← icrypto.money
What's auditable
Effective 2026-05-08 ยท Security policy
Trust earned by inspection beats trust extended on faith. Here is exactly what you can verify yourself about icrypto.money — and where you would still have to take our word.
The four layers
The wallet has four layers. Each has a different audit story.
Public · Inspect freely
1. The wallet engine (upstream MIT)
The atomic-swap engine, BIP-39 key generation, address derivation, transaction signing — the parts that touch your funds — come from swaponline/MultiCurrencyWallet, MIT-licensed and public. You can read every line, build it yourself, compare against what we ship.
How to verify. Clone the upstream, run npm ci && npm run build:mainnet, diff the resulting bundle against the JS we serve at icrypto.money/default-app.*.js. Differences are our additions (see layer 2).
Proprietary · Take on trust, for now
2. Our additions (the icrypto fork)
Our changes — sovereign config, edge geofence, kill-switch, fee-collection wiring, CSS — live in a private repo. They sit outside the parts that hold or move funds. The upstream wallet engine remains the trust root. We are working towards publishing this layer; until we do, the integrity claim relies on the upstream check above plus our security policy.
How to verify. Compare the JS bundle to the upstream build (above); the diff is our layer. Inspect icrypto.money/_headers for security policy. Inspect icrypto.money/.well-known/security.txt for the disclosure contact. We do not modify the swap or signing code paths.
Public · On-chain
3. Where the fee goes
Every swap routed through icrypto.money carries a 0.25-0.35% take rate. It lands in two addresses, one EVM, one BTC, both displayed at /admin. Anyone can inspect the balances and the inbound flow on a block explorer; we do not control which transactions can or cannot be observed.
How to verify. Open
/admin. Click the EVM address; Etherscan opens with full balance and transfer history. Click the BTC address; Blockstream Explorer opens with the same. The values shown to you are the values everyone sees.
Public · In your browser
4. Your keys
Your seed phrase is generated client-side, in your browser, on first wallet open. It is stored in localStorage and never travels over the network. We have no server that holds, mirrors, or escrows it. The seed is a standard BIP-39 phrase — if we disappeared tomorrow, it would still open your wallet on MetaMask, Trust, Ledger, or any compatible interface.
How to verify. Open browser DevTools → Application → Local Storage → https://icrypto.money. The seed material is there, in plain text — we do not encrypt it, and this is how you confirm that for yourself. Open the Network tab during wallet creation and operation; observe that no request carries the seed. Try restoring your seed in MetaMask; it works.
Things we do not do
- We do not run KYC. We do not ask for or store your name, email, address, ID, or selfie.
- We do not custody funds. The deposit addresses we display are derived from your seed, not ours.
- We do not run analytics that identify you. The site loads Plausible, which is cookieless and does not fingerprint visitors.
- We do not pass your seed, address list, or transaction history to any third party. There is no server endpoint to send them to.
Things we do do, and disclose
- We charge 0.25-0.35% on swaps. The fee is added to the 0x quote and routed to addresses listed at /admin.
- We use third-party RPC providers (Alchemy and public fallbacks), price feeds (CoinGecko), and the swap aggregator (0x). Your IP address reaches them when you use the wallet; their privacy policies apply at that boundary.
- We geofence the front-end against US and OFAC-sanctioned jurisdictions at the edge. The wallet engine itself is jurisdiction-blind; the front-end is not.
- We may take icrypto.money offline for any reason, with or without notice. Your seed phrase continues to open your wallet elsewhere; the chains do not stop just because we did.
Open issues we will not paper over
- Layer 2 above — our fork modifications — is private. We are not yet open-sourcing it. The MIT upstream is the auditable foundation; our layer is not.
- The browser is a difficult environment for key custody. A compromised device compromises the wallet. We do not pretend otherwise.
- BIP-39 phrases written down on paper get lost, photographed, or stolen. We do not have a recovery flow. There cannot be one.
Found something we got wrong? security@icrypto.money. We answer.