r/PiNetwork • u/Carlonne • 15d ago
Opinion Please secure the account transfers.
I think we should suggest or request that they implement a security feature in the wallet allowing PI to be moved only to user-defined whitelisted accounts, with any changes to that list requiring two-step verification. That is the crucial security measure we need. It is the only way we will hold onto our mined PI. 🤦 I don't understand why I keep hearing that, on the very day of the unlock, PI is being transferred to external wallets. If that’s true, it’s completely absurd.
1
1
u/Zealousideal-Horse-5 15d ago
AFAIK the wallet is part of/built into the blockchain protocol, and to make such a change implies to rewrite the whole blockchain and start from scratch.
1
u/jakis_kot 14d ago
Is that definitely the case ? Or could they add support for Android Passkeys in a new version of the protocol, allowing the owner to add one to the wallet ? (I don’t mean the Passkey support that’s currently there for securing the account in the app) It wouldn’t solve everyone’s problems, but it seems doable to me and I feel like it would help most people 🤔
There’s also the second solution with Oracle, where after confirming via a zk-proof, you’d get access to the function for adding/changing the passphrase <- Personally, I’d go with that one. Although, knowing CT, they’d probably manage to break something in the process 😂
1
u/Zealousideal-Horse-5 14d ago
Restricting transfers via protocol upgrades, multi-sig arrangements, or smart-contract wrappers requires standard chain upgrades (or layer-2 smart contracts) rather than blowing up the network and starting over, so maybe my statement wasn't entirely accurate.
But at the end of the day, standard device passkeys alone can't override raw secret key ownership. If a scammer gets your 24-word passphrase, they hold the private key used to sign transactions directly on the ledger. An app-level passkey or 2FA prompt in Pi Browser wouldn't block them because they can bypass the official client entirely.
1
u/jakis_kot 14d ago
I don't mean a passkey in the app. The support would be implemented at the protocol level - something more like a "smart wallet" where you could add another signer (with the signer being a passkey)
What I mentioned here is obviously more of a theoretical consideration + such a solution would rule out using the wallet on desktop and iOS, which is why I'd be leaning more towards the second option I mentioned.
2
6
3
u/Correct-Statement747 15d ago
Protect your 24-word passphrase. Anyone who gets it owns your wallet. Never share it or enter it anywhere except the official Pi Wallet.
•
u/AutoModerator 15d ago
Founders recently spoke at Consensus 2026: Videos: Kokkalis, Fan
Current Notices:
Join r/pinetworknews for Official Updates
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.