Cardano Wallet Security You Can Verify

GeroWallet's source code is public, version 2.7 passed two external audit rounds, and your keys are encrypted with Argon2id on your own device. Add a Ledger, Trezor or Keystone and nothing signs without your hardware.

100%
Non-Custodial
2
External Audit Rounds
3
Hardware Wallets
New in GeroWallet 2.7

Read the Code Before You Trust It

The full wallet source is open source on GitHub under the Apache 2.0 licence, which lets you read, fork and build it. It ships with a responsible disclosure policy, a code of conduct and contributor templates. Version 2.7 also upgraded mnemonic, 2FA and MPC encryption to Argon2id, removed the legacy crypto library entirely, and locked dApp signing to the real request origin so a malicious page cannot spoof it.

Argon2id key encryption

Recovery phrase, 2FA and MPC secrets moved from a weak key-derivation scheme to Argon2id. Existing wallets migrated transparently.

Two external audit rounds

Plus an internal review before the source went public. Findings landed in 2.7, including origin checks on dApp signing and CIP-30 frame validation.

Nothing hidden in the bundle

API keys are no longer baked into the client, and a dependency audit cleared production-critical CVEs.

View the source on GitHub
Powered by Cardano Shield

Cardano Shield: AI-Powered Threat Protection

GeroWallet built and integrates Cardano Shield, an advanced Cardano security solution backed by Project Catalyst Fund10 that protects your Cardano wallet from evolving threats through AI-powered detection.

Phishing Protection

Advanced URL analysis detects malicious websites before you connect your wallet, preventing phishing attacks in real-time.

Transaction Safety

Clear transaction summaries help you understand potential risks before authorizing any action with your wallet.

Scam Detection

Receive alerts about suspicious NFT projects and potential rug pulls, helping you avoid scams that could lead to permanent fund loss.

Cardano Shield logo
Protected
Malicious Sites Blocked1,247
Scams Prevented892
Users Protected15K+

Multi-Layer Authentication

A spending password protects every wallet. Add PIN, biometrics or a passkey on top, and change the password knowing the old one is invalidated immediately.

PIN Code Protection

Set a secure PIN code or pattern to protect your wallet from unauthorized access.

  • 4-digit PIN code
  • Pattern unlock
  • Encrypted storage

Biometrics & Auto-Lock

Use fingerprint authentication and auto-lock to keep your wallet secure at all times.

  • Fingerprint authentication
  • Configurable auto-lock timeout

Passkeys as an Option

Add a FIDO2 passkey (WebAuthn) next to your spending password. Your password stays; the passkey is an extra, phishing-resistant way in.

  • Works alongside your password
  • Phishing-resistant
  • Graceful fallback in browsers without PRF

Defence in Depth

Several independent layers, each of which you can inspect in the public source.

Origin-Locked dApp Signing

dApp signing trusts only the relay-set request origin, and CIP-30 reads validate frame sources against a server-side whitelist. A malicious page cannot pretend to be a trusted one.

Non-Custodial

You control your private keys. We never have access to your funds or recovery phrase.

Publicly Verifiable

The source is on GitHub with a SECURITY.md disclosure policy. Found something? There is a documented way to report it.

Secure Recovery

BIP39 standard recovery phrases ensure you can always restore your wallet securely.

Auto-Lock

Automatically locks your wallet after periods of inactivity to prevent unauthorized access.

Private by Design on Midnight

Choose where your zero-knowledge proofs run, and let your desktop prove for your phone over an end-to-end-encrypted channel. See the Midnight wallet.

Frequently Asked Questions

Common questions about GeroWallet security features

What is the most secure Cardano wallet?

The most secure Cardano wallet is one whose code you can read. GeroWallet is non-custodial, its source is public on GitHub, version 2.7 passed two external audit rounds, keys are encrypted with Argon2id, and it pairs with Ledger, Trezor and Keystone. Passkeys and biometrics are available as options next to your spending password, and Cardano Shield flags scams before you sign.

Does GeroWallet support hardware wallets?

Yes, GeroWallet supports three hardware wallet brands: Ledger (Nano S, Nano S Plus, Nano X), Trezor (Model One, Model T, Safe 3) and Keystone (3, 3 Pro). Trezor connects over WebUSB with no Bridge daemon, and every device signs transactions, delegations and dApp requests on its own screen.

What is Cardano Shield?

Cardano Shield is an AI-powered security solution built by GeroWallet and backed by Project Catalyst Fund10. It provides real-time phishing protection, scam detection, and transaction safety analysis to protect users from malicious websites and potential rug pulls.

Is GeroWallet non-custodial?

Yes, GeroWallet is 100% non-custodial. Your recovery phrase and private keys are encrypted with Argon2id key derivation and stored on your device. GeroWallet never has access to your funds, recovery phrase or private keys, and you can confirm that yourself in the public source code.

What authentication methods does GeroWallet support?

GeroWallet supports several authentication methods: a spending password, PIN codes (4-8 digits), pattern unlock, biometric authentication, FIDO2 passkeys as an option, and auto-lock after inactivity. Passkeys sit alongside your password rather than replacing it, and browsers without PRF support fall back gracefully.

Can I verify GeroWallet's security myself?

Yes. Since version 2.7 the full wallet source is public at github.com/Gero-Labs/gerowallet under the Apache 2.0 open source licence, with a SECURITY.md disclosure policy. You can read the key-derivation code, the signing paths and the dApp origin checks, and report anything you find. Two external audit rounds and an internal pre-release review preceded the release.

Where are my Midnight zero-knowledge proofs generated?

You choose. GeroWallet lets you run Midnight proofs on Gero Cloud, on a local proof server on your own machine, or on Arkhia zkPaaS with your own key, switchable from the dashboard. With Cross-Device Proving, your desktop can generate proofs for your phone over an end-to-end-encrypted channel, so Gero's infrastructure only ever sees ciphertext. Read more on the Midnight wallet page.

Security You Can Check, Not Just Trust

Download GeroWallet, pair your hardware wallet, and read the code that protects your ADA.

2
External Audit Rounds
100%
Non-Custodial
3
Hardware Wallets
Download GeroWallet Free