Risk Framework for Bitcoin Custody Operation with the Revault Protocol
Jacob Swambo, Antoine Poinsot

TL;DR
This paper develops a risk framework for Bitcoin custody operations, combining methodological analysis with an attack-tree library for the Revault protocol to enhance security assessment in diverse deployment scenarios.
Contribution
It introduces a comprehensive risk model for custodial Bitcoin operations, emphasizing its role alongside cryptographic security and providing a reusable attack-tree library for Revault.
Findings
Provides a risk quantification framework for custody protocols.
Demonstrates applicability to complex multi-stakeholder systems.
Offers an open-source attack-tree library for Revault.
Abstract
Our contributions with this paper are twofold. First, we elucidate the methodological requirements for a risk framework of custodial operations and argue for the value of this type of risk model as complementary with cryptographic and blockchain security models. Second, we present a risk model in the form of a library of attack-trees for Revault -- an open-source custody protocol. The model can be used by organisations as a risk quantification framework for a thorough security analysis in their specific deployment context. Our work exemplifies an approach that can be used independent of which custody protocol is being considered, including complex protocols with multiple stakeholders and active defence infrastructure.
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
