The Exact Security of BIP32 Wallets
Poulami Das, Andreas Erwig, Sebastian Faust, Julian Loss, Siavash Riahi
Abstract
In many cryptocurrencies, the problem of key management has become one of the most fundamental security challenges. Typically, keys are kept in designated schemes called wallets, whose main purpose is to store these keys securely. One such system is the BIP32 wallet (Bitcoin Improvement Proposal 32), which since its introduction in 2012 has been adopted by countless Bitcoin users and is one of the most frequently used wallet system today. Surprisingly, very little is known about the concrete security properties offered by this system. In this work, we propose the first formal analysis of the BIP32 system in its entirety and without any modification. Building on the recent work of Das et al. (CCS '19), we put forth a formal model for hierarchical deterministic wallet systems (such as BIP32) and give a security reduction in this model from the existential unforgeability of the ECDSA signature algorithm that is used in BIP32. We conclude by giving concrete security parameter estimates achieved by the BIP32 standard, and show that by moving to an alternative key derivation method we can achieve a tighter reduction offering an additional 20 bits of security (111 vs. 91 bits of security) at no additional costs.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers4
- On the Security of ECDSA with Additive Key Derivation and PresignaturesJens Groth, Victor ShoupEUROCRYPT 2022 · 29 citations
- SoK: Decentralized Finance (DeFi) AttacksLiyi Zhou, Xihan Xiong, Jens Ernstberger, Stefanos Chaliasos et al.S&P 2023
- Token meets Wallet: Formalizing Privacy and Revocation for FIDO2Lucjan Hanzlik, Julian Loss, Benedikt WagnerS&P 2023
- Liquidity Mining as an Attack Surface: Incentive-Induced Liquidity Attacks in Concentrated Liquidity Market MakersNora Sinong Lu, Chon Kit Lao, Yunlong Mao, Xiaobo Zhou et al.USENIX Security 2026
Builds on6
- Fast Secure Multiparty ECDSA with Practical Distributed Key Generation and Applications to Cryptocurrency CustodyYehuda Lindell, Ariel NofCCS 2018 · 220 citations
- Secure Two-party Threshold ECDSA from ECDSA AssumptionsJack Doerner, Yashvanth Kondi, Eysa Lee, Abhi ShelatS&P 2018 · 171 citations
- A Formal Treatment of Deterministic WalletsPoulami Das, Sebastian Faust, Julian LossCCS 2019 · 62 citations
- On the Provable Security of (EC)DSA SignaturesManuel Fersch, Eike Kiltz, Bertram PoetteringCCS 2016 · 55 citations
- Refresh When You Wake Up: Proactive Threshold Wallets with Offline DevicesYashvanth Kondi, Bernardo Magri, Claudio Orlandi, Omer ShlomovitsS&P 2021 · 35 citations
Related papers
- Schnorr Signatures and MuSig2 are Jointly Secure, Even in Deterministic WalletsRenas Bacho, Yanbo Chen, Poulami Das, Julian Loss et al.CCS 2026
- Deterministic Wallets in a Quantum WorldNabil Alkeilani Alkadri, Poulami Das, Andreas Erwig, Sebastian Faust et al.CCS 2020 · 6 citations
- Uncovering Impact of Mental Models towards Adoption of Multi-device Crypto-WalletsEaswar Vivek Mangipudi, Udit Desai, Mohsen Minaei, Mainack Mondal et al.CCS 2023 · 7 citations
- Server-Aided Anonymous CredentialsRutchathon Chairattana-Apirom, Franklin Harding, Anna Lysyanskaya, Stefano TessaroCRYPTO 2025 · 10 citations
- "Don't put all your eggs in one basket": How Cryptocurrency Users Choose and Secure Their WalletsYaman Yu, Tanusree Sharma, Sauvik Das, Yang WangCHI 2024 · 19 citations
