Privacy leak · On-chain
Signatures reveal the public key
One signature plus its message is enough to recover the secret passkey's public key.
medium
seen by: Anyone with a signature and its message
WebAuthn only hands you the public key at creation time, which makes it look private. It isn't. ECDSA allows public key recovery: from one signature and the signed bytes you get at most two candidate keys, and a second signature leaves exactly one. Combined with the vault derivation, a single leaked assertion can reveal your vault.
On Solana the key is in the instruction anyway. This matters for assertions you send off-chain, for example to a backend for login, or to a relayer before submission.
On Solana the key is in the instruction anyway. This matters for assertions you send off-chain, for example to a backend for login, or to a relayer before submission.
Mitigation
Treat assertions like your address and only send them to parties you would give your vault to. The playground runs this recovery on your own signature.