could bluewallet be leaking xpubs (if you setup a watch only wallet)? or is that unlikely / impossible?
Discussion
I don’t know for sure. Perhaps use this setup for your cold storage.
For your ultra-cold storage, use tools (cold card address explorer, seed tools offline, etc) to derive address and only check those on self-hosted block explorer. That way xpub never touches internet.