Wow! Ton of information here indeed!

I mean. Using the XPUB to generate a watch-only wallet (for instance on Blockstream green) comes in handy I think. But indeed… it ā€œleaksā€ all your addresses to some software you don’t own. However, that software being open source is ā€œsaferā€?

Reply to this note

Please Login to reply.

Discussion

If you don’t control the Electrum server you connect to, you can’t know what logging or monitoring they’re using.

For example, they could be running a free and open source Electrum server implementation like Fulcrum, but put it behind a reverse proxy that logs all traffic.

The software running on your wallet and/or hardware signing device can’t protect you against a logging third-party server.

So if you’re running your own node and connect your wallet to electrs, you should be good to go then. Only problem is, I can’t run my node at the moment šŸ˜