Transparent, non-custodial, yours

What public Wi-Fi actually threatens

HTTPS protects the connection. The genuine risks on a shared network are DNS manipulation, captive portals, shoulder surfing and device compromise.

Handled by HTTPS Content interception on the local network
Not handled DNS manipulation and hostile captive portals
Most likely risk Someone reading your screen or taking an unlocked device

FBT Swap

What you should know

The common advice — never use crypto on public Wi-Fi because someone can read your traffic — describes a threat that modern transport encryption largely handles. The real risks are different and less discussed.

They are worth knowing because they change what you should do, which is not simply "avoid cafés".

Encryption already covers interception

HTTPS encrypts content between your device and the site, so another device on the same network sees destinations and timing, not page contents or what you typed. Your private key never travels anywhere in any case.

This is why passive sniffing is not the primary concern it was a decade ago.

DNS and captive-portal manipulation

A hostile network can answer DNS queries with its own addresses, sending you to a clone of a site you typed correctly. Captive portals normalise clicking through certificate warnings, which trains exactly the wrong instinct.

A browser that enforces encrypted DNS, and a refusal to dismiss certificate warnings, both help. A reputable VPN moves the trust from the local network to the VPN provider, which is an improvement when the local network is unknown.

A VPN moves the trust rather than removing it. The network operator can no longer observe or redirect your traffic, and the VPN provider now can. That is usually the better trade on an unknown network, and a worse one if the provider is free and unaccountable.

The physical risks are underrated

Someone can see your screen, your approval prompt and your device passcode. A phone left unlocked on a table is a complete compromise with no technology involved at all.

Shoulder surfing is far more likely in a busy public place than a network attack.

A workable rule

Routine checking of balances on public Wi-Fi is fine. Signing meaningful transactions is better done on a network and in a setting you control, mostly for the physical reasons rather than the network ones.

Never enter a recovery phrase in public under any circumstances, on any network.

At a glance

At a glance

Handled by HTTPS

Content interception on the local network

Not handled

DNS manipulation and hostile captive portals

Most likely risk

Someone reading your screen or taking an unlocked device

Absolute rule

Never enter a recovery phrase in a public place

FAQ

Frequently asked questions

Clear answers before you decide.

Do I need a VPN for crypto?

It helps on untrusted networks by moving trust from the local operator to the VPN provider. It is not a substitute for verifying domains and reading approval prompts, which is where losses actually occur.

Can someone steal my key over Wi-Fi?

Not from the network. The key never leaves your wallet during normal use. Theft requires malware on the device or persuading you to reveal or approve something.

Is mobile data safer than public Wi-Fi?

Generally yes, because you are not sharing a network with unknown parties and DNS comes from your carrier. The physical risks of being in a public place are unchanged.

Risk notice

Crypto assets are volatile and on-chain transactions cannot be reversed. You can lose money, including all of it. Nothing here is financial advice.