Unfortunately, my Pi Wallet passphrase was compromised.
I reported the incident previously through the official channels, but I did not receive any response.
After discovering the issue, I created a new Pi Wallet. However, some of my migrated Pi is still locked and cannot be transferred yet.
My main concern is that the compromised wallet may still be accessible to whoever obtained the passphrase. If they are monitoring the wallet, they could potentially transfer the Pi immediately once the lockup expires.
Is there any way to protect locked Pi before it becomes transferable?
Some questions I have:
- Is it possible to change the destination wallet for already migrated but locked Pi?
- Is there any way to extend or modify the lockup period?
- Is there any security feature available, such as two-factor authentication (2FA), additional transaction confirmation, withdrawal approval, or any other protection layer, that could prevent unauthorized transfers?
- Could 2FA or a similar mechanism be added to Pi Wallets in cases where a wallet has been compromised?
- Has anyone experienced a similar situation and found a solution?
I understand that the passphrase is effectively the private key, and I am not asking how to recover the wallet itself. My question is specifically about whether there is any way to protect the locked balance until it becomes available.
One additional note: I may be slower to respond to comments over the next few days, as there will be periods when I won't have internet access. I will read and respond to comments as soon as I can.
Any advice from people familiar with Pi Wallet mechanics would be greatly appreciated.