Protocol · Security

Attacks the math actually blocks.

Six threats that make traditional wallets fragile. Every one either fails by cryptographic proof or is prevented on-chain — never by trust.

Attempts · today
12,847
Blocked
12,847
Compromised
0
128
Bit security
Post-quantum ready
ZK
Zero-knowledge
zkLogin native
21
Audit passed
SlowMist · 21/21
99.9%
Uptime
99.997% · 90d
Attack simulator

Click any threat. See it get blocked.

Six real-world attacks on wallets and identity systems. Each card is a live simulation — click to run it against HelixKey and see exactly why it fails.

Threat · 01
Seed-phrase theft
Attacker gets full access to your device and files.
▶ Run simulation
Threat · 02
Biometric DB breach
Attacker dumps the entire on-chain state.
▶ Run simulation
Threat · 03
Coerced enrollment
$5-wrench attack — forced to scan under duress.
▶ Run simulation
Threat · 04
Compromised device
Malware on your phone signs a transaction.
▶ Run simulation
Threat · 05
Quantum key recovery
Post-quantum computer breaks classical crypto.
▶ Run simulation
Threat · 06
Cross-chain replay
Signature captured on chain A, replayed on chain B.
▶ Run simulation
Threat · 01 ◉ SIMULATION
Attack blocked · reason will appear here
Key rotation

Revoke and re-anchor. Without losing the identity.

A seed phrase, once known, is compromised forever. HelixKey rotation is a first-class primitive: press the button, watch how the chain propagates a new key in real time.

Live rotation demo · gen 1
t=0 +6h +12h +18h +24h Key gen 1 ACTIVE Key gen 1 RETIRING Key gen 2 NEW HelixIdentity object · same address · gen list [1]
Current gen
1
Lifetime rotations
3,421
Avg rotation time
~1s + grace
Ledger propagation
Instant
Audit

Every box checked. Independently.

SlowMist audited the four Move modules. 21 checklist items. Zero unresolved findings. Full report on request.

21/21 CHECKLIST

SlowMist · 2026-05-19

All items passed on first review

Cross-chain

One key. Three different signatures.

Domain separation is baked into the key derivation. A signature you produced on Sui is cryptographically useless on Ethereum. Replay across chains is impossible by construction.

Biometric-derived key
k = 0x7c3aed
...bf29a4b8
Same message: "transfer 100 USDC"
SUI 0xa2f8d4...c7b91e ✓ valid
ETH 0x9b3e1a...f42d05 ✓ valid
SOL 0x5d7c8b...e19a3f ✓ valid
↻ Replay attempt — Sui signature submitted to Ethereum: ✗ rejected
Bug bounty

Find a bug. Name your price.

Four severity tiers, from $100 to $100,000. Drag the slider to see the reward. Responsible disclosure at [email protected].

LowMediumHighCritical
High severity
$10,000
Fund-loss vector requiring specific setup · privilege escalation · signature forgery
Full bounty program Disclose privately Architecture →