Skip to content
Open Oddeon

How wallet security works

Your Oddeon login and your wallet credentials do different jobs. Signing in opens your account. It does not, by itself, allow someone to export a key, change wallet permissions, or replace your passkey.

There are four separate layers:

Control What it does
Account login Identifies you and opens your account.
Wallet passkey Authorizes sensitive wallet actions, including exports, permission changes, and credential rotation.
Recovery credential Lets you replace a lost passkey and restore access to one wallet.
Wallet policies Limit the transactions Oddeon’s platform signer is allowed to authorize.

This separation matters: access to an account session is not enough to approve a passkey-protected change.

Each wallet has its own Turnkey security boundary, backed by secure hardware. Setup also creates two credentials:

  1. Passkey: stored by your device or passkey manager. The private part is not sent to Oddeon.
  2. 12-word recovery credential: created in your browser. Oddeon receives the public key, not the words themselves.

If you create several wallets, each gets its own passkey, recovery words, and policies. A credential for one wallet cannot authorize another.

Oddeon uses a platform signer to keep routine actions fast. That signer does not own the wallet and does not have open-ended access. Turnkey allows only the actions covered by the wallet’s current policies; everything else is denied.

You can use those policies to restrict:

  • Trading: enabled venues and a rolling daily limit.
  • Withdrawals: allowed destination addresses and a rolling daily limit.
  • Bridging: the supported bridge destination and maximum amount.
  • Deposits: inbound deposits do not require a wallet signature.

Your passkey is required to change these settings. Oddeon records the choices for display, but Turnkey enforces them when a signature is requested. A database change on its own cannot expand the signer’s authority.

For a sensitive action, Oddeon first prepares the exact request. Your browser then asks for the right credential. The approved request must match what Oddeon prepared, expires after a short time, and can be submitted only once.

Examples include:

  • Changing wallet permissions or limits.
  • Exporting a wallet key.
  • Replacing a passkey or recovery credential.
  • Completing wallet recovery.

Read the prompt before approving. If you did not start the action, cancel it.

You enter the key inside Turnkey’s import window, where it is encrypted before leaving the browser. Oddeon receives only the encrypted bundle, never the readable key. The imported wallet then gets the same passkey, recovery, and policy controls as a new wallet.

Exporting requires your passkey. Turnkey decrypts the key for you inside its protected browser interface; the readable key does not pass through Oddeon’s backend. Recovery words cannot directly approve an export.

Export only on a trusted device. Once the key is visible, protecting it is your responsibility.

The passkey has the highest authority over its wallet. Protect the device or password manager that holds it with a strong unlock method.

If the passkey is lost, the 12 recovery words can replace it. Oddeon then creates new recovery words, invalidating the set you entered during recovery.

Recovery words cannot directly sign a trade or withdrawal, export the wallet, or edit its policies. They can replace the passkey, however, which makes them just as important to protect. Keep them offline and separate from the device that holds your passkey.

Oddeon sends notifications for credential changes and other sensitive events. If you receive one you did not expect, act immediately.

These controls cannot protect a wallet if you approve a malicious request or expose multiple credentials. Keep control of:

  • The device or passkey manager holding your passkey.
  • Your 12-word recovery credential.
  • The email or identity provider connected to your account.
  • Any private key after you choose to export it.

Never share a private key, recovery words, passkey backup, password, or one-time code. Oddeon support will not ask for them.

  1. Verify that you are on app.oddeon.xyz.
  2. Read the action shown in the confirmation prompt.
  3. Check the wallet, destination, network, token, amount, and permission limits.
  4. Cancel if the request appeared after an unexpected link or message from someone claiming to be support.
  5. Avoid wallet recovery, import, or export on a shared or untrusted device.
  1. Stop trading and do not approve new requests.
  2. Secure the email or identity provider connected to your account.
  3. From a trusted device, review active sessions, wallet permissions, and recent activity.
  4. Contact Oddeon support at support@oddeon.xyz.

Support can work with public wallet addresses, transaction hashes, order IDs, and approximate times. Keep every secret credential private.