B28 is a non-custodial wallet. Your private keys and recovery phrase are generated and stored on your own device, inside its secure hardware, behind your biometrics. We never hold, control, or access your funds, and we could not move them even if we wanted to. Security at B28 is the combination of that design, the Sentinel scam-shield that checks every transaction before you sign, and a small number of habits only you can keep.
The security model: your keys, your device
When you set up B28, your wallet keys are created on your phone and never sent to us. They live in the device's secure hardware, the same protected area your phone uses for its own passcode and payment credentials, and they are unlocked by your biometrics (Face ID, Touch ID, or the equivalent on Android). Every time you send or sign, you approve it on your own device. We never hold your keys or your recovery phrase, and you do not have an account with us. Your balances and history live on the public blockchain under your control, not in a profile we keep about you.
This is true across all 16 networks B28 supports. The same on-device, non-custodial model applies whether you are holding Bitcoin, sending on Ethereum, or moving assets on Solana, XRP, or any other supported chain. To understand the model in plain language, see self-custody.
Your recovery phrase is the root of control
Your recovery phrase is the master key to your wallet. Anyone who has it can move your funds, from any device, without your phone or your biometrics. You can export it from B28 at any time to back it up yourself. Because we never hold it, we cannot recover it for you if it is lost, and we cannot reset it. Keep it offline, keep it private, and never type it into a website, a message, or any app that asks for it.
Transactions are final
Blockchain transactions are irreversible. Once you sign and a transaction is confirmed, it cannot be cancelled, reversed, or refunded by B28 or by anyone else. We do not operate the underlying blockchains and we do not approve or process transactions on your behalf. This is why checking before you sign matters so much, and why Sentinel exists.
Sentinel: the scam-shield that checks before you sign
Sentinel is B28's built-in scam-shield. It runs automatically and screens what you are about to do, so you get a clear warning before you sign rather than a regret afterwards. Sentinel looks for the patterns that drain real wallets:
- Address screening. It checks the address you are sending to against known-risk signals and flags anything that looks dangerous.
- Address-poisoning and look-alike detection. Scammers seed your history with addresses that resemble ones you have used before, hoping you copy the wrong one. Sentinel detects these look-alikes and warns you when a destination is suspiciously similar to, but not the same as, an address you trust.
- Honeypot detection. It screens tokens for honeypot traps, the kind designed so you can buy in but never get out.
- Drainer-approval detection. Many thefts happen not through a transfer but through a malicious approval that quietly hands a contract permission over your tokens. Sentinel flags drainer-style approvals so you can refuse them.
- Warn before you sign. When something looks wrong, Sentinel surfaces a plain-language warning at the moment of signing, while you can still stop.
Address and token reputation checks (look-alike, honeypot, and drainer screening) run on the networks we support for them today, which are the EVM networks such as Ethereum and its L2s. On other networks Sentinel still shows you the transaction and tells you when it cannot verify a recipient, so you never get a false all-clear. Sentinel is a safety net, not a guarantee. New scams appear constantly, and no screening catches everything. Treat its warnings seriously, and treat its silence as a reason to stay careful rather than a promise that you are safe. For the most common scams and how to avoid them, see scams and how to spot them.
What B28 will never do
These promises help you spot an impostor instantly. If anything claiming to be B28 does any of the following, it is a scam:
- We will never ask for your recovery phrase or private keys. Not by email, not in a message, not on a website, not in support chat. There is no situation in which real B28 needs them.
- We will never move funds for you. We cannot. Only you can sign a transaction, on your own device, with your biometrics.
- We will never ask you to "verify", "sync", or "restore" your wallet by entering your phrase somewhere. That is the most common drainer script.
- We will never freeze, reverse, or reclaim a transaction, because we do not have that power over the blockchain.
Reporting a vulnerability
If you believe you have found a security issue in B28, we want to hear from you. Email security@joinb28.app with enough detail for us to reproduce it, and please give us a reasonable opportunity to investigate and fix the issue before disclosing it publicly. We intend to run a coordinated responsible-disclosure and bug-bounty program, and we plan to publish a security.txt file with our current contact and disclosure details. Please do not access, modify, or delete data that is not yours, and do not run tests that could degrade the service for others.
Independent security review
We are committing to one future milestone here, and only this one: an independent security review of B28 will be published before the card launches. We will not claim certifications, audits, or ratings we do not have. When the review is available, we will link it from this page.
What only you can do
A non-custodial wallet puts you in control, which also means a few things rest with you. These habits prevent the large majority of real losses:
- Lock your device. Use a strong passcode and keep biometrics on. Your wallet is protected by your phone's own security.
- Back up your recovery phrase offline, and keep it secret. Write it down or store it offline, never as a screenshot, a note in the cloud, or a message to yourself.
- Slow down before you sign. Read the address, the amount, and any Sentinel warning. Most thefts rely on you rushing.
- Be suspicious of urgency. "Act now or lose your funds" is the signature of a scam, not of B28.
- Verify the source. Only download B28 from official links, and check addresses character by character for large transfers.
For deeper guidance, see scams and how to spot them, how self-custody works, and what to do if you lose or replace your device.
A note on what is live
The B28 wallet, including Sentinel, is live today for holding, sending, and receiving across the supported networks. In-app convert is a live-rate preview that is rolling out, buy-with-card uses an on-ramp partner, and the instant-convert Visa card is coming, not yet live. Where a feature involves a third party, such as the on-ramp partner or the convert provider, that third party operates under its own terms, and we surface it but do not control it.
Contact
For security reports, email security@joinb28.app. For anything else, email hello@joinb28.app. See also our Terms of Service and Privacy Policy.