Skip to content

Threat model

This page summarizes the public threat model in the vaultkeepr-public repository. The full document covers the open-source SDK packages and Solidity contracts as used by VaultKeepR clients; client applications live in a private repository.

AssetProtectionWhere it lives
Vault plaintextXChaCha20-Poly1305 AEAD, key derived client-sideNever leaves the device unencrypted
Master passwordArgon2id (t=3, m=64 MiB, p=4), never transmitted or storedUser’s memory only
Vault encryption keyDerived client-side, session copies in memory onlyDevice memory
Encrypted vault snapshotsContent-addressed ciphertext on IPFS / S3-compatible storageBy CID
Recovery fragmentsShamir splitting, encrypted fragmentsIPFS + on-chain pointers
Vault location pointersPublic by design; they reference ciphertext, not plaintextVaultKeeperCidRegistry on Base L2
Legacy instructionsTime-locked on-chain, encrypted beneficiary payloadsVaultKeeperLegacy on Base L2
  1. A passive network observer sees ciphertext blobs, CIDs, and traffic metadata. It learns that a vault exists, when it changes, and how big it is. It learns nothing about contents.
  2. A storage operator (IPFS gateway, S3 host) holds ciphertext and cannot decrypt it. It can withhold, corrupt, or censor data. That is an availability threat, not a confidentiality one; content addressing makes tampering detectable.
  3. An on-chain analyst reads the public registries on Base: writes, fragment pointers, legacy schedules, timestamps, sender addresses. Activity is linkable.
  4. A malicious client or dependency (a compromised SDK build, a supply-chain injection) could exfiltrate keys. Mitigations include pinned @noble/* primitives, a phishing blocklist inlined at build time, a redacting logger, and CI on every push.
  5. The server operator of the commercial service only ever handles ciphertext; compromising the backend does not decrypt vaults.
  6. An attacker with physical access or malware on your device is outside cryptographic scope.

Read these before trusting the product with anything critical.

  • Metadata is not protected. Timing, size, frequency, CID access patterns on gateways, and on-chain activity are observable. An adversary can correlate vault updates with real-world events.
  • A compromised endpoint is a compromised vault. Keyloggers, memory scrapers, and screen capture defeat any password manager’s client-side crypto. The threat model ends at the OS boundary.
  • Master password strength is the user’s risk. Argon2id raises offline attack costs but cannot rescue a weak password. The bundled entropy estimator informs; it does not enforce.
  • Availability depends on storage economics. IPFS gateways and pinning services can fail or disappear. Recovery fragments mitigate this, but they require you to hold the threshold.
  • On-chain records are permanent and public. Registry entries and legacy schedules cannot be hidden or removed once written. Treat chain addresses as pseudonymous, not anonymous.
  • Legacy windows are visible on-chain. Beneficiary timing leaks even though beneficiary payloads stay encrypted.