and what you still don't feel comfortable with.
[link] [comments]