CfB has mentioned that if one gets access to the memory of Java Virtual Machine then your passphrase would be exposed.
That makes forging a *very* risky endeavor!
Wouldn't a big stakeholder have to have the biggest balls in the world to forge? Everyone knows their IP. Does everyone know their account number (and balance) if they're forging? If so, they're a massive target with a huge reward.
If one were to get the passphrase, all they would need to do is unlock the account and see for themselves!
Yes, but are the account numbers of hallmarked nodes known? If so, an attacker could target the one with the highest balance.