Client security
How the client protects your keys, and how to check that you run the real one.
No server
The client is a static site. There is no backend, no account and no analytics. It talks only to your wallet, to the RPC endpoint you choose, and to Blockscout's public API for announcements (you can switch that off in Settings).
Keys stay in the tab
Your keys are derived from one signature and kept in the tab's memory only. They are never written to disk, browser storage or any server. They are forgotten when you close the tab, switch accounts or press Forget my keys now. Each payment's key is computed when you withdraw it and used once to sign, in the tab.
Hardening
The site is served with a strict content security policy (scripts only from its own origin), refuses to be framed by other sites, and sends no referrer.
Phishing
The one thing an attacker wants is your signature of the key message. Sign it only on the official client or a copy you run yourself. The message says so in its own text.
Check what you run
The client source is published with the rest of the project. Build it yourself and compare, or run your own copy. Report anything wrong to security@ephemeral.money; see Bug bounty.