> The box survives because it looks like a password field
I think this input field should not allow nsec anymore; if it detects nsec—it should become red with a warning text that it's basically not an adequate idea to paste it here or in other clients.