Wallet security
What protects a Blomo Wallet
Blomo Wallet is non-custodial, and that word is only worth something if it holds on the worst day. This page answers one question in full: who can move the money in the wallet, and on what conditions.
Open an accountWho can move the money
One person: whoever knows the passcode on the device where the wallet lives, or whoever holds the recovery phrase. Blomo is not on that list.
This is not a promise of good behaviour, it is an absence of ability. We hold the key only in encrypted form, and the passcode that opens it we do not hold at all. There is no internal tool, no admin screen and no support procedure that moves funds out of a Blomo Wallet, because there is nothing for such a tool to use.
The single exception is co-control, and it exists only if the user switches it on. Until then, a connected card cannot spend from the wallet either.
What a breach of Blomo would give an attacker
Assume the worst honestly: our database is copied in full. What the copy contains is encrypted keys — and nothing that opens them.
Opening one takes the passcode, which is not in that database, and a second piece, which is not in it either: that piece is kept by a separate service and released only to a signed-in user, a limited number of times. So the attacker cannot sit at home and try passcodes against the stolen copy. Every attempt has to come back through Blomo, where it is visible and slowed down.
That is the whole point of the design. An offline guessing attack is the one that succeeds quietly, at the attacker's own pace, and it is the one this makes impossible.
The recovery phrase is the only backup
The recovery phrase is shown once, when the wallet is created, and it must be written down then. Blomo never sees it and does not keep a copy.
This cuts both ways, and it is fair to say so plainly: with the phrase, a lost passcode is an inconvenience; without it, a lost passcode is a lost wallet, and we cannot help. A service that could restore your key without the phrase would be a service that could also take your money.
Signing happens where the key is
A transaction is assembled and signed on the device. What travels to Blomo is the finished, signed transaction, which we relay to the network.
The key does not travel. The passcode does not travel. Even a Blomo server fully under someone else's control sees only what a public block explorer will see a moment later anyway.
Co-control, if you want it, and only within your rules
Connecting the wallet to a Blomo card turns on co-control: the key is split into two shares, one with the user and one with Blomo, and signing needs both. It is off by default and is switched on deliberately.
Blomo's share does not sign whatever it likes. It signs inside a spending limit, a list of allowed recipients and a stop switch — all three set by the user in advance, and all three enforced by the signing service rather than by our good intentions.
- Storage model
- Non-custodial
- Where the key is created
- On the user's device
- Key encryption
- The user's passcode, on their own device
- Where signing happens
- On the device — the server receives an already signed transaction
- Guessing the passcode
- Only through Blomo and only a limited number of times
- If Blomo's database leaks
- The stored key is useless without the passcode
- If the passcode is lost
- The recovery phrase, and nothing else — Blomo cannot restore it
- Blomo spending from the wallet
- Impossible unless the user turns on co-control
FAQ
Questions people actually ask
Can Blomo move funds out of a Blomo Wallet?
No. The key is stored only in encrypted form and the passcode that opens it is not stored at all, so there is nothing for an internal tool to use. The only exception is co-control, which the user turns on and which signs only inside the limit, allowed recipients and stop switch the user set.
What happens if Blomo's database is stolen?
The thief gets encrypted keys and nothing that opens them. The passcode is not in the database, and a second piece needed to decrypt is held by a separate service that releases it only to a signed-in user, a limited number of times. Guessing would have to run through Blomo, where it is visible and rate-limited, instead of quietly against the stolen copy.
What if the passcode is lost?
The wallet is restored from the recovery phrase shown when it was created. Without that phrase the key is gone and Blomo cannot restore it — the same property that stops us from taking your money stops us from returning it.
Does Blomo see the private key at any point?
No. It is generated on the device, encrypted on the device, and used on the device. The server receives transactions that are already signed.
Is the Blomo balance protected the same way?
No, and it is a different thing on purpose. The Blomo balance is custodial: crypto sent there goes to Blomo's own wallets and cards spend from it by default. Account and card protections are described on the account security page.
Next
Read on
Hold your own key from day one
Create Blomo Wallet inside the app, write down the recovery phrase, and keep the only copy that matters.