Keeping Your Account Secure
There is no password
Brykto does not use passwords. You sign in with a link sent to your email, which lasts 15 minutes and works once.
That means there is no password to guess, reuse, or leak. It also means your email account is your Brykto account. Anyone who can read your email can sign in as you.
Protecting your email
Since your email is the way in, protect it properly:
- Turn on two-factor authentication with your email provider
- Use a password you do not use anywhere else
- Never forward a sign-in link to anyone
Brykto will never ask you to send us a sign-in link.
Brykto cannot touch your funds
Payments go straight to your wallet. Brykto has no ability to move funds out of it, and neither does anyone who gets into your Brykto account.
What someone in your account could do is change where your future payments go. That is the risk worth thinking about, and it is why the email on your account matters.
Your wallet recovery phrase
Brykto never asks for it. Not during onboarding, not by email, not through support. Anyone who asks is trying to steal from you.
Your recovery phrase belongs in LOBSTR or Xaman and nowhere else. Nobody can recover it for you, and anybody who has it owns everything in your wallet.