Privacy leak · Wallet design
Session keys are identities too
Temporary ed25519 keys that avoid repeated prompts are registered on-chain.
medium
seen by: Anyone reading the chain
To avoid a biometric prompt for every action, some secret passkey wallets let the secret passkey authorize a short-lived
ed25519 session key, often stored in the browser. The registration transaction links the session key to the vault. Every transaction signed by the session key is then attributable to you, and if the browser storage leaks, so does spending power until the session expires.Mitigation
Keep sessions short, scope them to one program and a spend limit, and revoke them on-chain when done. Don't reuse a session key across vaults.