Capitec Secure Safe: Why a Duress PIN Makes You Less Safe, Not More

Capitec Secure Safe: Why a Duress PIN Makes You Less Safe, Not More

👁6views

Capitec's Secure Safe removes accounts from the digital attack surface entirely. Once placed in the safe, an account has no digital footprint inside the banking app, cannot be transferred from the phone, and cannot be reached through normal digital banking channels. To access the money, the client must visit a branch in person.

CloudScale AI SEO: Article Summary
  • 1.
    What it is
    Capitec Secure Safe is a banking feature that removes accounts from the digital attack surface entirely rather than disguising them with clever tricks like duress passwords.
  • 2.
    Why it matters
    Clever security tricks fail because criminals learn about them through the same public channels as everyone else, so true protection requires making money digitally unreachable from the phone and from normal digital banking channels.
  • 3.
    Key takeaway
    The safest money is the money that is not digitally reachable to begin with, not money protected by another password or hidden feature that will eventually stop being hidden.
~12 min read
🎧 Listen to this article

1. The problem we are actually solving

South Africa has a crime problem that has quietly evolved into a banking problem. Violent crime is increasingly targeted at forcing people to unlock their phones and hand over their money. The industry has a name for it now, transfer mugging, and it is growing fast. Express kidnappings, where a victim is grabbed and forced to open their banking app on the spot, rose by seventy three percent in the first half of 2025. On average, one hundred and eighty nine phones are stolen in South Africa every single day, and cybercrime losses in South African banking reached R3.9 billion last year.

The knock on effect of this is what worries me most. A comparable pattern shows up in mobile banking research from the United States, where forty two percent of people who avoid banking apps altogether cite security distrust as the reason, and it would not surprise me if South African clients feel that pressure even more sharply given what they are actually facing here. Some clients have taken to uninstalling their banking app entirely before they leave home. That is not a client behaving irrationally. That is a client responding sensibly to a genuine threat with the only tool available to them. But it should not be necessary, and it tells you the industry has been solving the wrong layer of the problem.

It is worth being honest about what this problem actually is, because it is easy to talk about it as a software question when it is really a human one. Nobody lies awake worrying about an algorithm. They worry about being followed home, about a hand on their shoulder in a parking lot, about a voice telling them to unlock their phone before they have even worked out what is happening. Every feature discussed in this article exists because of that fear, not because of a gap in encryption or a weakness in an authentication flow. A duress attack does not care how strong your password policy is. It cares whether the person standing in front of a criminal has anything left to hand over once their phone is unlocked, and the honest answer for most clients today is that they do. Any solution that does not start from that fear, and end with genuinely removing the reason for it, is solving the wrong problem no matter how clever the engineering underneath it looks.

2. Why the clever tricks do not work

A comment on one of my earlier posts asked a fair question. Why not build something like the duress password found in GrapheneOS, where entering a special password secretly wipes the device if someone forces you to unlock it. It is a sensible idea for protecting a phone. Banking under physical duress is a different problem entirely, because the thing you are protecting is not the device. It is the client standing in front of an armed criminal.

The trouble with any clever secret is that it stops being a secret the moment a bank markets it. Criminals read the same press releases, the same app store update notes, and the same breathless coverage of new security features that everyone else does. A special password that quietly shows a fake balance sounds ingenious right up until the marketing team announces it exists, at which point every criminal in the country knows it exists too.

Picture what that actually means for the person standing there with a gun pointed at them. They enter what they believe is a safe number, and now they have to plead with an armed attacker that the low balance on the screen is genuine and that they did not just use the special pin. The criminal has read the same comms you have, so they know the feature exists, and they are going to apply enormous pressure before they believe anyone. You have not removed the danger. You have added an entire negotiation to it, one where the victim carries the burden of proof. Perversely, a client would have been safer without the feature at all, because there would be nothing to be accused of hiding in the first place. That is an appalling position to put someone in, and it is the same flaw hiding inside every version of this idea, whether it is renaming the app, changing its icon, burying it in a folder, running a decoy account, or setting a secondary password that quietly triggers a hidden state. Every one of those tricks depends entirely on the criminal not knowing about it, and history tells us that secrecy of that kind never survives contact with a large enough population of criminals for long, especially once the bank itself has told everyone the trick exists. Under real coercion, a renamed app can be recognised by its layout, a fake balance can be cross checked against a second device, a hidden account can be found by anyone patient enough to swipe through folders, and a secondary password can simply be beaten out of someone once its existence is suspected. None of these survive a determined duress attack, because they were never designed to remove the account from the attacker’s reach. They were only designed to make it slightly harder to find, and slightly harder is not the same as unreachable.

That leads to a much simpler and more powerful idea than any of the tricks above. The safest digital account is the one that simply does not exist digitally.

It is worth addressing the strongest version of this idea directly, because it comes up often enough that it deserves a proper answer rather than a dismissal. Some people suggest a duress PIN that looks identical to a normal PIN but silently flags the transaction to the bank for enhanced fraud monitoring, rather than showing a fake balance. It sounds safer because nothing on screen changes. But Capitec, like every bank, sometimes delays or holds a payment for entirely ordinary reasons that have nothing to do with duress, and a criminal who has heard that a silent flag exists now has a reason to treat any delay as proof that one was used. The client did not signal anything. The payment was simply slow. That does not matter to someone who is already primed to suspect a trick, and the client ends up carrying the risk of retribution for a delay they had no control over and possibly never triggered at all. A feature that can be blamed on the victim even when they did nothing is not a safer feature. It has just moved the danger to a moment the bank cannot control.

3. The real issue is digital visibility

Once you strip away the disguises, the underlying problem is unchanged, because the account still exists digitally. If it lives on the phone it can be found, if it appears anywhere in a support system it can be queried, and if it is something that can be demanded under duress at all then it remains part of the attack surface no matter how well it is disguised. That is the insight that matters here, and it is the one that most of the industry’s thinking about this problem has missed.

Most banking security asks a narrow question. How do we better protect digital access. It is the right question for almost every threat a bank faces, from phishing to sim swaps to card skimming, and it is the wrong question for a coercive crime happening in person, because a criminal standing next to the victim is not trying to defeat your authentication. They already have it, because the victim is unlocking it for them. The question that actually matters for this threat is not how you protect digital access more cleverly. It is whether digital access needs to exist at all.

Once you frame it that way, the design principle almost writes itself. Every improvement to a duress password, a hidden folder, or a fake balance is still an improvement to something that exists, and something that exists can eventually be found, demanded, or beaten out of someone. The only category of solution that actually changes the outcome for the client is one that removes the thing itself, so that there is nothing left for the criminal to find no matter how much time or violence they are willing to use.

4. Removing the attack surface instead of disguising it

The obvious response to that insight is not to disguise an account more cleverly but to remove it from the attack surface entirely, and that is the philosophy behind the feature we have just shipped at Capitec, which we are calling Secure Safe. The goal was never to make an account hard to find. The goal was to make it digitally unreachable.

Think about the difference between cash sitting in your wallet and cash sitting inside a physical vault at a bank branch. A criminal can empty your wallet in seconds, but nobody can stand on the pavement outside and force that vault open, because the vault still exists, it is simply not reachable from where the criminal is standing. Secure Safe brings that same physical logic into a digital world. Once an account is placed into the safe it has no digital footprint inside the banking app at all, it cannot be transferred from the phone, and it cannot be reached through any of the normal digital banking channels, and even our own staff cannot simply browse and discover it. The account also disappears from the list of accounts you can transfer to from within the app, so you cannot move money into it the way you would with any other account you hold. Instead you get money in the way you would send it to anyone else, as a normal beneficiary payment, which means the vault can keep receiving deposits without ever reappearing as a destination a criminal could point to and demand. The only way to reveal that a hidden account exists is for the client to explicitly authorise a query using their own fingerprint, and without that deliberate action the vault effectively does not exist and the digital duress vector disappears completely. To actually reach the money you need to walk into a branch, exactly the way you would with a physical vault.

It helps to compare the two attack paths side by side. In a traditional savings account, the path from client to bank runs through a single link, the phone, and anyone holding the phone unlocked in the client’s hand holds the account. In Secure Safe, that same path now runs through the branch, the vault record, the client’s own fingerprint, and the bank’s internal process for releasing an account from the safe. An attacker does not just need the phone anymore. They need the client to physically walk into a branch, they need the fingerprint of a living person who is willing to authorise the release, and they need to get past a process that was never designed to be rushed. That is not a harder version of the same attack. It is an entirely different attack surface, and one that a mugging on the street cannot reach no matter how much pressure is applied.

5. This is a deliberate trade off, not an oversight

I want to be direct about something. This is intentionally inconvenient, and that inconvenience is the entire point. If you are overseas and suddenly need the money, you will not get it. If you are travelling, the funds stay locked away regardless of how urgent the need feels in the moment. The vault behaves like a vault, not like a savings account with better marketing.

That means clients need to think carefully about what belongs in there before they use it. Emergency spending money almost certainly does not belong in Secure Safe. A pension payout, a lifetime of savings, money set aside for retirement or a house deposit, those are a completely different conversation and exactly the kind of balance this feature was built to protect. And to be clear on the practical detail that always comes up, if the account holder passes away, the funds remain part of their deceased estate and are administered through the normal legal process like any other asset.

6. The broader point about security design

Most security features try to make life harder for criminals within the existing rules of the game. The problem is that criminals adapt to those rules faster than most institutions can ship features. The strongest security designs do not try to change a criminal’s decision at the point of a duress attack. They remove the decision from existing at all. Instead of asking how you stop someone being forced to transfer money under coercion, the better question is what happens if there is simply nothing available to transfer in the first place.

Good security is not always about adding another layer. Sometimes it is about removing the attack surface altogether. Secure Safe is not harder to attack because we added more software on top of the account. It is harder to attack because, for that account, the software largely disappears, and a criminal cannot force open a door that was never there.

References

  1. National Financial Ombud Scheme digital banking fraud complaints, up 73 percent, BusinessTech
  2. SAPS average of 189 cellphones stolen daily in South Africa, Institute for Security Studies
  3. SABRIC banking fraud losses reaching R3.9 billion in 2025, EBNewsDaily
  4. Forty two percent of non app users citing security distrust, a United States finding rather than a South African one, NerdWallet