eric|10月 07, 2026 17:55
So much nonsense about @fomo security and mobile wallets today. Longer post:
The real question isn't "mobile vs hardware." It's where your key lives and what it takes to use it.
A hardware wallet keeps the key on a device you physically hold, and every signature needs that device plus a button press. That raises the floor, but it doesn't fix bad opsec. A Ledger user with their seed phrase in a notes app is in worse shape than a careful mobile user.
fomo is different from both. It uses @privy_io embedded wallets. Your key isn't sitting on your phone. It's split into shares and only reassembled inside secure hardware when you sign. In practice, your wallet is about as secure as your login.
The gates that matter:
1. Your Google/Apple login. No 2FA there means anyone who gets in can open your fomo.
2. 2FA inside fomo. With it on, a passkey or authenticator code is needed to sign, to set up your wallet on a new device, and to export your key. Without it, a logged-in session can sign anything.
3. Exported keys. Once you've pasted your key into another wallet, a notes app, or a screenshot, none of fomo's protections apply. My bet is this is where most drains start.
Face ID alone isn't the gate people think. It checks whoever is holding the phone. If someone logs into your account on their own phone, it's their face.
Where you log in matters too. A desktop browser full of extensions is generally a bigger target than an iOS app, though malicious iOS apps exist (see FomoPeek).
Apple ID with 2FA, Face ID to open the app, and passkey 2FA in fomo is far safer than a Google login with no 2FA on a desktop browser with no 2FA in fomo.
One ask for fomo: turn 2FA on by default for transactions and exports.
In the drain I looked at, every theft transaction was signed outside the fomo app with the raw key. That points to account security and exported keys, not a fomo or Privy breach.
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink