How M5wallet protects your keys
On your device
Section titled “On your device”Recovery phrases and private keys are kept in M5wallet’s local database, encrypted with AES-256-GCM. The encryption key is derived from your passcode with PBKDF2-SHA256 and 600,000 iterations, so the stored data can’t be read without your passcode.
Transactions are signed on your device. When you send, M5wallet’s servers receive the transaction already signed and pass it to the network unchanged.
What leaves your device
Section titled “What leaves your device”It depends on the kind of wallet.
| Wallet type | Stored away from your device |
|---|---|
| Seed phrase or private key | No secrets. Your addresses are sent to M5wallet’s servers to look up balances and history. |
| Google sign-in | Your recovery phrase, encrypted, and the two halves of the secret that decrypts it: one released after you sign in with Google, the other only with your PIN. |
| M5 Vault | For a Fast Vault, the M5 signing server holds the second key share. A Secure Vault keeps both shares on your own phones. |
| Hardware wallet | No secrets. Keys stay on the device. |
Protections you control
Section titled “Protections you control”- Passcode and biometrics: required to unlock M5wallet on each device.
- Auto-lock: starts at Never. Choose a timer so an unattended device locks itself.
- Passcode protection: resets the app after 10 failed passcode attempts.
Set these up in Security settings.