The screens that say no.

A wallet's real job is refusing the transaction you would have regretted. Here is every refusal Smartable is capable of, and the ones it is not.

01

The key itself

How the hit usually lands

Most thefts never touch the cryptography. They take keys off a server that never needed to hold them, or off a phone that was not locked.

What Smartable does

Keys are generated on your device, held in the platform keystore, and never transmitted. There is no Smartable account, so there is nothing of yours on our servers to lose. A PIN, biometrics, unlock throttling, and spend limits guard the device itself, and the app switcher is dimmed on iOS. One honest limit: the app does not block screenshots on iOS, because iOS has no API for it.

02

The address that looks right

How the hit usually lands

An attacker sends you dust from a lookalike address that matches the first and last characters of one you trust. It sits in your history until the day you paste the wrong one.

What Smartable does

Smartable flags lookalike and poisoning-pattern addresses in your history and warns you before you send. The second layer is a trusted-address book and recipient history, so the address you meant is the one you pick — not the one an attacker planted.

Smartable history view flagging a lookalike address warning
The warning you see before a lookalike address costs you.
03

The token that isn't the token

How the hit usually lands

Fake USDC, dust airdrops, and copycat contracts land in your wallet uninvited, each hoping you open a link, approve a contract, or trade the imitation.

What Smartable does

Spam and fake tokens are filtered out of the wallet view. Real assets carry a blue verified mark, which means exactly one thing: we checked this contract address. It does not mean the issuer is reputable, the token is safe, or the price is real — a verified mark is identity, not evidence.

04

The approval you forgot

How the hit usually lands

A dApp asks for permission to move your tokens, and most wallets hand over the whole balance. Months later, a contract you forgot about is exploited — and the allowance is still open.

What Smartable does

Smartable grants approvals for one trade, not the balance. Every approval is logged, and you can review and revoke any of them from Settings. Reviewing and revoking is a fee-free feature, not an upsell.

05

The site pretending to be a dApp

How the hit usually lands

A cloned site or a poisoned ad leads you to connect your wallet and sign something that drains it. The page looks right; the signature is not.

What Smartable does

Connections are checked against phishing lists before anything connects, permissions are granted per site and can be withdrawn per site, and the review screen decodes the calldata into plain language instead of showing you a hex blob.

What we do not claim

The refusals we are not capable of.

  • No third-party security audit yet. 3,541 automated tests run on every build, but a test suite is not an audit and we will not call it one.
  • No insurance. If funds are stolen, there is no policy that pays out and no fund that makes you whole.
  • No recovery service. If the phrase and every share are gone, so is the money. Any wallet that says otherwise is custodial — someone else is holding your keys.

Found a security issue? Report it to the address in our Privacy Policy. Responsible disclosure is taken seriously.

Nothing on this website constitutes investment, financial, legal, or tax advice. All information is provided for informational purposes only. Smartable Wallet is non‑custodial, self‑custody software; you are solely responsible for your own decisions and for securing your private keys. Digital assets are volatile and can lose value. Past performance is not indicative of future results. Please view our Terms of Use for more information.

© 2026 Smartable™. Self-custody means you are responsible for your own keys. Non-custodial. Your keys never leave your device.