Skip to content
Onchain Daily

Protocol-level crypto news, daily

Shared Computers Change the Wallet Threat Model

A shared computer can expose a hot wallet through saved browser state or keylogging; use a separate device, or keep signing keys on a hardware wallet.

Onchain Daily Newsroom4 min read

Cover artwork for Shared Computers Change the Wallet Threat Model

To protect a crypto wallet on a shared computer, avoid unlocking a hot wallet there; the operating system and browser can expose its session even when the blockchain never reveals its private key. A self-custody wallet signs transactions with keys controlled by the user, but the computer displays the request and passes it to the wallet. Anyone who can monitor that machine may capture credentials, alter what appears on screen, or reuse an unlocked wallet.

What can a shared computer expose?

A shared computer can expose both wallet secrets and the session used to access them. A browser extension may store an encrypted wallet vault in a browser profile. Its password protects the vault while locked, but it does not protect an active session from a compromised operating system, screen monitoring, or a keylogger. A person using the same account may also be able to reopen the browser profile, inspect saved data, or use an extension that was installed without your knowledge.

Typing a Secret Recovery Phrase or private key on that machine creates a more direct risk: malware can record keystrokes, and clipboard monitoring can capture copied secrets. A wallet password is not a replacement for the recovery phrase. Anyone who obtains the phrase can restore the wallet elsewhere and sign transactions without access to the original computer.

Separate browser profiles reduce accidental mixing of cookies and extensions, but they are not a security boundary against an administrator or malware with access to the computer. A separate operating-system account is stronger for keeping ordinary files and browser data apart, yet it still cannot make an untrusted machine safe from system-level monitoring. When a DeFi action requires a wallet signature, the interface and the key have different roles; Byreal’s swap and liquidity options explains that side of the workflow.

How should I use a wallet on a computer other people use?

Use a device you control for transactions that involve meaningful funds. For a brief, unavoidable session on a shared machine, use a hardware wallet so the signing keys remain on the device rather than in the computer’s wallet extension. The computer can still present a malicious transaction or mislead you about its contents, so confirm the destination, amount, network, and requested permissions on the hardware wallet’s display before approving.

For a hot wallet session, start with a browser and operating system you trust and that are up to date. Check the wallet extension and its permissions, and open the wallet’s intended site or extension directly rather than following an unexpected prompt. Do not install a wallet, “security” tool, or browser extension at another user’s request. Never enter a recovery phrase to unlock a wallet or approve a transaction; a phrase is for wallet recovery, not routine use.

  • Prefer your own device and your own operating-system account.
  • Keep a recovery phrase offline and never type it into a shared computer.
  • Use a hardware wallet for signing when the computer is shared or less trusted.
  • Review each transaction and signature request on the signing device before approval.

When finished, lock the wallet, disconnect the hardware wallet, sign out of accounts, and close the browser. Remove any downloaded files or temporary wallet data you created. These steps limit casual access to an open session, but clearing browser history or using private browsing does not remove malware or erase data captured during the session.

What if I already unlocked my wallet there?

If the computer may be compromised, treat the wallet session as exposed and stop signing transactions on it. From a trusted device, check the wallet for unauthorized transactions and review token approvals or other permissions granted to contracts. A wallet lock ends the current unlocked session, but it cannot undo a transaction already signed and confirmed on-chain.

If you entered a recovery phrase or private key on the machine, assume that secret may be copied. Create a new wallet with a new recovery phrase on a trusted device, then move assets to it. Do not import the old phrase into another browser on the same computer: that repeats the exposure. If only the browser was used and the phrase remained offline, the risk is lower, but there is no reliable way to prove that a shared computer was clean after the fact.

The practical rule is to separate the interface from custody: use a trusted computer to prepare and inspect a transaction, and keep valuable signing keys off a shared machine. A hardware wallet reduces the chance that computer access alone gives someone control of funds, while careful review on its screen addresses the remaining risk of a deceptive signing request.