Gzuuus on Nostr: Yes, a profile can announce the xpub is using for derivation and provide derivation ...
Yes, a profile can announce the xpub is using for derivation and provide derivation path for the subkeys used, but there are some security concerns about hardened derivation path if one subkey gets leaked, then with that SK and the xpub you can get the root SK if I'm not wrong (its fairly possible I'm wrong 😅)
Published at
2025-02-26 14:09:45Event JSON
{
"id": "b4e8f120ccd4b94c6baa5b44504e4a0637e011ccdc030aca97717def9cfc9a83",
"pubkey": "40b9c85fffeafc1cadf8c30a4e5c88660ff6e4971a0dc723d5ab674b5e61b451",
"created_at": 1740578985,
"kind": 1,
"tags": [
[
"e",
"78a3b4acc549dc3c58232d00a4420bcb99a0442126821082427653b4ad716b8f",
"",
"root"
],
[
"e",
"78a3b4acc549dc3c58232d00a4420bcb99a0442126821082427653b4ad716b8f",
"",
"root"
],
[
"e",
"da8e98671a955c24752e15ba2f18be7c6bf0c44988ef655c6f456a4bcb8aea65",
"",
"reply"
],
[
"p",
"de7ecd1e2976a6adb2ffa5f4db81a7d812c8bb6698aa00dcf1e76adb55efd645"
],
[
"p",
"05933d8782d155d10cf8a06f37962f329855188063903d332714fbd881bac46e"
]
],
"content": "Yes, a profile can announce the xpub is using for derivation and provide derivation path for the subkeys used, but there are some security concerns about hardened derivation path if one subkey gets leaked, then with that SK and the xpub you can get the root SK if I'm not wrong (its fairly possible I'm wrong 😅) ",
"sig": "56f6ba1d3b22a3686d3bbb7ba22ecb11ba24f37aba7bb5029afcb4d2114f22e214614aafc1befa357e9377f03ddec191323cbb8eea777e0e20ff6c32540e0c8c"
}