SECURITY

If your laptop dies tonight, your money is still there tomorrow.

Your funds are held by the networks, not by us, and your recovery phrase is the only thing that reaches them. Below: what happens in the situations people actually worry about, and what we do before every release.

Glowing shield
OUR THREAT MODEL

What we defend against.

  • Compromised endpoints
    Hardware wallet signing isolates your keys from a malware-infected machine.
  • Phishing & malicious dApps
    Transaction simulation shows exactly what will happen before you sign.
  • Supply-chain attacks
    Reproducible builds + signed releases prevent tampered binaries.
  • Server-side breaches
    There is no server holding your keys. There's nothing for an attacker to steal from us.
  • Coercion & rubber-hose
    Plausible-deniability accounts: a second passphrase reveals a decoy wallet.
YOUR KEYS

Where your keys are, at every moment.

Six moments cover the full life of your wallet. In none of them does your recovery phrase leave your control.

01

At rest

Your recovery phrase is encrypted on your own machine with a password only you know.

02

When you sign

A Ledger or Trezor signs on the device itself. The phrase never reaches the computer.

03

When you send

The wallet shows what a transaction can move before you approve it, in plain language.

04

On our side

Nothing. We hold no keys, no balances and no account of yours that could be breached.

05

When you recover

Your recovery phrase rebuilds the wallet on a new computer. We are never part of that process.

06

When you connect

Websites receive only the permission you approve. They never receive your recovery phrase.

INDEPENDENT REVIEWS

External eyes on every line.

We pay outside security teams to attack the wallet. A summary of every review is published with the release that fixes it.

Mar 2026 · Transactions and recovery phrases

Colebrook Labs

Two flaws that could produce a wrong address in a shared-account setup. Both were fixed and re-checked before the release went out.

Fixed and re-checked
Jan 2026 · Cross-network swaps

Nine Rivers Security

A timing flaw that could leave one side of a swap unfinished when networks were busy. The exchange logic was rebuilt so a swap either completes or returns your funds.

Fixed and re-checked
Nov 2025 · In-app browser and permission prompts

Independent review

A way to disguise what a signature request was really asking for. The approval screen now states what can move before you confirm.

Fixed and re-checked
Aug 2025 · Encrypted settings sync

Independent review

Setting names were readable even though their values were not. Names and values are now encrypted together.

Fixed and re-checked
HOW WE OPERATE

Every release passes four gates.

No single person can push an update to your wallet. Two named maintainers sign every release.

Gate 01

Review

Two maintainers approve

Gate 02

Stress test

Unexpected inputs tried

Gate 03

Isolate

Each chain stays separate

Gate 04

Release

Signed build published

Release control Ready only after 4/4
WHAT IF

The bad day, handled.

Choose a situation to see what the wallet protects and what you do next.

Signal detected
Device missing
Protected
Wallet stays locked

Restore on a new computer with your recovery phrase.

Signal detected
Local access lost
Protected
Funds stay untouched

Reinstall and recover. The password never controls the funds.

Signal detected
Unknown website
Protected
Risk shown before signing

The wallet clearly flags what can move your money.

Signal detected
Website offline
Protected
Desktop wallet remains yours

Your keys and balances do not depend on our website.

RESPONSIBLE DISCLOSURE

Found something? Tell us first.

Critical vulnerabilities pay up to $250,000. Every legitimate report gets a response within 24 hours.

Bug bounty program →