|
|
|
|
|
by vessenes
3744 days ago
|
|
Update, after reading the FAQ, I think that because blockcypher knows your public addresses, if they were to learn a single private key, they could regenerate the tree from that point forward. But it would be great to get a blockcypher dev here to say for certain what the risk model is. |
|
> One weakness that may not be immediately obvious, is that knowledge of a parent extended public key plus any non-hardened private key descending from it is equivalent to knowing the parent extended private key (and thus every private and public key descending from it).
Does blockcypher get the extended public key? Can you use hardened derivation? IIRC the only reason not to use hardened derivation is so that someone else can compute more public addresses for you.