usesecret

Privacy leak · Wallet design

If the domain disappears, the vault is stuck

A secret passkey only signs for the domain that created it, but your SOL stays on-chain.

high

seen by: n/a (availability risk)

A secret passkey is bound to its RP ID, so only pages served from wallet.example can ask it to sign. If that domain expires, is seized, or is taken over, you can no longer sign for a vault whose only authority is that secret passkey. The funds stay on-chain but frozen, and a new owner of the domain could prompt your secret passkey on their own page.

Passkeys.is documents a workaround: serve the open-source wallet locally on the old domain using /etc/hosts and a locally trusted TLS certificate (for example mkcert).

Mitigation

Vault programs should support multiple authorities: more than one secret passkey, a hardware key, or an ed25519 recovery key with a time lock. Keep a copy of the wallet's source code.
← Session keys are identities tooHigh-S signatures fail, and still leak →

No analytics. No cookies. No third-party requests. Your key never leaves your device.