ephemeral

Client security

How the client protects your keys, and how to check that you run the real one.

No server

The client is a static site. There is no backend, no account and no analytics. It talks only to your wallet, to the RPC endpoint you choose, and to Blockscout's public API for announcements (you can switch that off in Settings).

Keys stay in the tab

Your keys are derived from one signature and kept in the tab's memory only. They are never written to disk, browser storage or any server. They are forgotten when you close the tab, switch accounts or press Forget my keys now. Each payment's key is computed when you withdraw it and used once to sign, in the tab.

Hardening

The site is served with a strict content security policy (scripts only from its own origin), refuses to be framed by other sites, and sends no referrer.

Phishing

The one thing an attacker wants is your signature of the key message. Sign it only on the official client or a copy you run yourself. The message says so in its own text.

Check what you run

The client source is published with the rest of the project. Build it yourself and compare, or run your own copy. Report anything wrong to security@ephemeral.money; see Bug bounty.

On this page