usesecret

Privacy leak · Wallet design

High-S signatures fail, and still leak

The precompile only accepts low-S, 64-byte r||s signatures.

note

seen by: n/a (correctness)

WebAuthn returns ASN.1 DER signatures, and authenticators may produce either of the two valid s values. Solana's secp256r1 precompile requires the compact 64-byte r||s form with s ≤ n/2, to prevent malleability. Submitting raw DER, or a high-S value, makes the transaction fail.

A transaction that fails after landing still pays fees and still puts your public key on-chain, so it leaks data for nothing.

Mitigation

Convert and normalize before building the instruction: p256.Signature.fromDER(sig).normalizeS().toCompactRawBytes(). Simulate before sending.
← If the domain disappears, the vault is stuck

No analytics. No cookies. No third-party requests. Your key never leaves your device.