Skip to main content
0xio provides multiple layers of security to protect your funds and privacy. The protections below apply across the browser extension, desktop app, and mobile app, with a few platform-specific additions noted where relevant.

Biometric Unlock

All three clients support biometric unlock with a password or PIN fallback:
  • Extension: WebAuthn passkey: unlock with your device biometrics (enable it under Security & Backup). Passkey unlock is currently Chrome-only and not available on Firefox.
  • Desktop: Touch ID / Windows Hello. On desktop, biometrics are the primary prompt for sensitive actions, with your password as the fallback
  • Mobile: Face ID / Touch ID / fingerprint for transaction approval and unlock, with PIN fallback
Biometrics gate access to the locally encrypted vault. They never replace your recovery phrase, which remains the only way to restore the wallet on a new device.

Auto-Lock

Automatically lock your wallet after periods of inactivity.

Configuration

  1. Navigate to Settings > Security > Auto-Lock
  2. Select timeout period:
    • 5 minutes
    • 15 minutes (recommended)
    • 30 minutes
    • 1 hour
    • Never (not recommended)

How It Works

  • Timer resets with any wallet interaction
  • Locked wallet requires password to reopen
  • Protects against unauthorized access if you step away
  • Active sessions close automatically
Security Recommendation: Use 15 minutes or less for shared or public computers.

Password Management

Changing Your Password

1

Open Security Settings

Go to Settings > Security > Change Password
2

Enter Current Password

Verify your identity with existing password
3

Enter New Password

Create a strong new password (12+ characters)
4

Confirm New Password

Re-enter to confirm
5

Apply Changes

Password updated immediately
Important: Changing your password does NOT require your Recovery Phrase. The password only protects local access to your encrypted vault: it derives a key with PBKDF2 (900,000 iterations on the extension, 600,000 on desktop; mobile gates the vault behind a PIN at 100,000 iterations) that decrypts an AES-256-GCM vault.

Password Requirements

  • Minimum: 8 characters (12+ recommended)
  • Recommended:
    • Mix of uppercase and lowercase
    • Include numbers
    • Include special characters (!@#$%^&*)
    • Avoid common words or patterns

Recovery Phrase Management

Viewing Your Recovery Phrase

Extreme Caution: Only view your recovery phrase in a secure, private location. Never screenshot or photograph it.
  1. Settings > Security > Show Recovery Phrase
  2. Enter your password
  3. Write down all 12 words in order
  4. Hide/close the view immediately

Multiple Devices

Use your Recovery Phrase to access the same wallet on multiple devices:
  • Each device can have its own password
  • Balance changes sync via blockchain automatically
  • Transactions from any device reflect on all devices
  • No cloud synchronization required

Device Security

Recommended:
  • Different passwords per device
  • Enable auto-lock on all devices
  • Never store recovery phrase digitally
  • Regular security audits

Advanced Security Options

Export Private Key

Advanced Users Only: Exporting your private key is rarely necessary and increases security risk.
Use Cases:
  • Importing to other Octra-compatible wallets
  • Advanced development and testing
  • Cold storage solutions
How to Export:
  1. Settings > Advanced > Export Private Key
  2. Enter password
  3. Copy private key (never screenshot)
  4. Store securely (treat like recovery phrase)

Transaction Signing

All transactions require explicit approval:
  • Review: Every transaction shows full details (including contract method and parameters for contract calls)
  • Confirm: Password or biometric required (on mobile, sends to an address you have whitelisted skip this check; see Whitelisted Addresses)
  • Signing wallet shown: Every approval, message signatures included, names the wallet and network it signs with
  • No Auto-Sign: Even for connected dApps
  • Cancel Anytime: Before signing completes

Connection Management

Connected dApps

View and manage website connections:
  1. Settings > Connected Sites
  2. See all authorized dApps
  3. View permissions granted
  4. Revoke access anytime

Permission Types

Best Practice: Regularly audit connected dApps and revoke unused connections.

Session Security

Connected dApp Sessions

Each connected dApp holds a session scoped to the permissions you granted. Review and revoke them under Connected Sites (see Connection Management). Revoking a connection immediately ends that dApp’s session.

Secure Logout

Always lock the wallet on shared devices:
  1. Click the lock icon in the header (extension/desktop)
  2. Or use Settings > Lock Wallet
  3. Unlock requires your password, PIN, or biometrics

Watch-Only and Balance Privacy

  • Watch-only mode: Import an address without its private key to monitor balances and history. Watch-only wallets cannot send, sign, or run privacy operations.
  • Hide balances: Toggle the eye control to mask balance amounts on screen, useful in public or shared settings.

Mobile-Specific Protections

The mobile app adds device-level safeguards:
  • Screenshot and screen-recording prevention on sensitive screens
  • Secure clipboard handling for copied addresses and keys
  • Jailbreak / root detection with an on-screen warning when a compromised device is detected
  • PIN lock with auto-lock and rate limiting, backed by the device keychain/keystore
  • Honest browser lock: the in-app browser shows a lock only on https pages, marks plain http as not secure, and shows none for oct:// content

Network Security

RPC Endpoint Validation

0xio validates RPC endpoints before connecting:
  • Certificate Validation: HTTPS only
  • Known Networks: Pre-configured safe RPCs
  • Custom Networks: A node must answer as an Octra node before it is added, with a warning that it sees your address and the transactions you sign there

Phishing Protection

Built-in protections against common attacks:
  • Address Validation: Checks address format
  • Warning Banners: Alerts for suspicious transactions
  • Domain Verification: Highlights mismatched domains
  • Transaction Preview: Always shows full details
  • Wallet pictures: Each wallet’s picture is drawn from its address, the same in the mobile app and the extension, so a wrong wallet looks wrong before you check the address
  • Isolated content (desktop): Living NFTs, oct:// pages and the Circles preview run in isolated frames with a security policy of their own; NFT programs have no network access and cannot reach the wallet

Security Best Practices

DO:

  • Enable auto-lock (15 minutes or less)
  • Use a strong, unique password
  • Store recovery phrase offline securely
  • Regularly review connected dApps
  • Verify addresses before sending
  • Start with small test transactions
  • Keep browser and extension updated

DON’T:

  • Share password or recovery phrase with anyone
  • Store recovery phrase digitally
  • Screenshot or photograph sensitive information
  • Use the same password across services
  • Leave wallet unlocked on shared devices
  • Approve transactions without review
  • Connect to untrusted dApps

Emergency Procedures

Compromised Device

If you suspect your device is compromised:
1

Secure Access on New Device

Install 0xio on a secure device using your recovery phrase
2

Transfer Funds

Immediately transfer all funds to a new wallet
3

Create New Wallet

Generate a new wallet with a fresh recovery phrase
4

Abandon Old Wallet

Never use the compromised wallet again

Lost Recovery Phrase

Critical: If you lose your recovery phrase and lose access to all devices with the wallet:Your funds are PERMANENTLY INACCESSIBLE.0xio cannot recover lost recovery phrases. They are generated locally and never transmitted.
Prevention:
  • Maintain multiple secure backups
  • Consider metal backup solutions
  • Store in separate physical locations
  • Test recovery on a second device

Security Audit

Regular Security Checks

Perform monthly security audits:
  • Recovery phrase backed up securely
  • Password is strong and unique
  • Auto-lock enabled
  • Connected dApps reviewed
  • No suspicious transaction history
  • Extension is latest version
  • Device security software updated

Reporting Security Issues

Found a vulnerability? Report to: [email protected]
  • Do not publicly disclose until patched
  • Include detailed reproduction steps