Advanced techniques

Planning for coercion

The attack that ignores your cryptography and comes for you instead. Why decoy wallets are weaker than they sound, why being genuinely unable to comply beats lying convincingly, and the arrangements that make a bad situation worse.

Advanced About 30 minutes Updated Aug 18, 2026

Every other guide on this site makes the mathematics harder. Longer keys, more signers, better entropy, verified firmware. All of it assumes an attacker who has to get past the cryptography.

There is a well-known cartoon about this. Security people imagine an adversary building enormous machines to crack a key, when the realistic approach is to hit the owner with a cheap wrench until they hand it over. That image gave the whole problem its name: the five-dollar wrench attack — the attack that does not engage with your security at all, and instead engages with you.

No amount of key length helps here. What follows is an honest account of what does, what merely sounds like it does, and which popular measures can make a dangerous situation last longer.

Before anything else

If this ever happens to you, your safety is worth more than every coin you own. Bitcoin is replaceable and you are not. Nothing on this page is advice to resist, delay, or refuse someone who is threatening you — the entire purpose of planning in advance is so that you never have to make that choice while frightened.

1Be proportionate about this

This threat is real and it is also rare, and writing about it tends to make it feel imminent. It is worth placing accurately before redesigning your life around it.

  • The attack requires a belief. Somebody has to think you hold enough bitcoin to be worth the risk of a violent crime. That belief comes from somewhere, and it is nearly always something that was said.
  • It is concentrated among the visible. People who discuss holdings publicly, appear in media, work in the industry, or mention it socially are in a different position from people who have told nobody.
  • The realistic threat for most people is remote: phishing, fake support, malware, and address-substitution — not physical confrontation.
  • Household risk is worth naming. For some people the plausible coercion is domestic rather than a stranger, and that changes which measures make sense.

2The most effective defence is not technical

Because the attack depends on someone believing you are worth targeting, the highest-value measure available is not a device feature. It is discretion, and it costs nothing.

  • Do not discuss what you hold. Not amounts, not roughly, not as a joke, not to family who will repeat it warmly and harmlessly to somebody else.
  • Do not signal it indirectly — conference lanyards, stickers, clothing, and forum handles attached to your real name all describe you to strangers.
  • Keep addresses away from your identity. A public address next to your name lets anybody read your balance forever. The privacy guide covers why that link is hard to undo.
  • Have deliveries sent somewhere sensible. A branded hardware wallet box arriving at your home tells the delivery chain, and anyone watching your porch, what you now own.
  • Accept that some people must know. Your inheritance plan requires it. Keep that number small and chosen rather than accumulated.

None of this is glamorous, and all of it outperforms every clever feature below.

3Decoy wallets, honestly

The popular answer is a decoy: a wallet holding a modest amount that you surrender while the real one stays hidden, usually behind a passphrase or a device's alternate PIN.

The passphrase guide makes the core objection — it is a delay rather than a shield, because it depends on the attacker believing you and stopping. Three further problems are worth stating plainly before you rely on one.

  • You have to perform, under the worst conditions of your life. A decoy is a lie that must be told convincingly to a violent person while terrified. Most planning quietly assumes a calm, competent version of you that will not be there.
  • The amount is an unsolvable dilemma. Too little and it is transparently a decoy. Enough to be believed is enough that losing it genuinely hurts.
  • Being disbelieved makes things worse. If they think you are holding back, the encounter continues — and you have spent your one deception and have nothing left to offer.
  • Sophisticated attackers know the technique exists. Passphrases and duress PINs are not secrets; anyone who researched enough to target you has read the same pages you have.

Decoys are not worthless. They are a reasonable hedge against an opportunistic thief who wants a quick result. They are a poor foundation against anyone patient or informed.

4The principle that actually helps

Here is the shift that reframes the whole subject.

A truth you can state calmly is worth more than a lie you have to sell. Do not aim to deceive — aim to be genuinely unable to comply.

A decoy requires acting. An arrangement that makes immediate transfer impossible requires only that you explain it, and the explanation is verifiable, consistent, and does not collapse under pressure — because it is true.

  • Time delays. A wallet with a mandatory waiting period cannot be emptied now by anyone, including you. The COLDCARD login countdown does this at the device level; some products build a notice period into recovery itself.
  • Timelocked spending paths. Bitcoin can enforce that certain coins simply are not spendable until a future date. That is a fact about the chain, not a claim about your wallet — see scripts and miniscript.
  • Keys you cannot reach. A multisig whose second key is in another city, another country, or another person's hands cannot be assembled in an evening. Key geography is the design work behind this.
  • Keys other people must approve. A collaborative custody arrangement means a third party has to participate, on their schedule, through their process.

Each of these converts “transfer it now” into a request that cannot be satisfied at speed by anybody. That is a materially different position from hoping to be believed.

5The danger of over-engineering

This is where an honest guide has to complicate its own advice, because the measures in the previous section carry a real risk that enthusiasts rarely mention.

An attacker who cannot get what they want may not simply leave. A situation that could have ended in minutes with a transfer can instead continue while you explain a delay mechanism to somebody unwilling to hear it. Making yourself unable to comply is protective for your coins and is not automatically protective for you.

  • Keep something available to give. A hot wallet with a realistic everyday balance is not a weakness; it is a way for an encounter to end.
  • Never build an arrangement you cannot explain simply. If you cannot describe the delay in one sentence a stranger will accept, it will not help you in the moment.
  • Do not rely on features you have not tested. A trick PIN you configured once and never rehearsed is not something you will use correctly under threat.
  • Avoid measures that destroy. A wipe or brick triggered during a confrontation removes the attacker's incentive to stop without giving them anything — consider carefully whether that is the situation you want to create.

6Matching the measure to the risk

What each measure is actually good for
MeasureHelps againstCost to you
Discretion about holdingsBeing selected at allNone. Do this first.
A funded everyday hot walletOpportunistic demandsThe balance, occasionally
Decoy wallet or duress PINAn attacker who accepts itA performance, and a real balance
Login countdown or delayImmediate transfer, crediblyYour own access is delayed too
Geographic multisigAnything demanding speedComplexity, travel, rehearsal
Timelocked coinsAny demand before the dateTechnical skill; funds genuinely locked

Read that top row as the recommendation. Almost everybody should do the first two and stop, and the remainder is for people with a specific, identified reason.

7If it happens

  • Comply with what you can. Give up the hot wallet, the phone, the device. None of it is worth injury.
  • Do not improvise a deception you have not rehearsed. Being caught in one mid-encounter is worse than never attempting it.
  • Get to safety first, then act. Once you are safe, move whatever remains to a new wallet with new keys, because anything they saw must be treated as compromised.
  • Report it. Bitcoin's finality means recovery is unlikely, but coercion is a serious crime and patterns of these offences matter beyond your own case.
  • Rebuild differently. Whoever did this knew something. Work out what, and change it.

The short version

The five-dollar wrench attack bypasses your cryptography entirely, so cryptographic answers do not apply. It depends on someone believing you are worth targeting, which makes discretion the highest-value defence by a wide margin. Decoys ask you to act convincingly while terrified; delays and distributed keys let you tell the truth instead. And keep something available to hand over, because an encounter that can end quickly should.

If you take one thing from this page

Not being identified as a holder protects you from every attack on this page at once, and costs nothing but silence. Every technical measure here is a distant second — and the ones that make you unable to comply protect your coins, which is not the same thing as protecting you.

Do not guess

Stuck on a step?

If the screen in front of you does not match the guide, stop. Review the related walkthroughs or get a second set of eyes before exposing recovery words or approving a transaction.