Kache logoKache

Security Model

Kache is non-custodial: you hold the keys, and no server can move your funds. Here's what that means in practice.

Keys stay on your device

  • Your recovery phrase and private keys are generated on your device.
  • They're encrypted with your password and stored locally, they never leave the device or touch a Kache server.
  • Signing happens locally. A connected dApp or website only ever receives an address, a signature, or a broadcast transaction, never your keys.

No accounts, no tracking

Kache has no sign-up, no email, and no custody. There's no account to be breached because there isn't one.

Locking

Kache locks after a period of inactivity and requires your password to unlock. Lock it manually any time from the home screen.

Connecting to dApps

On the L2s, Kache exposes a standard EIP-1193 provider so dApps can request connections and signatures. Every sensitive request is origin-checked and shown to you for approval, you're always the one who confirms.

Approving a transaction or signature authorizes real actions. Only connect to sites you trust, and read what you're signing.

Transparency

Kache's code is published on GitHub so you can see what the wallet does. It is released under a license that reserves our rights, so the source is available to review but not to reuse or fork.

Your responsibilities

Self-custody puts you in control, and in charge of your backups. Read Your Recovery Phrase to keep your funds safe.