Coin Brief ENDE

Optech #425: wallet labels synced through an untrusted store

Bitcoin Optech's newsletter #425, published on 2 October, leads with a proposal to synchronise wallet labels between devices and with a summary of the continuing debate on post-quantum output types. It also covers the Eclair denial-of-service disclosures reported here earlier.

Label sync. BIP329 standardised a format for exporting the labels people attach to addresses and transactions, but moving them between wallets that use the same descriptor is still a manual export-and-import cycle, so coin selection on one device is done without the labels made on another. The proposal, posted by Jakub to the Bitcoin-Dev mailing list before writing a specification, has wallets derive a storage location and encryption keys from a canonical form of the descriptor, without any private keys, so wallets sharing a descriptor find the same data with no configuration. Unmodified BIP329 records travel inside an authenticated encryption envelope with the time they were written, so the most recent change wins, and deletions are recorded as markers because BIP329 has no way to delete a label. Nostr is proposed as the reference transport, but any service that can store and return data would do; the Bitcoin Safe wallet already syncs labels this way.

Jakub asked whether keys should come from the descriptor, which allows restoring labels from the descriptor alone but exposes them to anyone who has held the extended public keys, or from a separate secret, and how devices should pair. Craig Raw replied that label sync should be part of a broader inter-wallet communication specification covering PSBTs and multisig setups, and argued that financial data should favour privacy over censorship resistance, questioning Nostr as the default.

Post-quantum outputs. The newsletter summarises further discussion of output types whose quantum-vulnerable spending paths could later be disabled, with participants disagreeing on whether to bundle cross-input signature aggregation, whether such outputs are meaningfully quantum-secure given how entrenched address reuse is, and on witness discounts for large hash-based signatures.

Optech #425: wallet labels synced through an untrusted store
Optech #425: wallet labels synced through an untrusted store — Coin Brief

Why it matters

Labels are where a lot of a wallet's privacy work lives, and losing them between devices quietly degrades coin selection. The open question is the key derivation: convenience from the descriptor alone, or a separate secret that keeps labels private from anyone who has seen the xpubs.