Security & Audits
Joey is self-custody: your keys are created and kept on your device, and we never see them. Here's how we protect them, and who has checked our work.
Independent audits
Joey Wallet mobile app
Audited by Least Authority
An independent security review of the Joey Wallet app for iOS and Android.
Read the auditJoey Wallet browser extension
Audited by Least Authority · 2026
A security audit of the browser extension, covering key generation and encryption, locking, dApp connections and transaction approval. All reported issues were resolved before release.
How your keys are protected
On mobile
- Keys are generated on your phone and kept encrypted in the iOS Keychain or Android Keystore, never on our servers.
- Lock the app with your device passcode, Face ID or Touch ID.
- We cannot recover your keys for you, so keep your recovery phrase backed up.
In the browser extension
- Keys are encrypted on your computer with your password using scrypt and AES-256-GCM.
- No cloud backup or sync. Your wallet lives only in that browser profile.
- Auto-lock on a timer (15 minutes by default), on screen lock and on browser restart.
- Password required to sign transactions by default.
- Sites see nothing until you approve a connection; revoke any time under Connected Sites.
- No analytics, telemetry or crash reporting.
Stay safe
Only download Joey from
Fake wallet apps and extensions are common. Use the links on joeywallet.xyz rather than search ads or links sent to you.
Joey will never
- Ask for your recovery phrase, private key, PIN or password.
- Contact you first by DM to offer support.
- Ask you to "validate" or "sync" your wallet on a website.
Report a vulnerability
Found a security issue in the Joey mobile app, browser extension or website? Email us with the details and steps to reproduce. Please give us a reasonable time to fix it before sharing it publicly.
joey@joeywallet.xyz