One key.
Every chain.
A self-custodial wallet with bank-grade cryptography: keys are encrypted with Argon2id + AES-256-GCM, sensitive actions demand a fresh password, and every transfer carries a transparent 0.8% service fee.
Encrypted at rest
Wallet secrets are sealed with AES-256-GCM under a master key derived from your password (Argon2id). Not even the server can read them without your passphrase.
Password-gated export
Viewing a private key always demands a fresh password entry (plus 2FA when enrolled), is audited, and is wiped from screen when the dialog closes — Phantom-style paranoia, by default.
Cold vault mode
Flip a wallet to cold: its key is destroyed server-side and it becomes view-only. Restore it later only with the exact private key — a deliberate, friction-full act.
TOTP + recovery codes
Enroll an authenticator app; logins, unlocks and admin recovery then require a rotating code. Single-use recovery codes are shown exactly once.
Wormhole bridge
Burn WBTC on Solana, attest BTC deposits to custody and settle guardian-signed VAAs — guardian quorum verified before any mint.
Raydium swaps & on-ramp
Quote and execute AMM swaps straight from your wallet, and buy crypto with card through a Stripe on-ramp bound to your address.
◈Security policy — how OneNess protects you
Self custody. You hold the keys. Encrypted blobs live server-side but are useless without your password; changing it re-encrypts every wallet instantly.
Fresh unlock window. Sends, swaps, backups and exports require the password again after 5 idle minutes — session theft alone can't move funds.
Full audit trail. Logins, unlocks, exports and admin actions are recorded; the fee ledger is user-visible. Lockouts after repeated failures, rate limits on every route.
Never share secrets. Nobody legitimate will ever ask for your password, key or recovery code. Verify every address before sending — transfers are irreversible.