been reading about this. samo uses hardened xpubs, which can be used to derive sibling accounts. only if the postmix xpub is shared does the problem exist as we think

Reply to this note

Please Login to reply.

Discussion

If the app shows you the balance, it sent the xpub. Each of the 4 whirlpool accounts were sent. Only question is whether the agencies got that data, or eg. it was/will be wiped 🤷‍♂️

I'd err on the side of the xpub data being compromised

the app has separate views for each balanc eof the 4 accounts. if u havent opened the tab for mix in quite a while, the 3 relevant xpub may have been deleted from the cache

deposit xpub might as well be kyc anyway, if the funds deposited to it came from an exchange