Biometric Unlock
All three clients support biometric unlock with a password or PIN fallback:- Extension: WebAuthn passkey: unlock with your device biometrics (enable it under Security & Backup). Passkey unlock is currently Chrome-only and not available on Firefox.
- Desktop: Touch ID / Windows Hello. On desktop, biometrics are the primary prompt for sensitive actions, with your password as the fallback
- Mobile: Face ID / Touch ID / fingerprint for transaction approval and unlock, with PIN fallback
Biometrics gate access to the locally encrypted vault. They never replace your recovery phrase, which remains the only way to restore the wallet on a new device.
Auto-Lock
Automatically lock your wallet after periods of inactivity.Configuration
- Navigate to Settings > Security > Auto-Lock
- Select timeout period:
- 5 minutes
- 15 minutes (recommended)
- 30 minutes
- 1 hour
- Never (not recommended)
How It Works
- Timer resets with any wallet interaction
- Locked wallet requires password to reopen
- Protects against unauthorized access if you step away
- Active sessions close automatically
Password Management
Changing Your Password
1
Open Security Settings
Go to Settings > Security > Change Password
2
Enter Current Password
Verify your identity with existing password
3
Enter New Password
Create a strong new password (12+ characters)
4
Confirm New Password
Re-enter to confirm
5
Apply Changes
Password updated immediately
Important: Changing your password does NOT require your Recovery Phrase. The password only protects local access to your encrypted vault: it derives a key with PBKDF2 (900,000 iterations on the extension, 600,000 on desktop; mobile gates the vault behind a PIN at 100,000 iterations) that decrypts an AES-256-GCM vault.
Password Requirements
- Minimum: 8 characters (12+ recommended)
- Recommended:
- Mix of uppercase and lowercase
- Include numbers
- Include special characters (!@#$%^&*)
- Avoid common words or patterns
Recovery Phrase Management
Viewing Your Recovery Phrase
- Settings > Security > Show Recovery Phrase
- Enter your password
- Write down all 12 words in order
- Hide/close the view immediately
Multiple Devices
Use your Recovery Phrase to access the same wallet on multiple devices:- Each device can have its own password
- Balance changes sync via blockchain automatically
- Transactions from any device reflect on all devices
- No cloud synchronization required
Device Security
Recommended:- Different passwords per device
- Enable auto-lock on all devices
- Never store recovery phrase digitally
- Regular security audits
Advanced Security Options
Export Private Key
Use Cases:- Importing to other Octra-compatible wallets
- Advanced development and testing
- Cold storage solutions
- Settings > Advanced > Export Private Key
- Enter password
- Copy private key (never screenshot)
- Store securely (treat like recovery phrase)
Transaction Signing
All transactions require explicit approval:- Review: Every transaction shows full details (including contract method and parameters for contract calls)
- Confirm: Password or biometric required (on mobile, sends to an address you have whitelisted skip this check; see Whitelisted Addresses)
- Signing wallet shown: Every approval, message signatures included, names the wallet and network it signs with
- No Auto-Sign: Even for connected dApps
- Cancel Anytime: Before signing completes
Connection Management
Connected dApps
View and manage website connections:- Settings > Connected Sites
- See all authorized dApps
- View permissions granted
- Revoke access anytime
Permission Types
Session Security
Connected dApp Sessions
Each connected dApp holds a session scoped to the permissions you granted. Review and revoke them under Connected Sites (see Connection Management). Revoking a connection immediately ends that dApp’s session.Secure Logout
Always lock the wallet on shared devices:- Click the lock icon in the header (extension/desktop)
- Or use Settings > Lock Wallet
- Unlock requires your password, PIN, or biometrics
Watch-Only and Balance Privacy
- Watch-only mode: Import an address without its private key to monitor balances and history. Watch-only wallets cannot send, sign, or run privacy operations.
- Hide balances: Toggle the eye control to mask balance amounts on screen, useful in public or shared settings.
Mobile-Specific Protections
The mobile app adds device-level safeguards:- Screenshot and screen-recording prevention on sensitive screens
- Secure clipboard handling for copied addresses and keys
- Jailbreak / root detection with an on-screen warning when a compromised device is detected
- PIN lock with auto-lock and rate limiting, backed by the device keychain/keystore
- Honest browser lock: the in-app browser shows a lock only on https pages, marks plain http as not secure, and shows none for
oct://content
Network Security
RPC Endpoint Validation
0xio validates RPC endpoints before connecting:- Certificate Validation: HTTPS only
- Known Networks: Pre-configured safe RPCs
- Custom Networks: A node must answer as an Octra node before it is added, with a warning that it sees your address and the transactions you sign there
Phishing Protection
Built-in protections against common attacks:- Address Validation: Checks address format
- Warning Banners: Alerts for suspicious transactions
- Domain Verification: Highlights mismatched domains
- Transaction Preview: Always shows full details
- Wallet pictures: Each wallet’s picture is drawn from its address, the same in the mobile app and the extension, so a wrong wallet looks wrong before you check the address
- Isolated content (desktop): Living NFTs,
oct://pages and the Circles preview run in isolated frames with a security policy of their own; NFT programs have no network access and cannot reach the wallet
Security Best Practices
DO:
- Enable auto-lock (15 minutes or less)
- Use a strong, unique password
- Store recovery phrase offline securely
- Regularly review connected dApps
- Verify addresses before sending
- Start with small test transactions
- Keep browser and extension updated
DON’T:
- Share password or recovery phrase with anyone
- Store recovery phrase digitally
- Screenshot or photograph sensitive information
- Use the same password across services
- Leave wallet unlocked on shared devices
- Approve transactions without review
- Connect to untrusted dApps
Emergency Procedures
Compromised Device
If you suspect your device is compromised:1
Secure Access on New Device
Install 0xio on a secure device using your recovery phrase
2
Transfer Funds
Immediately transfer all funds to a new wallet
3
Create New Wallet
Generate a new wallet with a fresh recovery phrase
4
Abandon Old Wallet
Never use the compromised wallet again
Lost Recovery Phrase
Prevention:- Maintain multiple secure backups
- Consider metal backup solutions
- Store in separate physical locations
- Test recovery on a second device
Security Audit
Regular Security Checks
Perform monthly security audits:- Recovery phrase backed up securely
- Password is strong and unique
- Auto-lock enabled
- Connected dApps reviewed
- No suspicious transaction history
- Extension is latest version
- Device security software updated
Reporting Security Issues
Found a vulnerability? Report to: [email protected]- Do not publicly disclose until patched
- Include detailed reproduction steps