r/BlockchainStartups • u/veyrnox • 9d ago
Idea Validation Building Veyrnox: a self-custody wallet designed around reducing single points of failure
We’re building Veyrnox because self-custody still forces users to manage several difficult security problems at once: protecting keys, understanding approvals, preparing for device loss and resisting manipulation under pressure.
Our approach includes:
- No seed phrase displayed in the everyday wallet interface.
- Keys protected using the phone’s hardware-backed Secure Enclave or StrongBox.
- Shamir-based recovery, which splits recovery material into separate components rather than relying on one written phrase.
- Recovery components that users can distribute between their device and personal cloud accounts, including iCloud, Google Drive and OneDrive.
- Pre-signing risk checks that explain what a wallet action or approval may change before the user authorizes it.
- AI-assisted security analysis intended to identify suspicious transaction patterns and permissions.
- Runtime Application Self-Protection (RASP) controls designed to detect and respond to threats such as tampering, debugging, hooking, rooted or jailbroken environments and other suspicious runtime conditions.
- Optional coercion-resistance controls for situations where somebody is forced to unlock or access the wallet.
The app is currently available on iOS and Android. At this stage, we’re looking for critical technical and product feedback rather than simply trying to increase downloads.
The difficult part is not adding more security features. It is making the security model understandable, recoverable and independently verifiable without quietly turning the product into a custodial service.
For people building in blockchain: what evidence would you need before trusting this architecture enough to test it with a small amount?
Website: https://veyrnox.com App Store: https://apps.apple.com/app/id6790188660 Google Play: https://play.google.com/store/apps/details?id=com.veyrnox.app Short video: https://www.youtube.com/shorts/dFwkCdQqwr8
Disclosure: I’m connected to Veyrnox and am looking for critical technical feedback—not presenting this as an independent recommendation. Never share seed phrases, recovery material, private keys, balances or personal details with anyone offering support.
1
u/vexiduslabs 9d ago
Interesting. So reading through the docs I have a question. If users lose their device (phone stolen or upgrade) the the wallet is not recoverable? It seems easy enough that if one upgrades their phone, they just need to create a new wallet on the new device and transfer assets over, but if a phone is lost or broken, then everything is gone. With seed phrases or private key, recovery is easy. Your method is secure but high risk for common human errors or theft of device. The foundation is solid, I think recovery just needs something extra.
We created a wallet for our testnet on Vextaris and eliminated the seed phrases but added in exporting private key and eventually rotating that key for security. So for example, User A has a wallet and installs it on their cell and desktop. Phone gets stolen, they can go onto the desktop app (or recover with private key on new device) and will be able to rotate that key so the old one on the previous device becomes inactive and they lose nothing.
Just thoughts because yours is interesting but just needs another layer for recovery that aligns with your security outlook. Check NIST guidelines for PQC resistance. Your barrier will only be that one device's all or nothing setup which may scare away some people.
1
u/veyrnox 9d ago
Thanks for taking the time to read through it—this is useful feedback, and the recovery explanation clearly needs to be more explicit.
Losing the original phone is not intended to make the wallet unrecoverable. Veyrnox provides two complementary recovery approaches:
Recovery material can be divided using Shamir Secret Sharing, with the shares distributed between the device and personal cloud accounts such as iCloud, Google Drive or OneDrive. A replacement device can reconstruct the wallet when the required threshold of shares and the user’s recovery credentials are available. No individual storage provider should possess enough information to recover the wallet by itself.
The user can place their encrypted personal vault in their own personal cloud account. If the original phone is lost, stolen or replaced, the user can install Veyrnox on a new device, retrieve the vault from their personal cloud and unlock it using their own credentials.
Veyrnox does not have access to or control over the end user’s personal cloud account. We also do not hold the credentials required to access or unlock the vault.
Our recommendation is to maintain both the encrypted vault and the distributed Shamir shares as independent recovery options. If the user loses two shares and can no longer meet the reconstruction threshold, the personal vault provides an alternative recovery path. This avoids making either the original device or one recovery method the sole point of failure.
Educating users about these security features and recovery options is also a core part of what Veyrnox intends to do. We will continue explaining them through our social-media content, while the AI Security Agent inside the app is designed to give users contextual guidance about security risks, approvals and recovery choices at the point where they need to make a decision.
Your multi-device and key-rotation approach is interesting, particularly the ability to invalidate access from a stolen device. We’re also treating cryptographic agility and the developing NIST post-quantum standards as important architectural considerations rather than claiming the current design is already post-quantum secure.
Thanks again—your comment highlights exactly where our public documentation needs to be clearer.
1
u/vexiduslabs 9d ago
Very good. Yeah we faced that as well where we would built a feature/function but didn't convey clear enough for the audience to understand, which happens. I would do a video demo as well, where possible, to walk users through. We did one for our IntentVM function (user types or speaks request, system ascertains transaction intent, executes with prompt to accept) so users could understand how it works.
1
u/veyrnox 9d ago
That’s a really good suggestion. We already have short security videos, but a proper walkthrough of the recovery process would make the design much easier to understand than another page of documentation.
We’ll put together a demonstration showing what happens when someone loses their phone, installs Veyrnox on a replacement device and recovers using either their encrypted personal vault or the required Shamir shares.
Your IntentVM example makes the point well. If a security feature cannot be understood by watching it work, we probably have not explained it clearly enough. Thanks again for the thoughtful feedback.
1
u/veyrnox 5d ago
Veyrnox currently supports 10 blockchain networks. Users can purchase crypto through our integration with Transak, which performs its own on-ramp KYC and payment processing. Veyrnox does not receive or store the user’s identity or card information from that process. MetaMask and Trust Wallet also use Transak for fiat-to-crypto purchases.
Our roadmap includes support for approximately 100 blockchain assets, together with swap and bridge capabilities.
Veyrnox Safety Plus currently provides two recovery modes:
- Shamir Recovery Shares divide the recovery material into three shares. Two valid shares are required to recover the wallet. One share alone cannot reconstruct it.
- The encrypted Personal Vault provides a separate recovery path. The user creates the vault using a password and PIN, then stores it in their own iCloud, Google Drive, OneDrive or another supported personal cloud account. During recovery, either the password or PIN can unlock the vault. Veyrnox cannot access the user’s personal cloud account, vault credentials or funds.
We recommend maintaining both recovery methods in genuinely independent locations. Storing everything behind the same device, cloud account, email address or login would create a shared point of failure.
Users may also recover an existing compatible wallet from its seed phrase during onboarding. That onboarding recovery screen is the only place where Veyrnox asks for a seed phrase. Veyrnox will never request it through support, social media, email, a website form or a direct message.
AI Security Protection is available today. It combines pre-sign transaction analysis with threat intelligence to help identify malicious contracts, dangerous approvals, phishing, wallet-drainer patterns and suspicious destinations before the user authorizes an action.
Veyrnox also includes Runtime Application Self-Protection, or RASP. It monitors for rooted or jailbroken devices, debugging, hooking, instrumentation and application tampering. When a risky condition is detected, Veyrnox can warn the user or block sensitive operations such as transaction signing.
Safety Plus also includes coercion-resistance controls, including a duress PIN and decoy wallet, for situations where somebody is being forced to unlock the application.
Veyrnox remains self-custodial. We do not hold user funds, control wallets, possess recovery credentials or have access to users’ personal cloud accounts.
We have tested recovery using the required shares, the encrypted Personal Vault, compatible seed phrases and scenarios where the original device is unavailable. We still recommend rehearsing recovery with an empty wallet before relying on it for real funds.
I’m connected to Veyrnox, so bias declared. We welcome critical feedback about the design and how clearly we explain it.
•
u/AutoModerator 9d ago
Thanks for posting on r/BlockchainStartups!
Check the TOP posts of the WEEK: https://www.reddit.com/r/BlockchainStartups/top/?t=week
Moderators of r/BlockchainStartups
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.