Component: web-wallet/ (checkpoint persistence)
Severity: Disclosed PoC boundary (README warning); filed per request for completeness
Summary
The WASM web wallet persists its checkpoint — including the BIP39 mnemonic (from which every coin secret, transfer auth key, and recovery-fee key derives) — unencrypted in browser localStorage. The README discloses this:
"The browser wallet stores its seed phrase and signing material unencrypted in localStorage."
Consequences beyond key theft by XSS/malicious extensions: snapshots survive in browser profile backups and sync; the mnemonic also derives the recovery-fee key, so theft covers both the statecoins and the funds meant to pay for unilateral exits.
Suggested direction
Passkey/WebAuthn-gated encryption of the checkpoint blob (PRF-derived KEK), or session-only storage for the mnemonic with explicit re-entry for signing operations.
Found during security review of feature/bip448-web-wallet-mutinynet @ 64d2423.
Component:
web-wallet/(checkpoint persistence)Severity: Disclosed PoC boundary (README warning); filed per request for completeness
Summary
The WASM web wallet persists its checkpoint — including the BIP39 mnemonic (from which every coin secret, transfer auth key, and recovery-fee key derives) — unencrypted in browser
localStorage. The README discloses this:Consequences beyond key theft by XSS/malicious extensions: snapshots survive in browser profile backups and sync; the mnemonic also derives the recovery-fee key, so theft covers both the statecoins and the funds meant to pay for unilateral exits.
Suggested direction
Passkey/WebAuthn-gated encryption of the checkpoint blob (PRF-derived KEK), or session-only storage for the mnemonic with explicit re-entry for signing operations.
Found during security review of
feature/bip448-web-wallet-mutinynet@ 64d2423.