Skip to content

How Morsel protects you

Where your keys live, how they're encrypted, what Morsel's servers can and can't see, and the checks that run before you sign anything.

Morsel is self-custodial. Your keys are made on your device, stay on your device, and every signature happens on your device. There is no Morsel account, no sign-in, and no copy of your keys anywhere else.

Where your keys live

When you create or import a wallet, Morsel encrypts its recovery phrase or private key with your password before saving it.

  • Encryption: XSalsa20-Poly1305, with a key derived from your password by PBKDF2-SHA256 at 600,000 rounds and a random salt.
  • On iPhone and Android: the encrypted wallet is kept in the phone's secure storage, the Keychain or the Keystore. On iPhone, biometric unlock is tied to this device and only works while the phone has a passcode.
  • On the Chrome extension: the encrypted wallet is kept in the extension's own storage. While you're using it, the unlocked session is held in memory for about 5 minutes.

Your password is never stored as written and never leaves your device.

What Morsel's servers see

Morsel runs servers to show you prices, balances, activity, names and notifications quickly. They receive:

  • your public address, to look up balances and history, like any explorer can;
  • for push notifications on your phone, a device token tied to your active wallet's address, registered with a signature that proves you own it;
  • for chats, encrypted messages they can't read. See Chat privacy.

They never receive your recovery phrase, private keys or password. Nobody at Morsel can move your funds, freeze them, or recover your wallet.

Checks before you sign

  • Chain proof confirms which network a transaction really belongs to.
  • Simulation shows what would leave and enter your wallet before you sign.
  • Risk rules block unlimited spending permissions and changes of ownership, and make you confirm other risky requests.
  • Phishing protection blocks known scam sites and flags lookalike domains.
  • Recipient checks in Send warn about lookalike addresses, program addresses and first-time payments.

See Approve and sign safely and Send tokens.

Locking

Morsel locks when you've been away, and your password, Face ID or fingerprint unlocks it. Showing your recovery phrase or private key always asks you again. See Unlock, Face ID and auto-lock.

What only you can do

Self-custody means some protection is in your hands:

  • Back up your recovery phrase on paper, and keep it offline. See Your Secret Recovery Phrase.
  • Use a strong, unique password, and a short Lock after time on shared devices.
  • Read every request before you approve it.
  • Keep your phone and computer secure: a passcode, updates, and no unknown apps or extensions. Morsel can't block screenshots, and it can't protect a device that's already compromised.

Try one of these