pull down to refresh
Yeah, not only is that possible, it actually happened to me just recently with the CC vulnerability. I have a dedicated account (no kyc) for Nunchuk and I have notifications turned off. I completely missed the email about the platform keys being generated with an MK4... Didn't know about it until I saw someone post about it on X. And the database leak is a risk but again, no KYC, no address, no name. Nothing. So wouldn't really think about that being a concern.
For me, BitKey is just a different set of trade-offs. It's KYC and the hardware is made by a single vendor. Fuck that. Chain Code Delegation is a cool thing that definitely helps with the privacy aspect of collaborative custody but you just give that up when you use BitKey, unless I misunderstand.
Forgive the AI but it's useful here:
As far as I understand, the email is quite important, as you would get notifications there that you have to catch in case of a delayed cosign event, etc. Thus, you would usually have to install the app from the mail provider, turn on notifications, etc., and by doing this, link the device to your "identity/location". So, IMO, the moment the Nunchuk database leaks, an "attacker" would see all emails/clients, including their related balances, and then decide if it's worth locating this customer. So, at least to me, this seems like a lot of personal risks added for the purpose of inheritance or simply because you want a kind of other signer in your setup (iron hand plan). All this would be mitigated in big parts, IMO, by adopting chain delegation, etc.
Don't get me wrong, I don't want to talk bad about the product. I personally look to upgrade my multisig after the recent events and came to Nunchuk through this and am evaluating pros/cons now, but for me, if I get it right, at the moment it seems like it would at least for me create more headache than it solves. If they could offer the same service without these issues, which seems technically possible (chain delegation), it would be an easy yes for me, I assume.