45 iOS non-custodial wallets were called out: How did the security promise collapse?

CN
36 minutes ago

For a long time, "non-custodial wallet" equating to "users controlling their own private keys" has almost become an industry consensus, leading many to subconsciously believe that as long as this label is attached, the security baseline is guaranteed. Recently, however, the Chief Technology Officer of BlueWallet shattered this intuition by screening approximately 904 iOS applications classified as non-custodial crypto wallets in the App Store, and conducting a more in-depth technical analysis on 494 of them. According to a single source, among this batch of samples, 45 were explicitly marked as having serious or high-risk security issues, with some applications even potentially uploading users' mnemonic phrases or private keys to server-side processing, directly violating the most critical red line in non-custodial design. More unsettling is the fact that there has yet to be public disclosure regarding which specific applications are involved, nor is there a unified official response or handling plan, making it challenging for users to intuitively distinguish between "safe" and "dangerous" in the short term. This screening result has thus ripped open the narrative gap surrounding the security of non-custodial wallets and pulled the entire iOS wallet ecosystem into a watchful moment that requires a reevaluation of trust boundaries.

Distortion of Non-Custodial Commitment: 45 Wallets Labeled High Risk

For a long time, "non-custodial" has been viewed as a security trademark for crypto wallets: users independently control their private keys, without relying on any third parties, and mnemonic phrases and private keys are not stored or processed on servers. These components form the core premise of product marketing and industry narrative. Consequently, many iOS wallets classify themselves as non-custodial upon release, signaling to users that as long as they safeguard their mnemonic phrase, their on-chain assets will not be affected by issues with the project team or the server.

According to a single source, the sample screened this time is comprised of those wallets that self-labeled as non-custodial on the iOS platform. However, the screening results indicate that the actual behavior of some applications significantly diverges from the non-custodial commitments they made to users—disclosure materials indicate that some applications might upload users' mnemonic phrases or private keys to server-side processing, effectively reintroducing a centralized attack surface in technical design. After completing an analysis of 494 applications, this CTO categorized 23 as having potential serious risks, 22 as high risks, totaling 45 named as having serious or high-risk security issues. This group of numbers is no longer just indicative of "individual projects facing issues," but serves as a clear security warning directly aimed at the entire wallet sector, forcing the industry to readdress a simple yet harsh question: can the golden facade of non-custodial still be regarded as a trustworthy security boundary?

Mnemonic Phrases on Servers: From Self-Held Assets to Exposed Entrances

According to a single source, during the screening, the CTO of BlueWallet identified "uploading mnemonic phrases or private keys to servers" as a main security issue for several applications. Mnemonic phrases and private keys are essentially the core credentials for controlling on-chain assets; a string of words or a segment of code equals complete control over all related addresses. In the narrative of non-custodial wallets, they should only exist on user-controlled terminals, untouchable by any centralized service. Once an application is designed to allow or actively send these sensitive data to be processed by servers, the superficial "non-custodial" is rewritten into another form of custodial. Users believe they hold the key, but in reality, they have handed over a copy of that key to a remote system. Currently, published materials have not provided the specific technical details or audit reports for each of the marked applications, making it impossible for outsiders to accurately judge the scope and details of these upload behaviors, but just this design direction is sufficient to constitute a severe risk exposure.

The escalation of risks originates from changes in the attack surface. Traditionally, the main threats to non-custodial wallets are concentrated on individual terminals: attackers need to deploy trojans, phishing, or physical attacks on a specific phone or computer, with success rates and costs related to individual users. However, when mnemonic phrases or private keys are uploaded to centralized servers, even if just for so-called "cloud backup" or "remote recovery," once the server retains or has the capability to restore user keys, it immediately becomes a high-value attack target. Attackers no longer need to crack user devices one by one; by breaching this node, they may simultaneously compromise the core credentials and on-chain assets of a large number of users. In the absence of transparent audits and detail disclosures, users are unable to even confirm whether these applications permanently store keys on the server, how encryption is conducted, or if access logs are kept. This asymmetrical information structure makes the "non-custodial" label difficult to be considered a reliable security boundary.

Audit Gaps and Grey Areas in the iOS Crypto Wallet Ecosystem

When "non-custodial" can easily appear in product descriptions without having to undergo systematic scrutiny at the architectural level, the audit gaps of the App Store become exposed. The approximately 904 samples screened this time are applications that appear in the iOS ecosystem as non-custodial wallets. According to publicly available information, they have evidently passed Apple's standard listing reviews. Apple's reviews are more oriented toward compliance and privacy terms being in place, while there are currently no publicly available professional standards addressing the specifics of how mnemonic phrases should be generated and stored, or whether private keys might be uploaded to servers. This places the "non-custodial wallet" label in a de facto grey area during the audit process—it can be employed, yet may not correspond to unified technical constraints.

This grey area manifests on the user end as an absolute information asymmetry. Average users opening the App Store can only judge whether to download an application based on categorization, ratings, and a few lines of description. A wallet that states "non-custodial" and "user controls keys," with an interface that appears mature and professional, leaves users with virtually no means to distinguish whether the wallet manages local private keys or bypasses commitments by uploading mnemonic phrases to some server node. More realistically, the currently disclosed materials do not provide details such as the names of the marked applications, developers, or whether rectifications have been made, nor has there been authoritative reporting from Apple on a concentrated response to this batch of risks, leaving users facing a world of unverifiable labels. They can only endure vastly different security levels stemming from technological implementation differences among seemingly identical "non-custodial" wallets.

Trust Gaps in the Industry: Power Struggles Between Wallet Teams and the Security Community

This time, the focus is not on regulatory agencies or application stores, but rather on a third-party technology executive—BlueWallet's Chief Technology Officer—who has no direct affiliation with the screened applications. The proactive initiation of this screening by a technical role outside wallet projects breaks the inertia of the past "whoever makes the product defines security" narrative and highlights the necessity of independent security forces within this ecosystem: when labels can easily be affixed as "non-custodial," only an external observer has the motivation to verify whether these commitments are genuinely reflected in code and architecture.

For many wallet teams, this questioning strikes at the heart of their long-standing product paths. On one side are compelling features such as "cloud backup" and "key recovery," and on the other is the non-custodial core promise of "users exclusively possessing private keys without relying on servers." The line between these often is not clearly defined but exists within a vast range of grey technical areas: is it to lower the barriers to entry or to quietly introduce centralized attack surfaces? Currently, there are no visible materials regarding the delisting, punishment, or unified rectification arrangements for relevant applications, and the competition between project teams and the security community largely remains on the levels of public opinion and awareness. Therefore, this disclosure is being interpreted as a catalyst encouraging users and developers to more explicitly demand that wallet projects open their code, provide third-party security audit reports, and disclose threat models, allowing the so-called "non-custodial" to transition from mere marketing labels to independently verifiable security designs.

User Self-Help Checklist: What to Look For Before Choosing a Crypto Wallet

In this screening, the list of 45 high-risk applications marked was not publicly disclosed, leaving users with no ready-made "blacklist," nor can they view any authoritative rankings of so-called "absolutely safe wallets." They must accept the reality that merely relying on the self-labeling of "non-custodial" in the app store does not guarantee it will not upload mnemonic phrases or private keys to servers for centralized storage. The fundamental habits repeatedly emphasized by the security community—keeping mnemonic phrases only on an offline medium, not taking photos or screenshots, and not uploading them to cloud drives or chat tools—represent the last layer of control ordinary users have in an environment absent of lists and transparent audits.

Specifically regarding wallet selection, several signals that can be seen in advance become especially crucial: carefully checking permission requests before installation, avoiding those that immediately request unrelated permissions such as accessing contacts, photos, or location; confirming whether backup paths clearly guide users to use paper, hardware, or locally encrypted files rather than defaulting to online storage like email or cloud drives; paying attention to whether the project is open source, whether the code repository is continually updated, and whether there are publicly available third-party security audit reports; and considering community reputation, focusing on actual usage feedback from long-term users rather than just ratings and marketing descriptions. Following this incident, which wallets are willing to invest effort in providing clear risk alerts and hands-on security education, and which ones continue to treat "non-custodial" as an empty slogan, will itself become an important standard for user selection.

Join our community, let's discuss, and become stronger together!
AiCoin exclusive Hyperliquid benefits: https://app.hyperliquid.xyz/join/AICOIN88
AiCoin exclusive Aster benefits: https://www.asterdex.com/zh-CN/referral/9C50e2
On-chain Telegram community: https://t.me/AiCoinWhaleData
On-chain community: https://www.aicoin.com/link/chat?cid=N6OVMor5g
AiCoin on-chain Twitter: https://x.com/aicoinwhaledata

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink