According to Odaily, SlowMist's Cosine emphasized on X that it is crucial to enable two-factor authentication (2FA) for wallets based on Privy. Although Privy uses a Shamir's Secret Sharing (SSS) scheme to generate and manage user shard private keys, the actual plaintext private key is ultimately restored on the target frontend, existing within an independent iframe context.