NokNok Wallet — Security model

People you trust. Rules nobody can bypass.

NokNok separates your account, each enrolled app installation, and optional platform security signals. That lets witnesses stop an emergency quickly without pretending a browser ID is an IMEI—or locking an innocent owner out of Apple, Google, or Telegram.

NokNok does not receive your plaintext private key, passphrase, duress code, or wallet-wrapping key.

Witnesses authorize recovery; they do not take custody of your wallet. The relay coordinates signed decisions and encrypted packages but cannot independently open your wallet.

Three identities with different jobs

01

Your account

Your username and wallet addresses identify the account. Suspending an account temporarily stops sensitive recovery and enrollment operations while witnesses contact you.

02

Your installation credential

Each installation creates a P-256 signing key. Its private half stays on that installation; the relay stores the public half. A device ID is the SHA-256 fingerprint of that public key—not an IMEI.

03

Platform signals

Apple, Android, Telegram, and browsers provide different evidence. Signals may help recognize abuse, but they do not replace the installation key or witness approval.

04

Signed, single-use actions

Sensitive requests sign a fresh relay challenge bound to the action, account, device, request body, expiration, and security epoch. Replaying a signature or substituting another action fails.

If a legitimate device is lost or stolen

01

Three attempts means locked

An enrolled installation verifies its passphrase locally. After three incorrect selections it locks, allows no more retries, and sends witnesses a signed incident notification.

02

A witness can suspend immediately

One authenticated witness can impose an emergency suspension or veto a suspicious request. This fast action buys time for a phone call without giving one witness permanent control.

03

An innocent mistake is recoverable

After calling the user, two distinct witnesses can authorize recovery. The current release records that authorization and keeps the installation locked until a locally decryptable recovery package is available; it never sends the passphrase to the relay.

04

Theft is contained first

If the incident is theft, any witness can suspend access immediately. Revocation and cryptographic passphrase rotation require a separate quorum-approved, end-to-end encrypted rotation package; that package is part of the vault-v2 migration described below.

If an unknown device tries recovery

01

No online passphrase oracle

An installation that was never enrolled cannot submit words to discover whether they match an account. It supplies a username and installation credential, then waits for witnesses.

02

Correct words are not enrollment

Knowing or guessing a phrase does not activate a new installation. Two witnesses must verify the person and approve that specific public-key fingerprint.

03

Abuse closes the gate

Abusive unknown-installation attempts burn that credential and close unknown-device recovery for the target account until witnesses deliberately reopen it. Reinstall and network signals may add correlation where a platform supports them.

04

Platform accounts are not casually banned

A stolen phone still belongs to the legitimate owner, so NokNok revokes the offending installation—not the owner’s Apple, Google, or Telegram identity. Broader identity action requires corroborated abuse.

Witness authority

01

One witness: emergency brake

One current witness may suspend, veto, or report a suspected attack. That immediately cancels pending access, but cannot complete recovery or take the wallet.

02

Two witnesses: durable change

Two distinct current witnesses are required to authorize recovery. New-device enrollment, suspension clearing, recovery-package release, and credential rotation remain closed until their vault-v2 end-to-end encrypted flows are deployed.

03

Calls provide human verification

The witness UI asks witnesses to call the user. Calls and email coordinate the human check; signed wallet and installation credentials authorize the decision.

04

Every decision is scoped

Decisions bind to one request, one security epoch, an expiry, and an authoritative witness list. Duplicate, expired, forged, or non-witness decisions are rejected.

Platform assurance and limits

iOS

Secure Enclave and App Attest

Mobile signing keys can be non-exportable and Secure Enclave-backed. App Attest can certify a genuine installation when production attestation is configured; its identity does not survive reinstall and is not an Apple ID.

Android

Keystore and Play Integrity

Android keys use hardware-backed Keystore when available. Play Integrity and Device Recall can add genuine-app, device-risk, and repeat-abuse signals after production Play configuration.

WEB

Chrome

Chrome uses a non-exportable WebCrypto key stored in its browser profile. Browsers cannot prove a permanent physical-device identity, so every new profile or installation requires witness approval.

TG

Telegram

Telegram Mini App data can identify a signed Telegram account after server validation, not the physical phone. Its browser installation still uses its own credential and witness gate.

Honest limitations

01

No immutable phone identifier

Modern platforms deliberately withhold IMEI-like identifiers. NokNok uses cryptographic installation identity and layered attestation because it is safer and more private, while acknowledging reinstall limitations.

02

Legacy vault migration

Older passphrase-derived public vault records may permit offline guessing and cannot be made private retroactively. The relay now blocks unauthenticated vault downloads and passphrase-oracle recovery, but that cannot erase records already observed. Vault v2—high-entropy wrapping plus witness-approved device packages—is the required next migration before automatic unlock or rotation can safely ship.

03

No absolute guarantee

No wallet can promise protection from every compromised operating system, coerced witness, weak user choice, or future vulnerability. NokNok reduces trust, records authority, fails closed, and explains where platform guarantees end.

04

Security data is limited

The relay may retain installation public keys and fingerprints, assurance results, hashed anti-abuse correlations, recovery decisions, and security timestamps. See the Privacy Policy for how these records are used.