What to Look for in a Wallet Security Model
Seven questions that separate a wallet worth trusting from one that looks the same. None require reading code.
Wallet marketing is mostly indistinguishable between products. These seven questions are not, and the answers are findable.
1. Where are the keys generated, and where do they live?
On the device, never leaving it, is the answer you want. Any arrangement where keys are generated on a server, or backed up to one, is custodial regardless of what it is called.
Watch for wallets offering cloud backup of the recovery phrase. That is a convenience feature that moves the secret to an internet-connected system protected by a password.
2. Does it show what I am signing?
Transfer, approval, or contract call, with the amount and the counterparty. Wallets that present an unlimited token approval identically to a simple transfer are failing at the moment that matters most.
Transaction simulation, showing expected balance changes before signing, is the strongest version of this and is the single most valuable feature available.
3. Is recovery standard?
A standard seed phrase means the wallet can be restored in any compatible software. A proprietary scheme ties you to one company’s continued existence.
Standard recovery is strongly preferable and is a question with a yes or no answer.
4. Can I use my own node?
Determines whether balance queries reveal your addresses to a third-party provider. Most wallets default to a provider endpoint, which sees every address you hold.
Support for a custom endpoint is a privacy feature that costs nothing and is absent from many products.
5. What happens if the company disappears?
If the wallet is open source and uses standard derivation, the answer is that you restore elsewhere and nothing is lost.
If either of those is false, the answer may be that your funds depend on a company continuing to operate.
6. Has it been audited, and by whom?
Audits vary enormously in rigour and scope. An audit of an old version, or of a component rather than the whole product, is a partial answer presented as a complete one.
Check the date, the scope and the firm. Published reports are the norm for serious products.
7. Does it pair with a hardware wallet?
Even if you do not use one today. It is the upgrade path when the balance grows, and a wallet that cannot do it is one you will eventually replace.
The questions that do not matter
Interface design. Number of chains, beyond the ones you use. Built-in swap features, which route through aggregators at worse prices. Marketing language about encryption, which is universal.
What to do with the answers
Most people should use a hardware wallet for long-term holdings, a browser or mobile wallet with a small balance for applications, and a venue for buying.
Evaluate the software wallet on questions two, four and seven. Evaluate the hardware wallet on screen quality and standard recovery. Evaluate the venue on withdrawal reliability, published fees and whether two-factor authentication supports more than SMS, which platforms state in their security documentation.
Three evaluations, each answerable in about ten minutes, covering the whole arrangement.
Products covered here are bought at full retail price and used for real transactions before anything is written. There are no affiliate links on this site, no sponsored placements and no review units. If that ever changes, it will be disclosed at the top of the article.