usesecret

Privacy leak · On-chain

One secret passkey links every transaction

The secp256r1 instruction publishes the same 33-byte public key every time you sign.

high

seen by: Anyone reading the chain

A secret passkey cannot be a native Solana signer, because Solana signatures are ed25519 and secret passkeys are P-256. Instead, each transaction carries a Secp256r1SigVerify1111111111111111111111111 precompile instruction. Its data holds the compressed public key, the signature, and the signed message, all in plaintext.

The precompile's program id is in the transaction's account list, so an indexer can list every transaction that uses it and group them by the 33-byte key inside. Every vault, program, or app verified by the same secret passkey falls into one group, even if each vault has a different address.

Mitigation

Use one secret passkey per vault. Secret passkeys are scoped to a domain (the RP ID), so different sites can never share a credential, but one site serving several vaults should create a fresh secret passkey for each.
← All leaksYour public key gives away your vault address →

No analytics. No cookies. No third-party requests. Your key never leaves your device.