,
Antonio Ken Iannillo
,
Radu State
Creative Commons Attribution 4.0 International license
Cryptoasset systems often bind cryptographic key control to financial control: losing a wallet seed, custody share, hardware device, or smart-account credential can remove spend authority, while compromised recovery can enable theft. Existing work treats recovery through separate vocabularies-key backup, secret sharing, account recovery, credential re-issuance, social recovery, and asset migration-making mechanisms and tradeoffs difficult to compare. This paper presents a Systematization of Knowledge (SoK) on cryptographic key recovery for cryptoasset custody and financial technologies. Starting from a 118-paper systematic-review discovery corpus, we derive a 77-paper synthesis corpus and code each retained system in a master matrix covering recovered objects, recovery semantics, mechanisms, enrollment and storage, authorization, trust placement, failure events, post-recovery state, validation evidence, deployment status, privacy, usability, and limitations. The matrix supports an axis-first taxonomy that separates secret-restoring, hybrid, control-restoring, forensic/extractive, and framework-oriented recovery. Our central observation is that recovery is not a single operation: systems may reconstruct an original secret, regenerate a seed, restore a share, reissue a credential, migrate signing authority, restore account control, move assets, or extract forensic artifacts. We derive a generalized construction model, check it against production-facing designs, and identify six findings: recovery semantics are heterogeneous; recovery shifts trust; liveness improvements create abuse paths; post-recovery lifecycle management is uneven; protocol evidence outpaces user evidence; and recovery metadata remains underprotected. These gaps motivate a research agenda for recovery-aware financial technologies.
@InProceedings{sanchez_et_al:LIPIcs.AFT.2026.3,
author = {Sanchez, Francisco Javier Becerra and Iannillo, Antonio Ken and State, Radu},
title = {{SoK: Cryptographic Key Recovery for Cryptoasset Custody and Financial Technologies}},
booktitle = {8th Conference on Advances in Financial Technologies (AFT 2026)},
pages = {3:1--3:28},
series = {Leibniz International Proceedings in Informatics (LIPIcs)},
ISBN = {978-3-95977-451-2},
ISSN = {1868-8969},
year = {2026},
volume = {395},
editor = {Kiayias, Aggelos and Kyropoulou, Maria},
publisher = {Schloss Dagstuhl -- Leibniz-Zentrum f{\"u}r Informatik},
address = {Dagstuhl, Germany},
URL = {https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.AFT.2026.3},
URN = {urn:nbn:de:0030-drops-278575},
doi = {10.4230/LIPIcs.AFT.2026.3},
annote = {Keywords: Cryptoasset Custody, Key Recovery, Wallet Security, Smart Accounts, Threshold Cryptography, Secret Sharing, Decentralized Identity, Secure Hardware}
}