Cardano wallet security · Gero Dashboard 2.7.1

The safest ADA wallet is one you can check yourself.

GeroWallet is non-custodial and its source code is public, so anyone can check it. Keys are encrypted with Argon2id on your device, and with a Ledger, Trezor or Keystone nothing signs without your hardware.

  • Apache 2.0 open source
  • Ledger, Trezor and Keystone
  • Passkeys as an option

Open source since 2.7

How to check a Cardano wallet's security yourself

Every claim on this page points at something you can inspect: the code, the security fixes that shipped, and the encryption that protects your keys.

  • Open source under Apache 2.0. The full wallet source is on GitHub with a SECURITY.md disclosure policy, so you can read the key derivation, the signing paths and the dApp origin checks, and report what you find.
  • A security hardening pass before the code went public. Shipped in 2.7: origin checks on dApp signing, CIP-30 frame validation, and the Argon2id upgrade below.
  • Argon2id key encryption. Recovery phrase, 2FA and MPC secrets moved from a weak key-derivation scheme to Argon2id, and the legacy crypto library was removed entirely. Existing wallets migrated on their own.
  • Nothing hidden in the bundle. API keys are no longer baked into the client, OAuth uses a CSPRNG, and a dependency audit cleared production-critical CVEs.
Gero-Labs/gerowalletAPACHE-2.0
  • LICENSEApache 2.0. Read it, fork it, build it.
  • SECURITY.mdHow to report a vulnerability, with an email fallback.
  • ARCHITECTURE.mdHow the extension is put together.
  • src/Key derivation, signing paths and the dApp origin checks.
  • test/The test suite that runs on every change.
  • CONTRIBUTING.mdContributor guide, with issue and PR templates.
Hardened in 2.7, before the code went public.Open on GitHub

Cardano Shield · Project Catalyst Fund10

What Cardano Shield checks before you sign

GeroWallet built and integrates Cardano Shield, an AI-powered security layer that looks at the site and the transaction before you approve anything.

Phishing protection

URL analysis flags malicious sites before you connect your wallet, in real time.

Transaction safety

A plain summary of what a transaction does, so you can see the risk before you authorise it.

Scam detection

Alerts on suspicious NFT projects and potential rug pulls before they cost you funds.

Unlocking the wallet

Password first, then whatever you add on top

A spending password protects every wallet. PIN, biometrics and passkeys are layers you add for convenience or phishing resistance, never a replacement.

Spending password

Every wallet has one. Change it and the old one is invalidated immediately.

PIN or pattern

A 4 to 8 digit PIN or a pattern for quick unlocks on top of the password.

Biometrics and auto-lock

Fingerprint unlock where the browser supports it, and a configurable auto-lock timeout.

Passkeys as an option

Add a FIDO2 passkey next to your password. The password stays; the passkey is a phishing-resistant extra way in, with a fallback in browsers without PRF.

Defence in depth

Cardano security features you can inspect in the source

Independent layers, each one readable in the public code.

  • Origin-locked dApp signing. Signing trusts only the relay-set request origin, and CIP-30 reads validate frame sources against a server-side whitelist. A malicious page cannot pose as a trusted one.
  • Standard BIP39 recovery. Your recovery phrase restores the wallet in any BIP39 compatible wallet, so you are never locked in to Gero.
  • Private by design on Midnight. Choose where zero-knowledge proofs run: Gero Cloud, a local proof server, or Arkhia with your own key. Cross-Device Proving lets your desktop prove for your phone over an end-to-end encrypted channel.

Step by step

How to Set Up a Cardano Wallet Securely

  1. 01

    Install from the Chrome Web Store

    Get Gero Dashboard from the official Chrome Web Store listing on Chrome, Brave or Edge. Check the publisher before installing any wallet extension.

  2. 02

    Write down your recovery phrase offline

    Create a wallet and write the BIP39 phrase on paper. Never store it in a screenshot, a cloud note or a message. It is the only way to restore your ADA.

  3. 03

    Pair a hardware wallet

    Add a Ledger, Trezor or Keystone from the wallet menu. From then on transactions, delegations and dApp requests are confirmed on the device screen.

  4. 04

    Turn on auto-lock and a second unlock

    Set an auto-lock timeout, then add a PIN, biometrics or a passkey next to your spending password. Cardano Shield is on by default.

Cardano wallet security questions

Is a Cardano wallet safe?

A Cardano wallet is as safe as its key handling and the code you cannot see. GeroWallet is non-custodial, so keys never leave your device; its source is public; keys are encrypted with Argon2id; and with a Ledger, Trezor or Keystone nothing signs without the hardware. Cardano Shield checks sites and transactions before you sign.

What is the safest ADA wallet?

The safest ADA wallet is a non-custodial wallet whose code you can read, paired with a hardware device. GeroWallet is open source on GitHub and supports Ledger, Trezor and Keystone. Passkeys and biometrics are available as options next to your spending password.

Which hardware wallets work with GeroWallet?

Three brands: Ledger (Nano S, Nano S Plus, Nano X), Trezor (Model One, Model T, Safe 3) and Keystone (3 and 3 Pro). Trezor connects over WebUSB with no Bridge daemon, Keystone signs air-gapped by QR code, and every device signs transactions, delegations and dApp requests on its own screen.

What is Cardano Shield?

Cardano Shield is an AI-powered security layer built by GeroWallet and backed by Project Catalyst Fund10. It provides real-time phishing protection, transaction safety summaries and scam detection to protect you from malicious websites and rug pulls before you sign.

Is GeroWallet non-custodial?

Yes. Your recovery phrase and private keys are encrypted with Argon2id and stored on your device. GeroWallet never has access to your funds, recovery phrase or private keys, and you can confirm that in the public source code.

Can I use GeroWallet without a password?

No, and that is deliberate. Every wallet has a spending password. Passkeys, PIN, pattern and biometrics are options you add on top of it for quicker or phishing-resistant unlocks, not replacements for it.

What happens if I lose my Gero recovery phrase?

Nobody can recover it for you, including Gero, because it never leaves your device. If you still have the wallet installed and unlocked, back the phrase up now from settings. If not, the funds are only recoverable with the phrase, which is why it belongs on paper, offline.

How can I verify GeroWallet security myself?

Read the source at github.com/Gero-Labs/gerowallet, released under the Apache 2.0 open source licence with a SECURITY.md disclosure policy. You can inspect the key derivation code, the signing paths and the dApp origin checks, and report anything you find through the documented process.

Where are my Midnight zero-knowledge proofs generated?

You choose. GeroWallet can run Midnight proofs on Gero Cloud, on a local proof server on your own machine, or on Arkhia zkPaaS with your own key, switchable from the dashboard. With Cross-Device Proving your desktop generates proofs for your phone over an end-to-end encrypted channel, so Gero infrastructure only ever sees ciphertext.

Security you can check, not just trust

Free on Chrome, Brave and Edge. Non-custodial, open source, hardware wallet ready.