Does this mean that your private servers have the ability to re-key notes? What prevents someone from scanning the chip or storing the user key that they generated, handing the note to someone else, and then walking around the corner and immediately using the scanned information to re-key it?
Without understanding more about the technical details, this feels like unless a user is using an app to re-key immediately at the time of transfer that it's significantly less secure than normal cash. I guess I'm not completely clear on what you're doing with user keys.
---
> Because with a phone alone they need to store their keys locally.
But they have to do that here too, or is the assertion that they don't need to back up the user key necessarily and that it's not secret? Is the user key just plain-text readable?
If the user key is accessible from the chip just via scanning (not cutting), and isn't a user-defined secret that only they know (which seems like would require some form of backup), then does that mean an attacker can just walk past my wallet with a reasonably powerful RFID reader and then rekey every single one of my bills?