Your assumption is partly correct regarding storing passwords and passkeys in Bitwarden. However, my MFA is managed separately through Google Authenticator, and the recovery codes are stored in a separate account that itself is protected by multifactor authentication, including access only via a hardware security key.
Additionally, my Bitwarden account is secured with a 32-digit random master password, multi-factor authentication, and a security key.
So while I understand the potential attack vectors you mentioned, I’ve taken steps to keep these components isolated and strongly protected.
I’m facing repeated personal account hacks on platforms like Instagram, Facebook, and Discord (twice). I described the situation and asked Discord support for help, but they only recommended the usual security measures and then closed the query as resolved.
In the case of Telegram, everything I built was compromised, and the attacker even joined some Russian channels using my account.
I’ve asked the same question on Defcon Discord and other places but received no answers. I also tried Reddit’s cybersecurity community, but nothing there either.
Can anything be done about this?