How wallet security works
Your Oddeon login and your wallet credentials do different jobs. Signing in opens your account. It does not, by itself, allow someone to export a key, change wallet permissions, or replace your passkey.
Account login and wallet authorization
Section titled “Account login and wallet authorization”There are four separate layers:
| Control | What it does |
|---|---|
| Account login | Identifies you and opens your account. |
| Wallet passkey | Authorizes sensitive wallet actions, including exports, permission changes, and credential rotation. |
| Recovery credential | Lets you replace a lost passkey and restore access to one wallet. |
| Wallet policies | Limit the transactions Oddeon’s platform signer is allowed to authorize. |
This separation matters: access to an account session is not enough to approve a passkey-protected change.
How a wallet is created
Section titled “How a wallet is created”Each wallet has its own Turnkey security boundary, backed by secure hardware. Setup also creates two credentials:
- Passkey: stored by your device or passkey manager. The private part is not sent to Oddeon.
- 12-word recovery credential: created in your browser. Oddeon receives the public key, not the words themselves.
If you create several wallets, each gets its own passkey, recovery words, and policies. A credential for one wallet cannot authorize another.
What Oddeon can sign
Section titled “What Oddeon can sign”Oddeon uses a platform signer to keep routine actions fast. That signer does not own the wallet and does not have open-ended access. Turnkey allows only the actions covered by the wallet’s current policies; everything else is denied.
You can use those policies to restrict:
- Trading: enabled venues and a rolling daily limit.
- Withdrawals: allowed destination addresses and a rolling daily limit.
- Bridging: the supported bridge destination and maximum amount.
- Deposits: inbound deposits do not require a wallet signature.
Your passkey is required to change these settings. Oddeon records the choices for display, but Turnkey enforces them when a signature is requested. A database change on its own cannot expand the signer’s authority.
Sensitive actions
Section titled “Sensitive actions”For a sensitive action, Oddeon first prepares the exact request. Your browser then asks for the right credential. The approved request must match what Oddeon prepared, expires after a short time, and can be submitted only once.
Examples include:
- Changing wallet permissions or limits.
- Exporting a wallet key.
- Replacing a passkey or recovery credential.
- Completing wallet recovery.
Read the prompt before approving. If you did not start the action, cancel it.
Wallet imports and exports
Section titled “Wallet imports and exports”Importing a wallet
Section titled “Importing a wallet”You enter the key inside Turnkey’s import window, where it is encrypted before leaving the browser. Oddeon receives only the encrypted bundle, never the readable key. The imported wallet then gets the same passkey, recovery, and policy controls as a new wallet.
Exporting a wallet
Section titled “Exporting a wallet”Exporting requires your passkey. Turnkey decrypts the key for you inside its protected browser interface; the readable key does not pass through Oddeon’s backend. Recovery words cannot directly approve an export.
Export only on a trusted device. Once the key is visible, protecting it is your responsibility.
Passkeys and recovery
Section titled “Passkeys and recovery”The passkey has the highest authority over its wallet. Protect the device or password manager that holds it with a strong unlock method.
If the passkey is lost, the 12 recovery words can replace it. Oddeon then creates new recovery words, invalidating the set you entered during recovery.
Recovery words cannot directly sign a trade or withdrawal, export the wallet, or edit its policies. They can replace the passkey, however, which makes them just as important to protect. Keep them offline and separate from the device that holds your passkey.
Oddeon sends notifications for credential changes and other sensitive events. If you receive one you did not expect, act immediately.
What this model does not prevent
Section titled “What this model does not prevent”These controls cannot protect a wallet if you approve a malicious request or expose multiple credentials. Keep control of:
- The device or passkey manager holding your passkey.
- Your 12-word recovery credential.
- The email or identity provider connected to your account.
- Any private key after you choose to export it.
Never share a private key, recovery words, passkey backup, password, or one-time code. Oddeon support will not ask for them.
Before confirming a sensitive action
Section titled “Before confirming a sensitive action”- Verify that you are on app.oddeon.xyz.
- Read the action shown in the confirmation prompt.
- Check the wallet, destination, network, token, amount, and permission limits.
- Cancel if the request appeared after an unexpected link or message from someone claiming to be support.
- Avoid wallet recovery, import, or export on a shared or untrusted device.
If you suspect compromise
Section titled “If you suspect compromise”- Stop trading and do not approve new requests.
- Secure the email or identity provider connected to your account.
- From a trusted device, review active sessions, wallet permissions, and recent activity.
- Contact Oddeon support at support@oddeon.xyz.
Support can work with public wallet addresses, transaction hashes, order IDs, and approximate times. Keep every secret credential private.