usesecret

Privacy leak · On-chain

clientDataJSON puts the website on-chain

Verifying the challenge on-chain means publishing the origin you signed on.

high

seen by: Anyone reading the chain

A secret passkey never signs your Solana transaction directly. It signs authenticatorData || SHA-256(clientDataJSON), where clientDataJSON is built by the browser:

{"type":"webauthn.get","challenge":"…","origin":"https://wallet.example"}

To prove that the challenge equals the transaction hash, a program has to receive the full clientDataJSON in instruction data and parse it. That publishes the exact origin, subdomain included, next to your public key. It also costs 100–200 bytes of a transaction that is capped at 1232 bytes.

Mitigation

Assume the origin is public. Serve the wallet from one origin that reveals nothing beyond "a wallet", and avoid per-user or per-tenant subdomains such as alice.wallet.example.
← Your public key gives away your vault addressauthenticatorData fingerprints your device →

No analytics. No cookies. No third-party requests. Your key never leaves your device.