The screens that say no.
A wallet's real job is refusing the transaction you would have regretted. Here is every refusal Smartable is capable of, and the ones it is not.
The key itself
How the hit usually lands
Most thefts never touch the cryptography. They take keys off a server that never needed to hold them, or off a phone that was not locked.
What Smartable does
Keys are generated on your device, held in the platform keystore, and never transmitted. There is no Smartable account, so there is nothing of yours on our servers to lose. A PIN, biometrics, unlock throttling, and spend limits guard the device itself, and the app switcher is dimmed on iOS. One honest limit: the app does not block screenshots on iOS, because iOS has no API for it.
The address that looks right
How the hit usually lands
An attacker sends you dust from a lookalike address that matches the first and last characters of one you trust. It sits in your history until the day you paste the wrong one.
What Smartable does
Smartable flags lookalike and poisoning-pattern addresses in your history and warns you before you send. The second layer is a trusted-address book and recipient history, so the address you meant is the one you pick — not the one an attacker planted.

The token that isn't the token
How the hit usually lands
Fake USDC, dust airdrops, and copycat contracts land in your wallet uninvited, each hoping you open a link, approve a contract, or trade the imitation.
What Smartable does
Spam and fake tokens are filtered out of the wallet view. Real assets carry a blue verified mark, which means exactly one thing: we checked this contract address. It does not mean the issuer is reputable, the token is safe, or the price is real — a verified mark is identity, not evidence.
The approval you forgot
How the hit usually lands
A dApp asks for permission to move your tokens, and most wallets hand over the whole balance. Months later, a contract you forgot about is exploited — and the allowance is still open.
What Smartable does
Smartable grants approvals for one trade, not the balance. Every approval is logged, and you can review and revoke any of them from Settings. Reviewing and revoking is a fee-free feature, not an upsell.
The site pretending to be a dApp
How the hit usually lands
A cloned site or a poisoned ad leads you to connect your wallet and sign something that drains it. The page looks right; the signature is not.
What Smartable does
Connections are checked against phishing lists before anything connects, permissions are granted per site and can be withdrawn per site, and the review screen decodes the calldata into plain language instead of showing you a hex blob.
What we do not claim
The refusals we are not capable of.
- No third-party security audit yet. 3,541 automated tests run on every build, but a test suite is not an audit and we will not call it one.
- No insurance. If funds are stolen, there is no policy that pays out and no fund that makes you whole.
- No recovery service. If the phrase and every share are gone, so is the money. Any wallet that says otherwise is custodial — someone else is holding your keys.
Found a security issue? Report it to the address in our Privacy Policy. Responsible disclosure is taken seriously.
Backup
The second thing you need
The person reading this page is one scroll from the second thing they need: a backup that survives a lost phone. Twelve words, a 13th, and split shares.
Read the recovery page →
Get the app
The warnings above are on from the first run. Not available to download yet.