Join Nostr
2026-08-20 21:00:56 UTC

fiatjaf on Nostr: I don't think there was ever a vulnerability in a Bitcoin wallet that allowed a ...

I don't think there was ever a vulnerability in a Bitcoin wallet that allowed a remote attacker to steal a key directly.

Maybe the entire "don't put nsecs in apps" is kind of a moot point. If the app developer takes basic precautions and is not insane the odds of the key being stolen are pretty small.

The real risks are:

- web apps, as they come with a bunch of risks related to web and how it executes scripts from whatever sources in many circumstances.
- evil apps that will steal your key on purpose.
- physical access to the device.
- government-sponsored (or not) remote takeovers of your entire OS.

Amber/NIP-55 defends against the first two of these, but by the same account it should also be fine to use a trustworthy native app like Wisp.