- Home
- Security
Designed for custodial funds
OmniWallet receives and holds funds on your behalf, so key management, signing and payout controls sit at the core of the architecture. Here is how we protect funds.
Keys and signing
Isolated keys
HD keys exist only inside a separate signing service. It has no public endpoint and no database access, and can only be called by our internal services.
Signs only what it builds
The signing service builds every transaction itself and checks it against policy before signing. It never signs hashes or payloads passed in from outside.
Enforced signing policy
Deposit addresses can only send to the hot wallet on the same chain. The hot wallet can only pay cold and gas wallets, merchant addresses bound with 2FA after a 24-hour cooling-off period, or 2FA-authorized payout items — each usable only once.
Limits and emergency freeze
Per-transaction, daily and platform-wide payout limits apply, and any policy violation is refused and raises an alert. Funds can be frozen with one action; unfreezing requires two administrators.
Fund storage
Cold multisig
Most funds are held in hardware multisig cold wallets that are not derived from the system seed.
Hot wallet limits
The hot wallet keeps only about one to two days of payout volume; anything above its cap is moved to cold storage automatically.
Double-entry ledger and reconciliation
All amounts are recorded as integers in a double-entry ledger. On-chain balances are reconciled every hour, and every day we check that the ledger balances and that liabilities never exceed custodial assets.
Deposit integrity
Whitelisted contracts only
Tokens are matched by chain and contract address. Tokens that are not on our list are never credited, which blocks fake USDT and address-poisoning attacks.
Confirmations and reorg detection
Deposits are credited only after each chain’s confirmation threshold, and failed (reverted) transactions are never credited. Reorgs are detected by block hash; if a credited deposit disappears, related payouts are frozen immediately.
Second-provider verification
Deposits of US$1,000 or more are verified with a second node provider, so a single faulty node cannot mislead us.
Account and payout controls
Mandatory 2FA
Owners, admins and any role that can send payouts or edit whitelists must use 2FA. Payouts, settlement wallet changes, API keys and team changes all require a fresh code.
Payout approvals
Payouts can require one or two approval levels, with a second approver for large amounts.
API keys
Keys are stored hashed, shown only once and can be limited in scope. Keys with payout permissions require an IP allowlist.
Audit logs
Every money-related or security-related change is recorded in an audit log, written in the same atomic batch as the transaction itself.
AML screening
Sanctions and scam lists
Source addresses of incoming funds are checked against OFAC, UN and EU sanctions lists, the ScamSniffer scam list and the Tether freeze list, all synchronized automatically.
When a match occurs
Payments that match a sanctions list are marked failed, the funds are frozen, and they are never returned automatically to a sanctioned address.
Risk tools
The console includes AML review and fund-tracing tools to help you investigate suspicious payments.
Infrastructure
Built on Cloudflare
The website and API run on Cloudflare’s global network. Internal services have no public URLs and can only be reached through internal service bindings.
Fully separated environments
The sandbox and production use completely separate services, databases and keys.
Connection and login security
All traffic uses HTTPS, sessions use HttpOnly cookies, sign-up is protected against bots, and rate limits apply.
Report a security issue
If you find a vulnerability, email support@ewin888.com with steps to reproduce it. Please don’t disclose it publicly or access data that isn’t yours. We’ll get back to you as soon as possible.
