Security model
Your keys are made and used on your device, the wallet shows you what it signs, and nobody at OpenWallet can move your funds or skip a safety step for anyone.
OpenWallet has not yet had an independent security audit.
What stays on your device
- Your keys and your 24 words. They are made from your computer's secure random number source and stored only in a wallet file encrypted with your password (Argon2id with 64 MiB of memory, then XChaCha20-Poly1305).
- Cold lock. The unlocked key lives only in the memory of the extension's key code, never in browser storage. When the wallet locks or the browser stops the extension, the key is gone.
- Separate key code. A small Rust program, compiled to WebAssembly, holds the keys and decides what to sign. The rest of the extension cannot ask it to sign raw bytes.
What the wallet will and will not sign
- Payments, and adding or removing a token. Every other transaction type is refused with a reason.
- It decodes the bytes it is about to sign and shows you that. It refuses partial payments, which can deliver less than they seem to.
- It checks the network before signing, so a test transaction cannot be signed on the main network or the other way round.
- Every signed transaction expires within about a minute if it is not validated.
- No website can ask it to sign. It has no access to the pages you visit. The only site that can reach it is wallet.opensync.network, to hand back a Google sign-in, and nothing else.
What OpenWallet ID holds
| Part | Where it is | Alone, it can |
|---|---|---|
| 1 | This browser, inside your encrypted wallet | Nothing without a second part |
| 2 | OpenWallet ID's server, encrypted | Nothing. It is useless on its own |
| 3 | Your Recovery Kit, locked by a recovery code only you have | Nothing without a second part |
OpenWallet ID also holds your email address and your authenticator secret (encrypted). It never holds your 24 words, your password, your recovery code or a key that can sign. Someone who took over the server would get part 2 of every wallet, which cannot rebuild any of them. A recovery releases part 2 only after your sign-in and a 72-hour wait that your email and your devices are told about.
AI agents
- An AI app pays only from a separate agent wallet, never from your main one, within limits it cannot raise.
- OpenWallet's MCP server holds no keys. Every payment it relays is checked again and signed in your extension, on your device, after you approve it.
- The extension fetches the merchant's price itself and refuses if it differs from what the server passed on. See Agents.
Phishing
OpenWallet never asks for codes on a website. Type email and authenticator codes only inside the extension.
- OpenWallet never asks for your 24 words, your password, your recovery code or your Recovery Kit anywhere but inside the extension.
- You can set a personal phrase in Settings. It shows on your unlock and sign-in screens, so a fake OpenWallet window cannot copy it. If it is missing or wrong, stop.
- This site never asks for your wallet password, recovery code or recovery kit.
What OpenWallet staff cannot do
- There is no admin, support or operator function that releases a part of your wallet, changes your sign-in, links a device to your account, or shortens the 72-hour wait.
- No one at OpenWallet can recover a wallet for you or move your funds. Anyone claiming to be support and offering to is a scammer.
- In an emergency an operator can pause all recoveries, which only delays them.
What this does not protect against
- Someone who has your 24 words has your wallet.
- Malware on your computer while the wallet is unlocked can see what you see.
- A payment you approve to the wrong address cannot be undone. Read the review screen.
- Token issuers, including Ripple for RLUSD, may be able to freeze or claw back what they issued.
Report a security issue
Email security@opensync.network. See also security.txt.