Does a web page get the same PRF bytes a native Android app gets, for the same passkey + rpId + salt? Compare the hex below with the app's.
rpId (this origin):—
PRF salt (fixed, = the suspect app's):"wallet" → base64url d2FsbGV0
WebAuthn available:checking…
Step 1 — create the test passkey (once)
—
Step 2 — read the PRF output (this is the wallet entropy)
PRF output — 32 bytes (compare this with the app)
—
Derived BIP39 seed phrase (downstream of the bytes above)
—
If the app prints the same 32 hex bytes, the seed is re-derivable from a web page on this rpId → the vector is real. Different bytes → WebAuthn domain separation defeats it.