Feature Request: Improve Wrench-Attack Protection by Separating Passphrase Wallets from Labeling History
Hi Trezor Team,
I am writing to suggest a critical UX/security improvement regarding how Trezor Suite handles hidden (Passphrase) wallets when the Labeling feature is enabled.
Current Problem:
When a user enables Labeling (Suite Sync or Legacy) to organize transactions, Trezor Suite automatically forces the app to remember the hidden wallet. This triggers the “Open previously used” button in the wallet switcher interface.
This behavior completely defeats the purpose of plausible deniability against a $5 wrench attack. A physical attacker looking at Trezor Suite can instantly see that a hidden wallet was used in the past, destroying the user’s ability to safely present a “decoy” Standard Wallet. Forcing users to choose between having labeled transactions and maintaining full privacy/security is an unacceptable trade-off for a premier hardware wallet.
Proposed Solutions:
-
“Never Remember Hidden Wallets” Toggle: Introduce a global settings toggle that prevents Trezor Suite from ever keeping a trace of hidden wallets in the UI cache, even if Labeling is globally turned on.
-
Dynamic Label Loading via USB: Instead of linking labels to a visible wallet history entry, allow Trezor Suite to fetch and decrypt the labeling file (from Google Drive/Dropbox) on-the-fly only after the correct Passphrase has been successfully entered and computed by the hardware. If the wallet is disconnected or forgotten, the label cache and any UI trace (like “Open previously used”) should instantly evaporate from RAM.
-
Decoy Label Profile (Dual PIN concept): Allow users to load specific metadata profiles depending on the hardware state, ensuring no overlapping history traces are visible in a single shared interface.
Please consider separating the metadata/labeling logic from the wallet switcher visibility to preserve absolute plausible deniability.
Thank you for keeping our crypto safe!
Best regards,
Trezor Fan