Time changes what a key compromise can actually do.
Even if an attacker reconstructs both user keys A and B, the delayed fallback cannot be used until its CSV condition matures.
Before then, the legitimate owner can use (A or B) + C to spend the current vault output V0 into a new output V1.
Once V0 is spent:
• transactions prepared against V0 become invalid
• V1 becomes the active vault output
• the fallback delay starts again on V1
The keys remain A, B and C.
BitVault does not remove the key compromise. It creates a response window in which the legitimate owner can refresh the UTXO before the attacker’s delayed path becomes available.
Read the full analysis:


BitVault Blog
If your Coldcard was integrated with BitVault -
If your Coldcard was integrated with BitVault, reconstructing its defective private key would not, by itself, have given the attacker immediate con...