nextAuth passwordless Strapi auth integration

My concern with that approach is that there is some hidden mysterious password set for ALL users.
What if somehow someone get to know it? Suddenly, it’s a key to ALL users.