I have my money on social recovery/rotation for what it's worth. If a few close friends report the account as compromised, for example, and say "this is their new npub" - clients could easily pick up on it.
there has been no case of compromised keys that i am aware of, i'm curious to know if there has been though also, wen nip-06 in clients and signers ffs
Can't get your keys back from some clients.
yes, web clients are bad mkay, only use alby/nos2x/amber all good client devs should just remove in-app signing, period @hzrd149 *nudge*