Security

Security you can verify.

Nova is a self-custody wallet built on one premise: trust should be proven, not promised. Secret material is isolated at input, every release is reproducible from public source, and nothing leaves your device that you did not explicitly sign.

0telemetry or analytics endpoints shipped in the binary
100%of release artifacts reproducible byte-for-byte from source
8exploit classes screened by Nova Shield before every signature
8/8exploit classes

Engineered to be checked, not believed

Each control below is enforced in code and auditable in the public repository — including the absence of the things we claim not to have.

Air-gapped input context

Recovery phrases and private keys are entered into an isolated input context that shares no state with dapp or rendering layers. Secret material never reaches the DOM, the clipboard, or any network-capable code path.

Zero telemetry

No analytics SDKs, no crash beacons, no device fingerprinting. The release binary contains zero outbound telemetry endpoints — verifiable in source and observable on the wire.

Reproducible open-source builds

Every release is built deterministically from public source with signed provenance. Rebuild locally and compare SHA-256 hashes against the release manifest — the binary you run is the code you read.

Nova Shield pre-sign checks

Before you sign, Nova Shield simulates the outcome locally and screens the request against signed threat lists — unlimited approvals, drainers, honeypots and lookalike addresses are flagged in plain language.

Per-chain key isolation

Keys are derived and scoped per chain in separate keystores. A compromised contract or integration on one network has no path to key material belonging to another.

Memory-zeroed buffers

Secrets live only in locked, non-pageable buffers that are overwritten the moment they are no longer needed. Locking the wallet zeroes every byte — nothing survives for swap files, crash dumps or forensic recovery to find.

FAQ

Direct answers

Does Nova ever see my recovery phrase?

No. Your phrase is entered through the air-gapped input context and held only in a locked memory region that is zeroed on lock. It is never written to disk, transmitted, or logged — there is no code path that could send it anywhere. You can confirm this in the source.

What happens when I connect to a dapp?

Nova exposes only your public address and chain ID, then relays signing requests. Every request is decoded by Nova Shield and shown in plain language — what is being approved, for how much, and to whom — before you commit. A dapp receives signatures only when you explicitly approve; it never touches your keys.

How does Nova Shield decide what’s risky?

Deterministic on-device checks plus cryptographically signed threat lists: approvals with unlimited spend, setApprovalForAll to unverified contracts, known drainer addresses, honeypot bytecode patterns, and lookalike-address poisoning. Evaluation runs locally — the lists are data, not a remote kill switch.

Can I verify the build myself?

Yes. Clone the repository, run the deterministic build, and compare the SHA-256 hash of your output against the signed release manifest. Build provenance is published with every release, so the artifact in the store can be traced back to an exact commit.

What data leaves my device?

Only what the networks require: signed transactions and the RPC reads needed to fetch balances and state, sent to endpoints you can inspect and change. No analytics events, device identifiers, or usage metrics — if you block our domains entirely, the wallet still works.

Network

Every chain, live

Nova speaks to 120+ networks. This is what on-chain activity looks like right now — blocks ticking, gas moving, transactions settling.

Verify, then trust.

Read the code, reproduce the build, watch the wire. Nova is designed to survive that scrutiny.

Connect wallet Read the security model