نسخهٔ فارسی

Transparent, non-custodial, yours

Making a phone wallet genuinely safe to use

Phones have secure enclaves and biometrics, and are also lost, shoulder-surfed and installed with fake apps. What to configure before funding one.

Advantage Secure enclave storage and enforced app sandboxing
Main risks Fake apps, device theft while unlocked, shoulder surfing
Configure Strong passcode, biometric app lock, short auto-lock, no lock-screen previews

FBT Swap

What you should know

A modern phone is better hardware for key storage than a laptop. Secure enclaves, enforced app sandboxing and biometric gates are real advantages over a browser extension.

The weaknesses are behavioural and physical: phones are lost, screens are visible to the person behind you, and app stores carry convincing fakes.

Installing the right app

Fake wallet apps are a persistent problem in both major stores, often ranking for the real wallet's name. Reach the store through the link on the project's official site, then verify the developer name and the install count.

An app that asks for your recovery phrase before letting you create a new wallet is malicious. There is no legitimate reason for that order.

Device settings that matter

A strong device passcode, not a four-digit PIN. Biometric unlock for the wallet app itself. Automatic screen lock on a short timer. Disabled lock-screen notification previews, so a recovery code or transaction alert is not readable to anyone holding the phone.

Keep the operating system current. Most practical mobile compromises use vulnerabilities that were patched months earlier.

Physical and shoulder risk

The realistic threat for a phone wallet is someone taking the unlocked device, or watching you enter a PIN before doing so. Both are solved by the lock timer and by never entering a recovery phrase in a public place.

If a phone is lost, the key is protected by the device lock, and your recovery phrase lets you restore elsewhere immediately. Having that phrase stored somewhere other than the phone is the entire plan.

Connecting to applications

Mobile wallets connect to sites via WalletConnect or an in-app browser. Both surface approval prompts in the wallet, and those prompts are the authoritative view of what you are signing — not the page behind them.

FBT Swap runs as a web app, an installable progressive web app and an Android build. In all three, the signature happens in your own wallet, and the recovery phrase of an external wallet never reaches us.

At a glance

At a glance

Advantage

Secure enclave storage and enforced app sandboxing

Main risks

Fake apps, device theft while unlocked, shoulder surfing

Configure

Strong passcode, biometric app lock, short auto-lock, no lock-screen previews

Non-negotiable

The recovery phrase stored off the phone

FAQ

Frequently asked questions

Clear answers before you decide.

Is a phone safer than a laptop for crypto?

For key storage, generally yes — enclave-backed storage and sandboxing are stronger than a desktop browser. For transaction review, a larger screen is easier to read carefully, which matters more than people expect.

Should I use biometrics or a PIN?

Biometrics for convenience with a strong passcode behind them. The passcode is the real credential; a weak one undermines the biometric entirely, since the device can always fall back to it.

What if my phone is stolen with the wallet installed?

Provided the device is locked and the app requires authentication, the key is protected. Restore from your recovery phrase onto a new device, and move funds to a fresh wallet if you have any doubt about the old one.

Risk notice

Crypto assets are volatile and on-chain transactions cannot be reversed. You can lose money, including all of it. Nothing here is financial advice.