The main problem is that a lot of Lightning, ecash, etc. wallets allow you to associate an nsec to unlock the wallet. Not many people pasting their nsecs into random vibecoded apps are security-conscious enough to use a separate Nostr key, so if one of those vibecoded apps leaks nsecs, you can pretty much scan the respective lud16 for half a dozen popular wallet domains and, more likely than not, hit the BTC jackpot.

Replies (1)

Oh yea, if you're raw dogging your nsec around like that, good luck. The more I've looked at NWC the more I think I'm just going to keep paying the invoices manually with my existing lightning wallet. It was annoying when I was using speed wallet but now that I can see who zaps me using Zeus I'm pretty content with the flow as is. A little friction with the flow of money is often a good thing.