Archived dispatch

What are the security tradeoffs of non-custodial browser session keys?

Lowconfidenceno citation passed the evidence gate

8/10/2026, 1:05:37 AM · llm:deepseek:deepseek-v4-flash + llm:mimo:mimo-v2.5 on 1 step

The dispatch, itemised.

§ IThe decision$0 / $0.05
0%
Decompose

Breaking down: "What are the security tradeoffs of non-custodial browser session keys?"

Decompose

Identified 4 sub-claim(s) to support

Discover

Discovered 20 verified source(s)

Discover

Recalled 19 past runs on this subject — how these sources performed when they were available.

Discover

ERC-8004 reputation loaded — composite scores on this subject.

DecideCACHE
Distributed Systems Notes — Idempotency keys prevent double-spends$0.003 · EV 85%

Distributed Systems Notes has high historical citation rate (56%) and reputation on this subject (52/100). Idempotency keys are relevant to security tradeoffs of session keys (preventing double-spends, replay attacks). Already cached, so reuse for free.

DecideCACHE
Web Payments Review — How long do x402 payments take to finalize?$0.002 · EV 50%

Web Payments Review covers x402 payment finality, which may touch on settlement security but not browser key storage. Low citation rate (14%) and reputation (5/100). Already cached.

DecideCACHE
The Coinbase Blog - Medium — Celer Bridge incident analysis$0.003 · EV 50%

Coinbase Blog covers security incidents (Celer Bridge) which may contain relevant insights on key compromise and recovery mechanisms. Low citation rate (25%) but relevant to security tradeoffs. Already cached, so use for free.

DecideCACHE
Stripe Blog — Rethinking risk in the age of AI$0.002 · EV 30%

Stripe Blog on risk and AI may touch on browser security or fraud, but historically never cited on this subject (0/13 runs). Already cached, low cost to include, but likely low relevance to non-custodial browser session keys specifically.

DecideCACHE
Cointelegraph.com News — Crypto wrench attacks steal more than $30M so far in 2026: Chainalysis$0.002 · EV 30%

Cointelegraph.com News covers crypto wrench attacks, which relates to physical security of keys, but not browser-level threats. Never cited on this subject (0/5 runs). Already cached, low relevance.

DecideCACHE
Stablecoin Ledger — Stablecoins as the unit of account for agents$0.003 · EV 40%

Stablecoin Ledger focuses on stablecoins as unit of account, not directly on browser session key security. Low citation rate (7%) and reputation (2/100). Already cached, but weak relevance.

DecideCACHE
Agent Economy Weekly — x402 turns HTTP 402 into an agent payment rail$0.004 · EV 45%

Agent Economy Weekly covers x402 and machine economy, which may involve agent key management. Low citation rate (15%) and reputation (4/100), but some relevance to non-custodial agents. Already cached.

DecideSKIP
Ethereum Foundation Blog — The triage is the product: running AI agents against Ethereum's protocol code$0.002 · EV 20%

Ethereum Foundation Blog on AI agents vs protocol code may have tangential security insights but historically never cited on this subject (0/9 runs). Not directly relevant to browser session keys.

DecideSKIP
CoinDesk: Bitcoin, Ethereum, Crypto News and Price Data — Bitcoin holders risk losing real BTC if they sell coins from BIP-110 fork, says developer$0.002 · EV 15%

CoinDesk on Bitcoin fork risks is about blockchain forks, not browser session keys. Historically never cited on this subject (0/3 runs). Not relevant.

DecideSKIP
Retro Game Hardware — Recapping a 1990s console$0.002 · EV 10%

Retro Game Hardware is about console recapping, not relevant to browser security or cryptographic key management.

DecideSKIP
Vitalik Buterin's website — Low-risk defi can be for Ethereum what search was for Google$0.004 · EV 20%

Vitalik Buterin's site on low-risk DeFi may touch on Ethereum security, but not browser session keys. Not cached and not worth buying for this specific question.

DecideSKIP
Decrypt — Putin Signs Russia's First Crypto Law: Trading Is Legal, Payments Stay Banned$0.002 · EV 10%

Decrypt on Russia's crypto law is regulatory news, not relevant to browser session key security. Not cached and not worth buying.

DecideSKIP
Latent.Space — Ontologies Are So Back: Why AI Agents Are Reviving the Semantic Web$0.004 · EV 15%

Latent.Space on ontologies and AI agents is about semantic web, not browser key security. Never cited on this subject (0/5 runs). Not relevant.

DecideSKIP
Arc Settlement Benchmarks — Measuring x402 settlement latency on Arc$0.003 · EV 10%

Arc Settlement Benchmarks measures x402 latency on Arc testnet, never cited on this subject (0/14 runs). Not relevant to browser session key security.

DecideSKIP
Simon Willison's Weblog — New release of LLM adds support for reasoning traces, OpenAI Responses, server-side tools, and smarter logging$0.003 · EV 10%

Simon Willison's Weblog covers LLM tooling, not browser security or key management. No prior citations on this subject. Not relevant.

DecideSKIP
Onchain Micropayments Digest — Nanopayments and the $0.000001 floor$0.005 · EV 15%

Onchain Micropayments Digest is about nanopayments and batching, not browser session key security. Low citation rate (7%) and reputation (4/100). Not relevant.

DecideSKIP
Hugging Face - Blog — TutorMoments: Do AI tutors know when to help and when to hold back?$0.003 · EV 5%

Hugging Face Blog on AI tutors is completely off-topic from browser session key security. Not relevant.

DecideSKIP
Inner Axiom — The Codex — As Above, so Below: The Mirrored Principle of the Tree of Life$0.002 · EV 0%

Inner Axiom on mysticism/occult is completely off-topic. No relevance whatsoever.

DecideSKIP
Conzit Labs — Cougars as Natural Traffic Controllers: A Surprising Solution$0.002 · EV 0%

Conzit Labs on cougars as traffic controllers is completely off-topic. No relevance.

Fetch

Agent spend wallet ready: 0xBC04248d14bB94D6ecf89067dD66Cd247E3a2988 (balance sufficient)

Fetch

Reused cached Distributed Systems Notes — Idempotency keys prevent double-spends (free) — S1

Fetch

Reused cached Web Payments Review — How long do x402 payments take to finalize? (free) — S2

Fetch

Reused cached The Coinbase Blog - Medium — Celer Bridge incident analysis (free) — S3

Fetch

Reused cached Stripe Blog — Rethinking risk in the age of AI (free) — S4

Fetch

Reused cached Cointelegraph.com News — Crypto wrench attacks steal more than $30M so far in 2026: Chainalysis (free) — S5

Fetch

Reused cached Stablecoin Ledger — Stablecoins as the unit of account for agents (free) — S6

Fetch

Reused cached Agent Economy Weekly — x402 turns HTTP 402 into an agent payment rail (free) — S7

Re-evaluate

Sub-claim "Non-custodial browser session keys reduce the risk of server…": 0% covered — No gathered content discusses browser session keys, private key custody, or server-side compromise of such keys.

Re-evaluate

Sub-claim "They increase the risk of permanent loss of access, as clear…": 0% covered — No gathered content mentions browser storage, device loss, backup, or access loss related to session keys.

Re-evaluate

Sub-claim "They are exposed to browser-level threats such as malware, m…": 0% covered — No gathered content addresses browser-based attacks (XSS, extensions, malware) in the context of local private keys.

Re-evaluate

Sub-claim "They lack central revocation and recovery mechanisms, so a c…": 0% covered — No gathered content discusses revocation, recovery, key expiry, or compromise reporting mechanisms for session keys.

Re-evaluate

All sub-claims are effectively uncovered by the gathered content, which focuses on payments, idempotency, x402, and a bridge incident rather than non-custodial browser session keys. The available skipped sources do not appear relevant to this specific topic, so purchasing them would not fill the coverage gap.

Sufficiency

Final check — "Non-custodial browser session keys reduce the risk of server…": 0% assessed

Sufficiency

Final check — "They increase the risk of permanent loss of access, as clear…": 0% assessed

Sufficiency

Final check — "They are exposed to browser-level threats such as malware, m…": 0% assessed

Sufficiency

Final check — "They lack central revocation and recovery mechanisms, so a c…": 0% assessed

Sufficiency

Final coverage assessment — The gathered sources cover idempotency keys, x402 payment timing, a bridge incident, payment conference promotions, physical wrench attacks, stablecoin unit-of-account use, and x402 as a payment rail. None of them discuss non-custodial browser session keys or their security tradeoffs, so the claim cannot be evaluated.

Synthesize

Synthesizing a grounded answer from 7 source(s)…

Evidence

Rejected 0 invalid evidence span(s) and 2 unsupported citation marker(s); rejected markers cannot receive citation rewards.

Evidence

No citation passed the evidence gate — the $0.025000 citation pool stays unspent; settled access tolls still stand.

Synthesize

Drafted answer citing 0 source(s)

Verdict

Confidence: Low — no citation passed the evidence gate.

Done

Done. Spent $0 across 0 confirmed/simulated payment(s) to creators.

§ IIIThe settlementweighted · USDC on Arc

Payouts to cited creators appear here.

§ IIThe reading0 cited
Lowconfidenceno citation passed the evidence gate

The supplied sources do not discuss non-custodial browser session keys or their security tradeoffs. None of– mention browser session keys, private key custody, browser storage, revocation, or recovery. Therefore the subclaims cannot be verified or refuted from these sources.

Evidence ledger — quotes verified before rewards

  1. Non-custodial browser session keys reduce the risk of server-side mass key compromise because private keys never leave the user's device.

    0%

    No reward-qualifying evidence

  2. They increase the risk of permanent loss of access, as clearing browser storage or losing the device without a backup can destroy the key irrecoverably.

    0%

    No reward-qualifying evidence

  3. They are exposed to browser-level threats such as malware, malicious extensions, or XSS attacks that can extract the private key from memory or storage.

    0%

    No reward-qualifying evidence

  4. They lack central revocation and recovery mechanisms, so a compromised key may remain valid until its natural expiry unless the user manually reports the compromise.

    0%

    No reward-qualifying evidence

Helpful?
Spent$0
To creators100%
Decisions0 bought · 7 cached · 12 skipped
llm:deepseek:deepseek-v4-flash + llm:mimo:mimo-v2.5 on 1 step
Ask a follow-upNew dispatch · creators paid again

Carries this dispatch’s question as context — never its answer. The next dispatch is read from sources bought for it.

From the archive

Related dispatches