BlackHole
Last updated: October 2, 2026
BlackHole — Duress Layer
Nyxor Edition
BlackHole is an advanced duress-protection layer available in Nyxor. Under forced disclosure, what an attacker obtains does not lead to your assets.
What It Gives You
- Something credible to surrender under coercion, with nothing that signals a further layer is in play
- No visible indicator in daily use — the wallet behaves normally with your master password
- Opt-in by design: with BlackHole off, your seed is a standard BIP-39 mnemonic that restores in any compatible wallet
How the Layer Works
The BlackHole transform reconstructs your wallet from your words plus your secret, using a fixed, global salt. That is a deliberate design requirement, not an oversight. The guarantee of this layer is that the words plus the secret alone restore the wallet, with nothing else stored, written down or backed up. A random per-install salt would have to be saved somewhere, and the moment it is, the words are no longer sufficient to recover — which would defeat the purpose of the mechanism.
The consequence is worth stating plainly: the strength of this layer is the entropy of your secret, and it is not at-rest encryption. Your vault on disk is protected separately, by AES-256-GCM under a PBKDF2-derived key with a random 128-bit salt per wallet. The right comparison for BlackHole is not an encrypted database, but the plaintext seed on a card that every hardware wallet asks you to keep. Against that baseline it is a strict improvement.
Configuration and Recovery
Enabling BlackHole changes how the wallet is recovered: it trades portability for coercion resistance, by design. Setup, day-to-day behaviour, and the full recovery procedure are documented in the licensed user manual, available to licence holders in the XColdPro account area.
Before Enabling
- Create SeedVault shares from the original seed first
- Read the manual section in full before enabling the layer
- There is no recovery function for a lost BlackHole credential