I don't think there was ever a vulnerability in a Bitcoin wallet that allowed a remote attacker to steal a key directly.
Maybe the entire "don't put nsecs in apps" is kind of a moot point. If the app developer takes basic precautions and is not insane the odds of the key being stolen are pretty small.
The real risks are:
- web apps, as they come with a bunch of risks related to web and how it executes scripts from whatever sources in many circumstances.
- evil apps that will steal your key on purpose.
- physical access to the device.
- government-sponsored (or not) remote takeovers of your entire OS.
Amber/NIP-55 defends against the first two of these, but by the same account it should also be fine to use a trustworthy native app like Wisp.
Maybe the entire "don't put nsecs in apps" is kind of a moot point. If the app developer takes basic precautions and is not insane the odds of the key being stolen are pretty small.
The real risks are:
- web apps, as they come with a bunch of risks related to web and how it executes scripts from whatever sources in many circumstances.
- evil apps that will steal your key on purpose.
- physical access to the device.
- government-sponsored (or not) remote takeovers of your entire OS.
Amber/NIP-55 defends against the first two of these, but by the same account it should also be fine to use a trustworthy native app like Wisp.
172โค๏ธ1๐3๐คทโโ๏ธ1