Archived dispatch

What are the security tradeoffs of non-custodial browser session keys?

Lowconfidenceno citation passed the evidence gate

9/3/2026, 11:12:52 PM · llm:deepseek:deepseek-v4-flash + llm:mimo:mimo-v2.5 on 2 steps

The dispatch, itemised.

§ IThe decision$0.006 / $0.03
20%$0.024 under cap
Decompose

Breaking down: "What are the security tradeoffs of non-custodial browser session keys?"

Decompose

Identified 4 sub-claim(s) to support

Decompose

Deep mode: up to 4 paid/cached reads plus one bounded gap-expansion pass when needed.

Discover

Discovered 20 verified source(s)

Discover

Recalled 27 past runs on this subject — how these sources performed when they were available.

Discover

ERC-8004 reputation loaded — composite scores on this subject.

Pre-check

Claim-aware portfolio selected 4/5 positive proposal(s): 2 cached + 2 fresh, predicting 3/4 claim(s) above the evidence floor with $0.006000/$0.015000 fetch USDC reserved.

Pre-check

Free-preview pre-check covers 3/4 sub-claims (75%). The agent may buy only claim-targeted sources and will label the answer provisional if paid evidence stays thin.

DecideBUY
Vitalik Buterin's website — My self-sovereign / local / private / secure LLM setup, April 2026$0.004 · EV 70%

Vitalik Buterin's article on self-sovereign, private, secure LLM setup directly addresses client-side security, trust models, and local key management—highly relevant to non-custodial browser session keys. Worth $0.004. — selected for the claim-aware evidence portfolio (targets claims 1, 2, 3; $0.004000 fetch USDC, 1 attention slot).

DecideCACHE
Distributed Systems Notes — Idempotency keys prevent double-spends$0.003 · EV 60%

Distributed Systems Notes cached article on idempotency keys is highly relevant—distributing trust and preventing double-spends are core to session key security. Excellent source; reuse free. — selected for the claim-aware evidence portfolio (targets claims 1, 2; 0 fetch USDC, 1 attention slot).

DecideCACHE
Ethereum Foundation Blog — The triage is the product: running AI agents against Ethereum's protocol code$0.002 · EV 50%

Ethereum Foundation Blog cached article discusses AI agents running against protocol code, touching on security testing and trust models. Some relevance to security tradeoffs; reuse free. — selected for the claim-aware evidence portfolio (targets claims 2, 3; 0 fetch USDC, 1 attention slot).

DecideBUY
Decrypt — Dozens of Fake Firefox Wallet Extensions Linked to Crypto-Stealing Malware$0.002 · EV 85%

Decrypt article on fake Firefox wallet extensions and crypto-stealing malware is directly on-point—illustrates browser extension threats, a key client-side risk for session keys. Excellent match; worth $0.002. — selected for the claim-aware evidence portfolio (targets claim 2; $0.002000 fetch USDC, 1 attention slot).

DecideSKIP
Stablecoin Ledger — Why USDC settles instantly onchain$0.003 · EV 10%

Stablecoin Ledger is cached but its content is about USDC settlement speed, not browser session key security tradeoffs. Low relevance; skip without cost. — the free-preview coverage check could not connect this source to any sub-claim, so no toll is authorized.

DecideSKIP
Agent Economy Weekly — x402 turns HTTP 402 into an agent payment rail$0.004 · EV 10%

Agent Economy Weekly cached article is about x402 payment rails for AI agents, not client-side key security. Off-topic for this security-focused question. — the free-preview coverage check could not connect this source to any sub-claim, so no toll is authorized.

DecideSKIP
Onchain Micropayments Digest — Nanopayments and the $0.000001 floor$0.005 · EV 10%

Onchain Micropayments Digest cached article covers nanopayment settlement mechanics, not the security tradeoffs of non-custodial browser session keys. Not useful here. — the free-preview coverage check could not connect this source to any sub-claim, so no toll is authorized.

DecideSKIP
Garden & Soil Monthly — Building a no-dig raised bed$0.002 · EV 0%

Garden & Soil Monthly is about organic gardening; completely off-topic for crypto/browser security. No value.

DecideSKIP
Retro Game Hardware — Recapping a 1990s console$0.002 · EV 0%

Retro Game Hardware article is about vintage console repair; irrelevant to browser session key security.

DecideSKIP
Stripe Blog — New currency capabilities for global businesses to cut FX costs$0.002 · EV 20%

Stripe Blog cached article is about FX capabilities for global businesses, not browser-side key security. Low relevance. — the free-preview coverage check could not connect this source to any sub-claim, so no toll is authorized.

DecideSKIP
Cointelegraph.com News — US officials work with CrowdStrike to fight malware behind crypto theft$0.002 · EV 80%

Cointelegraph article on malware fighting crypto theft is directly relevant—illustrates client-side threats (malware) that non-custodial browser session keys must defend against. High topical value; worth $0.002. — the claim-aware portfolio chose a stronger, less redundant set inside the 4-source attention and $0.015000 fetch-budget caps, so this proposal stays unspent.

DecideSKIP
Latent.Space — Ontologies Are So Back: Why AI Agents Are Reviving the Semantic Web$0.004 · EV 20%

Latent Space article cached but focuses on AI agent ontologies and semantic web, not browser session key security. Off-topic.

DecideSKIP
Simon Willison's Weblog — New release of LLM adds support for reasoning traces, OpenAI Responses, server-side tools, and smarter logging$0.003 · EV 10%

Simon Willison's Weblog article is about LLM tooling and logging; not relevant to browser session key security tradeoffs.

DecideSKIP
Hugging Face - Blog — Give Your Coding Agents a Memory You Own$0.003 · EV 10%

Hugging Face article on coding agent memory is about LLM infrastructure, not client-side key security. Low value for this question.

DecideSKIP
The Coinbase Blog - Medium — Celer Bridge incident analysis$0.003 · EV 40%

Coinbase Blog cached article analyzes a bridge compromise with security tips; relevant to attack vectors and incident response but older. Moderate value; reuse free. — cached bytes are free, but this read does not clear the attention gate (EV 0.40, minimum 0.45, with a required claim target).

DecideSKIP
CoinDesk: Bitcoin, Ethereum, Crypto News and Price Data — Crypto Long & Short:$0.002 · EV 20%

CoinDesk article cached but covers settlement cycles and capital efficiency, not browser session key security. Low relevance. — the free-preview coverage check could not connect this source to any sub-claim, so no toll is authorized.

DecideSKIP
Inner Axiom — The Codex — ISIS: The Godess, From An Esoteric Perspective$0.002 · EV 0%

Inner Axiom article is about esoteric mythology; completely irrelevant to browser session key security.

DecideSKIP
Conzit Labs — Innovative Gaming: Client-Side Groth16 Proofs in Dario Dash$0.002 · EV 10%

Conzit Labs article on client-side proofs in gaming is tangential—mentions client-side cryptography but not browser session keys. Low value.

DecideSKIP
Arc Settlement Benchmarks — Measuring x402 settlement latency on Arc$0.003 · EV 20%

Arc Settlement Benchmarks cached article measures x402 latency; not about browser session key security tradeoffs. Skip. — the free-preview coverage check could not connect this source to any sub-claim, so no toll is authorized.

DecideSKIP
Web Payments Review — How long do x402 payments take to finalize?$0.002 · EV 20%

Web Payments Review cached article is about payment finality timing; not relevant to session key security. Skip. — the free-preview coverage check could not connect this source to any sub-claim, so no toll is authorized.

Fetch

Agent spend wallet ready: 0x29028Fe1122E17Fe7863A22701e863FE4DaE1aFB (balance sufficient)

Fetch

Paying $0.004 toll to read Vitalik Buterin's website — My self-sovereign / local / private / secure LLM setup, April 2026…

Fetch

Paid $0.004 to Vitalik Buterin's website — My self-sovereign / local / private / secure LLM setup, April 2026, but its content response failed after settlement; receipt retained and the run continues without that article.

Fetch

Reused cached Distributed Systems Notes — Idempotency keys prevent double-spends (free) — S2

Fetch

Reused cached Ethereum Foundation Blog — The triage is the product: running AI agents against Ethereum's protocol code (free) — S3

Fetch

Paying $0.002 toll to read Decrypt — Dozens of Fake Firefox Wallet Extensions Linked to Crypto-Stealing Malware…

Fetch

Paid $0.002 to Decrypt — Dozens of Fake Firefox Wallet Extensions Linked to Crypto-Stealing Malware (settled 2c3ef9a5-8…) — S4

Sufficiency

Sub-claim "Non-custodial browser session keys prevent server-side key t…": 0% covered

Sufficiency

Sub-claim "They increase exposure to client-side threats such as malwar…": 0% covered

Sufficiency

Sub-claim "The short-lived nature of session keys reduces the window of…": 0% covered

Sufficiency

Sub-claim "Without strong permission scoping, session keys may grant ex…": 0% covered

Sufficiency

The gathered sources discuss idempotency keys, AI agent security triage, and malicious wallet extensions, but none of them mention non-custodial browser session keys or their security tradeoffs. Therefore, there is no coverage for the sub-claims.

Re-evaluate

Sub-claim "Non-custodial browser session keys prevent server-side key t…": 0% covered — No gathered content addresses non-custodial browser session keys or whether private keys remain on the client device. The provided snippets are about idempotency, AI protocol triage, and fake browser extensions.

Re-evaluate

Sub-claim "They increase exposure to client-side threats such as malwar…": 20% covered by S4 — S4 documents malicious Firefox wallet extensions harvesting recovery phrases, which is an example of a malicious browser extension exposing client-side credentials. However, it does not specifically discuss session keys, malware generally, or XSS, so coverage is weak.

Re-evaluate

Sub-claim "The short-lived nature of session keys reduces the window of…": 0% covered — No gathered source discusses the temporal expiration of session keys or any related reduction in attacker opportunity.

Re-evaluate

Sub-claim "Without strong permission scoping, session keys may grant ex…": 0% covered — No gathered source addresses permission scoping, transaction capabilities, or impact amplification for session keys. The idempotency note concerns retries, not authorization scope.

Re-evaluate

All sub-claims have coverage below 0.5, but after reviewing the available skipped sources, none directly or substantively addresses non-custodial browser session keys, their client/server key custody, session lifetime, or permission scoping. Purchasing unrelated sources would not meaningfully close the coverage gap and would waste budget.

Sufficiency

Final check — "Non-custodial browser session keys prevent server-side key t…": 0% assessed

Sufficiency

Final check — "They increase exposure to client-side threats such as malwar…": 30% assessed by S4

Sufficiency

Final check — "The short-lived nature of session keys reduces the window of…": 0% assessed

Sufficiency

Final check — "Without strong permission scoping, session keys may grant ex…": 0% assessed

Sufficiency

Final coverage assessment — The gathered sources do not cover the core security tradeoffs of non-custodial browser session keys. S4 mentions malicious browser extensions, which relates to client-side threats, but the other sub-claims about server-side theft prevention, reduced window for misuse due to short-lived keys, and permission scoping are not addressed. Therefore, more information is needed.

Synthesize

Synthesizing a grounded answer from 3 source(s)…

Evidence

No citation passed the evidence gate — the $0.015000 citation pool stays unspent; settled access tolls still stand.

Synthesize

Drafted answer citing 0 source(s)

Verdict

Confidence: Low — no citation passed the evidence gate.

Done

Done. Spent $0.006 across 2 confirmed/simulated payment(s) to creators.

§ IIIThe settlementweighted · USDC on Arc

Payouts to cited creators appear here.

§ IIThe reading0 cited
Lowconfidenceno citation passed the evidence gatedeep researchpreview plan 3/4 claimsportfolio 4/5 · evidence 0%

None of the supplied sources discuss non-custodial browser session keys or their security tradeoffs. Therefore, none of the four subclaims can be supported: the sources do not address where private keys are stored, client-side threat exposure for session keys, key lifetime reduction of compromise windows, or permission scoping of session keys.

Evidence ledger — quotes verified before rewards

  1. Non-custodial browser session keys prevent server-side key theft since private keys never leave the client device

    0%

    No reward-qualifying evidence

  2. They increase exposure to client-side threats such as malware, malicious browser extensions, and cross-site scripting attacks

    0%

    No reward-qualifying evidence

  3. The short-lived nature of session keys reduces the window of opportunity for an attacker to misuse a compromised key

    0%

    No reward-qualifying evidence

  4. Without strong permission scoping, session keys may grant excessive transaction capabilities, amplifying the impact of theft

    0%

    No reward-qualifying evidence

Helpful?
Spent$0.006
To creators100%
Decisions2 bought · 2 cached · 16 skipped
llm:deepseek:deepseek-v4-flash + llm:mimo:mimo-v2.5 on 2 steps

Portable research receipt

Take the evidence trail with you

One deterministic JSON bundle binds the answer, visible decisions, exact article versions, claim evidence and a Circle-settlement snapshot under SHA-256. Retain the digest to detect later changes; the self-check is not a publisher or Keryx signature.

Ask a follow-upNew dispatch · creators paid again

Carries this dispatch’s question as context — never its answer. The next dispatch is read from sources bought for it.

From the archive

Related dispatches