Security & Privacy
Security & Privacy help and FAQs from Moneda on your self-custody account, stablecoins, transfers, security, and AI agent.
Yes, Moneda is designed with security as our top priority. We employ industry-leading practices and technologies to ensure your assets and personal data are protected at all times. Here’s how Moneda keeps you safe:
- Blockchain Security: Moneda runs on the Base Network. This means your transactions benefit from Ethereum's robust security infrastructure while maintaining high efficiency.
- Data Protection: All identifiable user data is encrypted at REST, ensuring it remains private and secure from unauthorised access.
- Passkeys: To strengthen account security, Moneda supports passkeys, an advanced authentication method that replaces traditional passwords with cryptographic keys. This approach offers greater protection against phishing and unauthorised access while ensuring a seamless login experience.
- Regulatory Compliance: Moneda adheres to strict regulatory standards in Europe, including GDPR and Travel Rule, to safeguard your privacy and ensure transparency in how your data is handled.
- Continuous Monitoring: Our systems are continuously monitored for suspicious activities or vulnerabilities, allowing us to respond proactively to potential threats.
Passkeys are a new secure and phishing-resistant authentication method that replace traditional passwords. They are cryptographic keys stored on your device or password manager, enabling seamless and secure logins without the need to remember complex passwords. Passkeys work with biometric authentication (like Face ID or fingerprint scanning) or a device PIN to verify your identity.
We recommend using iCloud Keychain on Apple devices or Google Password Manager on Android and Chrome for the best cross-device compatibility. We also recommend using a general password manager like 1Password to store the passkeys. These services ensure that your passkeys are encrypted and synchronized across your trusted devices, making authentication easy and secure.
Here are some general recommendations for managing your Moneda passkey:
- Never delete your passkey for your Moneda Account, or you risk losing access to your funds.
- Use a cloud-based passkey manager like iCloud, Google Password Manager, or Microsoft Cloud, or 1Password to ensure you have cross-device accessibility to your Moneda account and passkey.
- Avoid bulk clean ups of passwords and passkeys.
- When using Google Chrome Profile as a passkey, never check Passwords and Passkeys in the Advanced tab when clearing any browser data history.
- When using a hardware device such as Yubikey, do not clear or reset your keys or you will lose access to your wallet.
- Google Chrome Profile, Brave profiles, and other browser based passkeys are typically device specific. We recommend using a cloud-based passkey provider whenever possible.
Yes, if you utilize a password manager such as iCloud Keychain, Google Password Manager or 1Password, you can use the same passkey on any device that also has access to your iCloud, Google or 1Password accounts. Certain passkey providers, such as Chrome Profile are device specific and will not work across platforms.
If you lose a device with your passkeys and have used a password manager, you can still access your Moneda account from another trusted device where your passkeys are synchronized. Simply log in using your password manager and continue authentication as usual. If your passkey was only ever stored on the lost device, you may need to recover access by using the exported key generated through Moneda’s account recovery process, and then set up a new passkey on your replacement device.
On iOS
- Open your device Settings.
- Navigate to Passwords.
- Search for auth.moneda.com, select the Moneda passkey named with the appropriate date the passkey was created. • You can view, rename, or delete your passkey here. On Android devices
- Open device Settings.
- Go to Passwords & Accounts.
- Select Google
- Select Google Password Manager under the corresponding user profile.
- Search for auth.moneda.com, select the Moneda passkey named with the appropriate date the passkey was created.
- Open the 1Password App
- Search for auth.moneda.com , select the Moneda passkey named with the appropriate date the passkey was created.
Passkeys don’t require traditional two-factor authentication (2FA) because they inherently provide strong security guarantees. They use cryptographic authentication that binds your credentials only to your device and require biometric verification or a PIN. Since passkeys cannot be phished or stolen remotely, they eliminate many of the vulnerabilities associated with passwords and traditional 2FA methods.
Moneda is a fully self-custodial platform, meaning Moneda does not hold, manage, or maintain your funds in any way. Here’s how it works and why this approach is unique and beneficial for you:
- You Own Your Assets: With Moneda, only you have access to your funds because you hold the private keys to your account. Unlike traditional banks or custodial services, we cannot access your money.
- No Middlemen: Your funds are stored securely on the blockchain, a decentralised financial infrastructure that ensures you are the sole owner and controller of your money.
- Access Anytime, Anywhere: Since funds are stored on the blockchain, they can be accessed instantaneously through Moneda, as long as you have your device and private keys to sign into the app.
Using Moneda is not exempt of risks. Unforeseen events can always happen, but they are extremely unlikely. Moneda is designed to prioritise your safety
- Price stability: Your funds are held in stablecoins, pegged to assets like the Euro or US Dollar, reducing price volatility and providing stability.
- Self-custody: We use blockchain technology on the Base Network to secure your assets. As a self-custodial platform, you retain full control of your funds, eliminating reliance on middlemen who could pose security risks.
- Social Recovery: You can recover access to your account with the help of Recovery Contacts in case you lose access to your Passkey.
- Reliable systems: Third-party hacking or issues with the Base Network, its rigorous audits and strong track record make such events highly unlikely.
- High security: By securing your own private keys via passkey authentication, you can confidently manage your funds, knowing your safety is our highest priority.
While Morpho and YO introduce safeguards for the Earnings and Smart Earnings accounts on Moneda, potential risks include:
- Losses due to smart contract vulnerabilities or exploits.
- Stablecoins de-pegging from their corresponding fiat currency.
- Temporary unavailability of funds during extreme liquidity shortages.
- Extreme Market events where liquidated collateral is insufficient and the Reserve Factor is exhausted. → These risks are low for stablecoin lending but still exist.
No, funds held in Moneda are not insured by the Deposit Guarantee Scheme (DGS) in the EU or the Federal Deposit Insurance Corporation (FDIC) in the United States. These protections apply to traditional bank accounts. Moneda operates as a self-custodial platform, meaning your funds are held in digital currencies that are pegged to the corresponding asset, stablecoins. These stablecoins (such as USDC and EURC) live on the blockchain rather than in a traditional bank. These stablecoins are issued by reputable providers with robust reserves, ensuring transparency and security. However, they are not covered by government deposit insurance programs.
Moneda prioritises user privacy by implementing security measures that protect your personal information. While blockchain transactions are publicly recorded, Moneda does not store personally identifiable information on the blockchain. Any data stored by Moneda, such as email addresses or device information, is fully encrypted in our database and protected using industry-standards and best security practices.
Moneda operates on blockchain technology, which means that transactions and balances are recorded on a public ledger. While your personal identity is not directly linked to your account, your account address allows anyone to view your balance and transaction history. This concept, known as pseudo-anonymity, means that while identities are not explicitly revealed, data analysis techniques or service providers can sometimes be used to link transactions to individuals based on spending patterns, interactions with previously known addresses, or external data sources.
Overall, Moneda Earnings has a generally low risk due to the use of fully regulated stablecoins. However, no investment is risk free. Moneda Earnings has the following risk profile compared other options in the market: • Market risk: Low due to the use of stablecoin • Liquidity risk: Low due to the use of stablecoin vaults with deep liquidity • Credit/default risk: Low due to the use of overcollateralised loans • Inflation risk: Low. Potential earnings can outpace the inflation rate for USD and EUR. • Regulatory risk: Low due to the use of fully compliant stablecoins in the EU (MiCa) • Technology risk: Moderate due to the use of smart contracts. Smart contracts have been fully audited but are not risk free.
For paying merchants, yes: Moneda supports WalletConnect Pay for in-person payments by QR code, approved by you in the app.
Connecting your account to dApps online more generally, to browse, sign messages, or interact with contracts, is not supported yet.
Since Moneda is a self-custody interface, your funds would remain secure and accessible in the event our company shuts down.
Moneda is a fully self-custodial wallet. This means you are the only person who controls your passkey and wallet credentials. Moneda does not store your private keys or passkeys and cannot restore them for you. To reduce the risk of losing access, Moneda offers a self-custodial recovery mechanism using Recovery Contacts (also known as social recovery). You can nominate trusted contacts who are authorised to help you recover access if you lose your passkey. These recovery mechanisms are controlled by your account onchain, not by Moneda.
Social recovery is implemented using a Safe recovery module and works fully onchain. If you lose access to your device or passkey, you initiate a recovery request inside the app and generate a new passkey. Your authorised Recovery Contact must approve the request by signing an onchain transaction. A safety delay (default: 24 hours) applies before finalisation. During this time, you can cancel the process if it was initiated maliciously. After the delay, your new passkey becomes the owner of your account.
Go to Settings > Security > Recovery Contacts. Search for a user by username or name and send an invite. After they accept, you must confirm the setup by signing with your passkey. Only after this confirmation does the contact become an authorised guardian.
Go to Settings > Security > Recovery Contacts and select "Remove myself as Recovery Contact." Once removed, you will no longer be able to initiate recovery for that user.
You should only accept recovery invitations from people you personally know and trust. If you do not recognise the person, decline the invitation.
Log in using Google, Apple, or email. Navigate to Settings > Security > Recovery Contacts and select "Request Recovery." You will generate a new passkey. Your Recovery Contact must approve the request. After the safety delay period, access will be restored.
If you did not set up a recovery mechanism and lose your passkey, you will likely lose access to your wallet permanently. Moneda does not store or recover credentials. For this reason, setting up Recovery Contacts is strongly recommended.
Recovery emails let you get back into your account if you lose your passkey, using an email address you control. When you set one up, Moneda links a recovery method to that email, so later you can prove the account is yours and restore access. Your money never leaves your own self-custodial wallet in the process. Recovery restores your ability to sign; it doesn't move or hold your funds. You can use recovery emails on their own or alongside Recovery Contacts (social recovery). Add or change your recovery email anytime in the app's security settings.
You log in to Moneda with a passkey instead of a password. A passkey lives on your device or in your synced keychain, and you unlock it with your face, fingerprint, or device PIN, so there's nothing to type and nothing to remember. Since it isn't a shared secret that leaves your device, a passkey can't be phished or leaked the way a password can. If your passkey syncs through your Apple, Google, or password-manager account, you can log in on your other devices too. If you lose the device that holds it, having recovery emails or Recovery Contacts set up beforehand lets you get back in. Note that this login passkey is separate from your transaction passkey, which approves payments and other on-chain actions.
It depends on how you sign in. If you use Google or Apple, just sign in again with that account on your new device; there's nothing separate to recover. If you use an email passkey and you've lost it, say you got a new phone or cleared your keychain, you can restore login access through the email address on your account. Moneda sends a one-time code to that email; you enter it to prove the address is yours, then create a fresh login passkey on your current device and sign in with it from then on. Keep in mind this is separate from recovering your wallet. Logging back in gets you into the app, while recovery emails and Recovery Contacts restore your ability to sign transactions and move your funds. If you've also lost access to your account email, use those wallet-recovery methods instead.
Moneda uses two passkeys, and they do different jobs. Your login passkey gets you into your account: it's what opens the app on a device, like a password but safer. Your transaction passkey approves anything that moves money or changes your security, such as sending a payment, withdrawing to a bank, or adding a Recovery Contact. It's the self-custodial key that keeps your funds under your control, and nothing leaves your wallet without it. Keeping them separate means getting back into the app and authorizing money movement are protected independently, and each one has its own way to recover. We use "log in" for the first and "transaction" for the second precisely so the two don't get mixed up.
