Original Reporter: Nat
In the case of cloud based wallet (aka IdP), not only k-anonymity but pairwise pseudonymity is lost if there is only one user. My IdP is like that.
It probably is worth analysing if similar risk exists for mobile wallets / SIOP.
Whether or not if the risk exists, it a summary of the analysis should go into the Privacy Consideration.
I have marked the component as SIOP but it may also have impacts on OIDC4VP.