Skip to content

How M5wallet protects your keys

Recovery phrases and private keys are kept in M5wallet’s local database, encrypted with AES-256-GCM. The encryption key is derived from your passcode with PBKDF2-SHA256 and 600,000 iterations, so the stored data can’t be read without your passcode.

Transactions are signed on your device. When you send, M5wallet’s servers receive the transaction already signed and pass it to the network unchanged.

It depends on the kind of wallet.

Wallet type Stored away from your device
Seed phrase or private key No secrets. Your addresses are sent to M5wallet’s servers to look up balances and history.
Google sign-in Your recovery phrase, encrypted, and the two halves of the secret that decrypts it: one released after you sign in with Google, the other only with your PIN.
M5 Vault For a Fast Vault, the M5 signing server holds the second key share. A Secure Vault keeps both shares on your own phones.
Hardware wallet No secrets. Keys stay on the device.
  • Passcode and biometrics: required to unlock M5wallet on each device.
  • Auto-lock: starts at Never. Choose a timer so an unattended device locks itself.
  • Passcode protection: resets the app after 10 failed passcode attempts.

Set these up in Security settings.