Security
What protects your keys, and how to check the wallet code yourself.
Qlyphs asks you to trust as little as possible, and lets you check the rest. What protects your keys on your device is described in The wallet; this page is about checking the code.
Open source
The wallet is open source under the MIT licence: github.com/yacinealloul/qlyphs-wallet. It covers Qlyphs Keys, the extension and the provider that sites use to talk to the wallet.
Verify keys.qlyphs.com
A web wallet downloads its code on every visit, so you should be able to check what you received. Every release of Qlyphs Keys is reproducible: the same source always builds the same bytes.
Each GitHub release (tag keys-v<version>) publishes a release hash, the SHA-256 of the list of
every file the site serves. Every response from keys.qlyphs.com carries it in the x-qlyphs-release
header.
curl -s https://keys.qlyphs.com/SHA256SUMS.txt | shasum -a 256The result must equal the release hash on GitHub. For a full check of every file and of the page's security policy, run the verifier from the repository (Node 18 or later):
node apps/keys/verify.mjs https://keys.qlyphs.com --expect <release hash>A check proves what the site served to you, when you checked. It cannot prove that everyone else received the same files. The extension does not have this limit, which is why it is the better choice for larger amounts.
How the page is locked down
- The page runs only its own scripts: no third-party code, no analytics, no
eval. - It connects only to the Quantus network and the Qlyphs service it was built with. A website cannot change them.
- It cannot be embedded in another site.
Report a vulnerability
Report it privately through GitHub's private vulnerability reporting. Please do not open a public issue for a security problem.