usesecret

Privacy leak · On-chain

authenticatorData fingerprints your device

rpIdHash, backup flags, and signCount are signed, so they go on-chain too.

medium

seen by: Anyone reading the chain

The 37-byte authenticatorData is part of the signed message, so it sits inside the precompile instruction:

• rpIdHash: SHA-256 of the domain. Hash a list of likely wallet domains and compare.
• flags: backup-eligible and backed up usually separate an iCloud or Google synced secret passkey from a hardware key.
• signCount: synced secret passkeys report 0, while hardware keys increment it. An increasing counter shows how often the key is used and orders your transactions across vaults.

Mitigation

Nothing can be stripped, because these bytes are covered by the signature. Treat your authenticator type and rough usage as public.
← clientDataJSON puts the website on-chainYour token holdings are one RPC call away →

No analytics. No cookies. No third-party requests. Your key never leaves your device.