usesecret

Privacy leak · Wallet design

Session keys are identities too

Temporary ed25519 keys that avoid repeated prompts are registered on-chain.

medium

seen by: Anyone reading the chain

To avoid a biometric prompt for every action, some secret passkey wallets let the secret passkey authorize a short-lived ed25519 session key, often stored in the browser. The registration transaction links the session key to the vault. Every transaction signed by the session key is then attributable to you, and if the browser storage leaks, so does spending power until the session expires.

Mitigation

Keep sessions short, scope them to one program and a spend limit, and revoke them on-chain when done. Don't reuse a session key across vaults.
← Durable nonce accounts link pre-signed transactionsIf the domain disappears, the vault is stuck →

No analytics. No cookies. No third-party requests. Your key never leaves your device.