fiatjaf on Nostr: I don't think there was ever a vulnerability in a Bitcoin wallet that allowed a ...
I don't think there was ever a vulnerability in a Bitcoin wallet that allowed a remote attacker to steal a key directly.
Maybe the entire "don't put nsecs in apps" is kind of a moot point. If the app developer takes basic precautions and is not insane the odds of the key being stolen are pretty small.
The real risks are:
- web apps, as they come with a bunch of risks related to web and how it executes scripts from whatever sources in many circumstances.
- evil apps that will steal your key on purpose.
- physical access to the device.
- government-sponsored (or not) remote takeovers of your entire OS.
Amber/NIP-55 defends against the first two of these, but by the same account it should also be fine to use a trustworthy native app like Wisp.
Published at
2026-08-20 21:00:56 UTCEvent JSON
{
"id": "9ebbbc3c10ff003c28daa97665bd5946ef726289d5ea1cac561a5f121b517551",
"pubkey": "3bf0c63fcb93463407af97a5e5ee64fa883d107ef9e558472c4eb9aaaefa459d",
"created_at": 1787259656,
"kind": 1,
"tags": [],
"content": "I don't think there was ever a vulnerability in a Bitcoin wallet that allowed a remote attacker to steal a key directly.\n\nMaybe the entire \"don't put nsecs in apps\" is kind of a moot point. If the app developer takes basic precautions and is not insane the odds of the key being stolen are pretty small.\n\nThe real risks are:\n\n- web apps, as they come with a bunch of risks related to web and how it executes scripts from whatever sources in many circumstances.\n- evil apps that will steal your key on purpose.\n- physical access to the device.\n- government-sponsored (or not) remote takeovers of your entire OS.\n\nAmber/NIP-55 defends against the first two of these, but by the same account it should also be fine to use a trustworthy native app like Wisp.",
"sig": "a2d380e543812fd53199a2f4932ca3c6d354f8adb848869cade69e6c03c9f43ab5272fdde21622adc129c96a907a3c3708f505317de0c828cf6d3b23d64c6494"
}