If your laptop dies tonight, your money is still there tomorrow.
Your funds are held by the networks, not by us, and your recovery phrase is the only thing that reaches them. Below: what happens in the situations people actually worry about, and what we do before every release.
What we defend against.
- Compromised endpointsHardware wallet signing isolates your keys from a malware-infected machine.
- Phishing & malicious dAppsTransaction simulation shows exactly what will happen before you sign.
- Supply-chain attacksReproducible builds + signed releases prevent tampered binaries.
- Server-side breachesThere is no server holding your keys. There's nothing for an attacker to steal from us.
- Coercion & rubber-hosePlausible-deniability accounts: a second passphrase reveals a decoy wallet.
Where your keys are, at every moment.
Six moments cover the full life of your wallet. In none of them does your recovery phrase leave your control.
At rest
Your recovery phrase is encrypted on your own machine with a password only you know.
When you sign
A Ledger or Trezor signs on the device itself. The phrase never reaches the computer.
When you send
The wallet shows what a transaction can move before you approve it, in plain language.
On our side
Nothing. We hold no keys, no balances and no account of yours that could be breached.
When you recover
Your recovery phrase rebuilds the wallet on a new computer. We are never part of that process.
When you connect
Websites receive only the permission you approve. They never receive your recovery phrase.
External eyes on every line.
We pay outside security teams to attack the wallet. A summary of every review is published with the release that fixes it.
Colebrook Labs
Two flaws that could produce a wrong address in a shared-account setup. Both were fixed and re-checked before the release went out.
Nine Rivers Security
A timing flaw that could leave one side of a swap unfinished when networks were busy. The exchange logic was rebuilt so a swap either completes or returns your funds.
Independent review
A way to disguise what a signature request was really asking for. The approval screen now states what can move before you confirm.
Independent review
Setting names were readable even though their values were not. Names and values are now encrypted together.
Every release passes four gates.
No single person can push an update to your wallet. Two named maintainers sign every release.
Review
Two maintainers approve
Stress test
Unexpected inputs tried
Isolate
Each chain stays separate
Release
Signed build published
The bad day, handled.
Choose a situation to see what the wallet protects and what you do next.
Restore on a new computer with your recovery phrase.
Reinstall and recover. The password never controls the funds.
The wallet clearly flags what can move your money.
Your keys and balances do not depend on our website.
Found something? Tell us first.
Critical vulnerabilities pay up to $250,000. Every legitimate report gets a response within 24 hours.