Security and recovery
Passkeys authenticate service access. WebAuthn PRF derives the key that opens an encrypted vault in your browser. The service cannot decrypt your EOA keys. It can observe credential associations, ciphertext sizes and request timing.
Recover a wallet
Save each wallet's private key before using it. On another device, use an available passkey with working PRF support. If that is unavailable, import the saved private key into a new vault or an external wallet. This restores the same EOA address and its assets. It does not recover the old vault's labels or other unsaved keys.
There is no email recovery, administrator reset, recovery-code login or automatic cross-provider passkey transfer in this release. Losing all usable passkeys and all saved EOA keys loses access. A newly created wallet needs its own saved private key.
Limits
- Malicious code running in an unlocked client page can access or use its signing keys. CSP reduces injection opportunities but does not stop privileged extensions, DevTools or every browser's bookmarklets.
- A compromised allowed script or client deployment can steal future unlock material. The API origin alone is not an isolated signing application.
- JavaScript cannot promise complete memory erasure. Locking releases keys and signers and aborts pending work.
- Local revision checks detect stale snapshots previously observed on that device. A new device cannot independently detect a malicious server rollback.
- Removing service access cannot revoke an EOA key someone has already copied. Move assets to a new EOA if its private key is exposed.
- Passkey removal, offline encrypted archives and recovery of an existing server account after all passkeys are lost are not available in this increment.
Storage and operations
Each registered tenant has separate transactional storage. Anonymous account lookup is unavailable. Authentication challenges expire after two minutes and are consumed once. Sessions last ten minutes. APIs use no-store responses and do not use shared caches. Expired provisional enrollment records are removed after one day; operation receipts remain for seven days. Routine logs must exclude request bodies, authentication material and wallet identifiers.
Report a problem
Contact the Thetanuts team through its established support channel with a short description and the affected site/version. Do not send private keys, passkey output, recovery material or authorization headers. There is no public upload endpoint for secrets.