<oembed><type>rich</type><version>1.0</version><author_name>fiatjaf (npub180…jh6w6)</author_name><author_url>https://nostr.ae/npub180cvv07tjdrrgpa0j7j7tmnyl2yr6yr7l8j4s3evf6u64th6gkwsyjh6w6</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>I don&#39;t think there was ever a vulnerability in a Bitcoin wallet that allowed a remote attacker to steal a key directly.&#xA;&#xA;Maybe the entire &#34;don&#39;t put nsecs in apps&#34; is kind of a moot point. If the app developer takes basic precautions and is not insane the odds of the key being stolen are pretty small.&#xA;&#xA;The real risks are:&#xA;&#xA;- web apps, as they come with a bunch of risks related to web and how it executes scripts from whatever sources in many circumstances.&#xA;- evil apps that will steal your key on purpose.&#xA;- physical access to the device.&#xA;- government-sponsored (or not) remote takeovers of your entire OS.&#xA;&#xA;Amber/NIP-55 defends against the first two of these, but by the same account it should also be fine to use a trustworthy native app like Wisp.</html></oembed>