Security & Audits

Joey is self-custody: your keys are created and kept on your device, and we never see them. Here's how we protect them, and who has checked our work.

Independent audits

Joey Wallet mobile app

Audited by Least Authority

An independent security review of the Joey Wallet app for iOS and Android.

Read the audit

Joey Wallet browser extension

Audited by Least Authority · 2026

A security audit of the browser extension, covering key generation and encryption, locking, dApp connections and transaction approval. All reported issues were resolved before release.

How your keys are protected

On mobile

  • Keys are generated on your phone and kept encrypted in the iOS Keychain or Android Keystore, never on our servers.
  • Lock the app with your device passcode, Face ID or Touch ID.
  • We cannot recover your keys for you, so keep your recovery phrase backed up.

In the browser extension

  • Keys are encrypted on your computer with your password using scrypt and AES-256-GCM.
  • No cloud backup or sync. Your wallet lives only in that browser profile.
  • Auto-lock on a timer (15 minutes by default), on screen lock and on browser restart.
  • Password required to sign transactions by default.
  • Sites see nothing until you approve a connection; revoke any time under Connected Sites.
  • No analytics, telemetry or crash reporting.

Learn more about the extension

Stay safe

Only download Joey from

Fake wallet apps and extensions are common. Use the links on joeywallet.xyz rather than search ads or links sent to you.

Joey will never

  • Ask for your recovery phrase, private key, PIN or password.
  • Contact you first by DM to offer support.
  • Ask you to "validate" or "sync" your wallet on a website.

Report a vulnerability

Found a security issue in the Joey mobile app, browser extension or website? Email us with the details and steps to reproduce. Please give us a reasonable time to fix it before sharing it publicly.

joey@joeywallet.xyz