usesecret

Privacy leak · On-chain

Your public key gives away your vault address

Vault PDAs are derived from public seeds, so anyone with the key can compute the address.

high

seen by: Anyone who has seen your public key

Secret passkey wallets typically derive the vault as a PDA from the secret passkey, for example seeds = ["passkey", sha256(pubkey)] under the wallet program. Seeds and program code are public, so the mapping is too.

Anyone who sees your secret passkey's public key, from a single transaction, a backend log, or a shared signature, can run findProgramAddressSync and get your vault address. From there they can read your balances and full history.

Mitigation

Mix a random salt into the seeds, such as ["vault", salt] with the secret passkey stored as an authority inside the account. The address then can't be recomputed from the key, though anyone watching the creation transaction can still link the two.
← One secret passkey links every transactionclientDataJSON puts the website on-chain →

No analytics. No cookies. No third-party requests. Your key never leaves your device.