Privacy leak · Wallet design
If the domain disappears, the vault is stuck
A secret passkey only signs for the domain that created it, but your SOL stays on-chain.
high
seen by: n/a (availability risk)
A secret passkey is bound to its RP ID, so only pages served from
Passkeys.is documents a workaround: serve the open-source wallet locally on the old domain using
wallet.example can ask it to sign. If that domain expires, is seized, or is taken over, you can no longer sign for a vault whose only authority is that secret passkey. The funds stay on-chain but frozen, and a new owner of the domain could prompt your secret passkey on their own page.Passkeys.is documents a workaround: serve the open-source wallet locally on the old domain using
/etc/hosts and a locally trusted TLS certificate (for example mkcert).Mitigation
Vault programs should support multiple authorities: more than one secret passkey, a hardware key, or an
ed25519 recovery key with a time lock. Keep a copy of the wallet's source code.