Langsung ke konten

Halaman ini hanya tersedia dalam bahasa Inggris.

Security

How FxWallet handles your keys and data, and how to recognise the official FxWallet apps and channels.

Self-custody

FxWallet is a self-custody wallet. Your mnemonic phrase and private keys are created on your phone, stored there encrypted, and never sent to FxWallet’s servers. FxWallet cannot move your assets, and it cannot restore your wallet for you.

  • Back up the mnemonic phrase offline, on paper: it is the only way to restore your wallet on a new phone. The app reminds you until you have checked your backup.
  • Showing the mnemonic phrase or a private key asks for your password or biometrics every time, and hides it again after two minutes.
  • Signing asks for your password or biometrics, and you can require biometrics to open the app.

Checks before you sign

Most losses start with a signature obtained through deception. Before you confirm, FxWallet performs the following checks where possible:

  • For every transfer, the recipient is checked against known scam and sanctioned addresses. On EVM networks, FxWallet also flags an address that looks like one you have sent to before, the technique used in address poisoning.
  • Token, NFT and Send pages show a GoPlus security check on the networks GoPlus covers.
  • Token approvals and permits show the token, the spender and the amount, and you can set a custom allowance instead of an unlimited one.
  • Swap simulates every Solana trade, and EVM trades above a set value, before you sign, and stops one that is predicted to fail or to return far less than quoted.
  • The DApp browser warns you before it opens a site flagged as high risk.
  • Approvals lists what you have approved on EVM networks, flags the risky ones and revokes them one at a time or in a batch.
  • Spam transactions are hidden from your history by default, on networks that support it.

Keep large amounts offline

FxWallet works with Keystone and Goldshell hardware wallets over QR codes, and can use a second phone kept offline as a cold wallet. The keys stay on the device, and FxWallet checks every signature it returns before broadcasting it.

What FxWallet’s servers see

To show your balances, history and prices, the app sends your wallet’s public addresses to FxWallet’s servers (for Bitcoin-family chains, the account’s extended public key), with an identifier for your device. The addresses are public on the blockchain in any case. The servers never receive your mnemonic phrase or private keys.

  • Push notifications are sent through OneSignal, which receives an ID for your device.
  • Product analytics are sent to Mixpanel under an anonymous ID: the features you use and amount ranges in US dollars, not exact amounts or your wallet addresses.
  • A DApp you connect to, directly or through WalletConnect, sees the address you connect with.
  • The Privacy Policy sets out how FxWallet handles personal data.

Recognise the official FxWallet

  • Install FxWallet from the App Store (developer DXP COMPUTING POWER FOUNDATION PTE. LTD.), Google Play (developer ECHOINFI PTE. LTD.) or this site.
  • Before you install the APK, check its SHA-256 against the one on the download page.
  • FxWallet support never messages you first, and never asks for your mnemonic phrase or private key.
  • FxWallet’s official accounts are listed on the About page.

If your wallet is compromised

If you typed your mnemonic phrase into a site or an app, or signed something you do not recognise, act at once: move your assets to a new wallet with a new mnemonic phrase, and revoke any approval you did not mean to give. What to do if your wallet is compromised describes each step.

Di pusat bantuan

Dapatkan FxWallet

Gratis di iPhone dan Android.