- Users need to understand public/private keys so that the can rotate keys whenever necessary. They should have had users generate the wallets empty and then have them authenticate as a second step to get the payout.
- Maybe you need government-authored software to carry out the business of government, but since the chain is public and the keys can be used for signing things other than transactions there's no need for that software to ever see your private key. You ought to be able to handle everything you need by sending signed messages to the government app or having the government app examine the chain.
- Pairing an ID number with a photo of a face is not a valid authentication step. Neither of these things are secrets. You're going to need a government employee to look at the ID and the face before they accept the key, that way when skulduggery ensues, that employee can be found and questioned. Relying on non-secrets to do the job of secrets is a bad idea--as everybody who has a ssn knows.