Every mobile wallet
ships OTA. None verify on-chain.
The 2022 Slope hack started with a compromised app bundle — $8M drained, thousands of wallets. OTA is a wider vector. We built the first on-chain verification layer: a Rust SDK that checks every bundle hash against a smart contract before it runs. Open source. Free.
Shipped
proof
Built with
A real attack. A structural fix.
One open source primitive.
OTA supply-chain attacks on wallets are not a future risk — they have already happened. We built the fix as a free open source Rust SDK, then shipped it in a real wallet (Coin) to prove the architecture works. Managed signing and audits are available for teams that want help going live.
The attack takes 3 minutes. The damage is permanent.
Attacker breaches CI/CD. Injects one line into the JS bundle. Pushes to CDN. Every user downloads it silently on next open. Seed phrases exfiltrated. This isn't theoretical — the 2022 Slope wallet hack started exactly this way. $8M drained. One update. Zero warning.
The fix: hardware wallet as final gatekeeper.
Before any update runs, the Rust verifier hashes the bundle and queries the on-chain registry. If the developer's hardware wallet didn't sign that exact hash — the update is rejected silently. The attacker owns your CI/CD, your CDN, your signing server. They don't own your Ledger.
Free SDK. MIT licensed.
Open source Rust crate on crates.io. Integrate in a weekend. React Native JSI wrapper included. Free forever.
Managed signing for teams.
Don't want to run your own multi-sig quorum? We operate it. Sub-5-minute publish. 99.9% SLA.
Crypto wallets only.
Not a general security firm. Every line of code we write protects users who hold real funds.
We built it ourselves first. Then open sourced it.
Coin is a fully functional non-custodial wallet with on-chain OTA verification running in production. We built it to prove the architecture ships — not just in theory. The full source is open. Audit every line before you integrate ours.
Who we build for
You don't get a second chance
when users' funds are gone.
Start with the free SDK. If you want velm to manage the signing infrastructure, we're available for a 30-minute call to scope it. No funnels. Directly to Divyam.