Frequently Asked Questions about Security
1. Is this a non-custodial wallet? If so, what is it?
Yes, this is a non-custodial wallet. That means: We do not have access to your funds. We cannot block, freeze, or restrict your access to your money. You are the sole owner of your private keys and seed phrase. We believe in financial freedom – your assets belong only to you.
2. How is my seed phrase stored? Do you save it?
Your seed phrase never leaves your device. We do not store it on our servers. The seed phrase is encrypted on the client side using AES‑256‑GCM (bank‑grade encryption) with a key derived from your PIN via PBKDF2 with 350,000 iterations. The encrypted seed phrase is stored in Telegram’s own cloud storage (TelegramStorage), which is officially part of the Telegram Bot API. Telegram only sees encrypted characters and numbers – even if your Telegram account is compromised, the seed phrase remains unreadable without your PIN. We have zero access to your seed phrase, and neither does anyone else.
3. How do you store data in Telegram?
We use double‑layer encryption: First layer: your data is encrypted with AES‑256‑GCM (bank‑grade standard) on the client before it is sent to Telegram. Second layer: Telegram itself encrypts all data with its own keys (at rest and in transit). Additionally, we apply: 350,000 PBKDF2 iterations – this dramatically slows down brute‑force attempts. Auto‑lock after 3 incorrect PIN attempts – this blocks offline dictionary attacks. So even if someone gains access to your Telegram cloud storage, the encrypted data is practically impossible to crack without your PIN.
4. How and what kind of data do you store on your servers?
We store only the minimum necessary data on our secure servers, and all of it is encrypted or anonymised: Encrypted Telegram ID – used for identification and notifications. Encrypted wallet addresses (TON) – used for balance queries and transaction history. Username hash (SHA‑256) – used for searching other users. Referral code – a public identifier for referral programs (not sensitive). Public wallet address – only if you choose to make a wallet public for receiving payments. All sensitive fields are stored in encrypted form using the same AES‑256‑GCM + HMAC scheme described above. We never store your PIN, private keys, or seed phrase on our servers.
5. Why do you need my data, how do you encrypt it, and how secure is it?
We need your data only for the wallet to function properly: Telegram ID – to authenticate you, link your wallet, and send you important notifications (e.g., transaction confirmations, swap statuses). Wallet addresses – to display your balances, transaction history, and enable transfers. Username – to allow other users to find you and send payments. How we encrypt it on the server: We use AES‑256‑GCM – symmetric encryption with authentication. The encryption key is derived from a master key using scrypt (a memory‑hard KDF). Every encrypted field is protected by an HMAC‑SHA256 signature to detect any tampering with the data.
Additionally, we insert random “marker” characters into the encrypted hex string as an extra layer of obfuscation (not cryptographic, but it adds complexity for automated analysis).
How secure is it?
AES‑256 is considered unbreakable with current technology – even quantum computers would take decades. Scrypt and PBKDF2 make brute‑forcing PINs or keys infeasible. All communication is over HTTPS with strict HSTS, CSP, and CORS policies. Your seed phrase and PIN never leave your device – they are only used locally. We follow industry best practices and continuously improve our security. Your data is safe with us.
We value freedom, we value you as our clients, we do everything to provide you with the best user experience, new technologies, and so on. If you have any problems, please contact our support team using a direct message in the channel - t.me/SociaWallet?direct.
Welcome to @SociaWallet | @Socia.
Post #18
144

- ⚡ 5
- 🏆 4