Threat model
Plain-language notes on how Roto protects your keys, and why.
In scope
Nonce reuse and bias
A repeated or biased k leaks the private key. Roto uses RFC 6979 or a health-checked hardware RNG, and the watcher flags repeated r and skewed s/r.
Side channels
Timing and power leaks during signing. The production signer uses constant-time code inside the sealed module; the watcher tracks timing spread.
Public-key stability
The longer one public key stays in use, the more data an attacker collects. Keys retire after N signatures and rotate to a fresh hardened child.
Implementation bugs
Audited libraries, low-s normalization, and verify-after-sign on every signature.
Single-assumption backups
The seed backup needs both X25519 and ML-KEM-768 secrets. Breaking one scheme does not open it.
Harvest now, decrypt later
An attacker who copies your backup today and waits for a quantum computer still faces ML-KEM-768.
Out of scope
A classical ECDLP break
If secp256k1 itself falls to a classical algorithm, every wallet on the chain is affected.
A fault-tolerant quantum computer during exposure
If someone runs Shor on your public key in the minutes it is visible, Roto cannot stop it. It only keeps that window small.
Malware controlling the signing UI
If your computer shows you one transaction and signs another, use a device with its own trusted display.
Invasive chip attacks
Decapping, laser fault injection, and probing require lab access to your hardware.
Quantum section
A large quantum computer running Shor's algorithm can compute a secp256k1 private key from its public key. That only works once the public key is visible. Most addresses are a hash of the public key, so until you spend, there is nothing for Shor to attack.
Roto keeps public keys hidden until they are spent, then retires them right after, so the exposure window is as small as possible. Your funds move to a fresh child key whose public key nobody has seen.
The seed backup uses ML-KEM-768, a post-quantum key encapsulation scheme, combined with X25519. Stored backups are post-quantum secure today.
Live signatures are still ECDSA or Ed25519, because that is what chains accept. Full quantum safety for signing arrives when chains adopt post-quantum signature schemes, which Roto is designed to support.



