{"type":"rich","version":"1.0","author_name":"fiatjaf (npub180…jh6w6)","author_url":"https://nostr.ae/npub180cvv07tjdrrgpa0j7j7tmnyl2yr6yr7l8j4s3evf6u64th6gkwsyjh6w6","provider_name":"njump","provider_url":"https://nostr.ae","html":"I don't think there was ever a vulnerability in a Bitcoin wallet that allowed a remote attacker to steal a key directly.\n\nMaybe the entire \"don't put nsecs in apps\" is kind of a moot point. If the app developer takes basic precautions and is not insane the odds of the key being stolen are pretty small.\n\nThe real risks are:\n\n- web apps, as they come with a bunch of risks related to web and how it executes scripts from whatever sources in many circumstances.\n- evil apps that will steal your key on purpose.\n- physical access to the device.\n- government-sponsored (or not) remote takeovers of your entire OS.\n\nAmber/NIP-55 defends against the first two of these, but by the same account it should also be fine to use a trustworthy native app like Wisp."}
