Skip to main content

How Quick Login keeps your recovery phrase safe

Your recovery phrase is generated on your device and encrypted before it ever leaves it. Solflare never receives or stores a readable copy of it — here's how that's enforced, not just promised.
​

The backup key is split three ways
​

Your recovery phrase is encrypted with its own random key — one that's never derived from your passcode. That key is then split into three separate parts using Shamir's Secret Sharing, a battle-tested cryptographic method. Any two of the three parts can rebuild the key. One part alone rebuilds nothing.

  • One part stays on your device

  • One part is stored in your own Google Drive or iCloud, alongside the encrypted backup

  • One part is held by Solflare

No single party — not Solflare, not your cloud provider — holds enough on its own to open your backup.
​

Your encrypted backup lives in a private part of your cloud account
​

The encrypted backup isn't sitting in your regular Google Drive or iCloud files where you'd browse it. It's stored in the reserved area your cloud account keeps for apps to save their own data — the same kind of space WhatsApp uses to back up your chat history, for example. You won't see or open it from the normal Drive or iCloud app.

Solflare bundles everything needed to restore your wallet into one encrypted package: your recovery phrase(s), private key(s), and your wallet order, names, and backgrounds. Bundling it all together is what lets everything come back in sync, neatly, whenever you restore or add a new device.

Your passcode is checked without ever leaving your device

When you unlock a cloud backup, the process that checks whether your passcode is correct is itself encrypted end to end — your passcode is never sent to, or stored on, Solflare's servers in a readable form. Solflare cannot look up or recover your passcode, because Solflare never has it in the first place.
​

What happens if something is breached

  • Someone steals a copy of your cloud files. They get an encrypted backup and one key part — nothing in those files can be used to test passcode guesses offline. Without the encrypted check described above, there's no way to turn a guessed passcode into a working key.

  • Solflare's database is breached. An attacker gets one key part and account bookkeeping — not your encrypted backup, and not your phrase. One part alone rebuilds nothing.

  • Someone takes over your cloud account. They'd have your encrypted backup and its key part, and could attempt to sign in to Solflare. Passcode guesses from there are rate-limited, with each wrong attempt adding a progressively longer wait before the next one.

What Solflare actually stores
​

To be specific about what "Solflare never sees your phrase" means in practice, Solflare's servers hold:

  • Login info — your provider, account ID, and email — used to sign you in

  • One of the three key parts (encrypted)

  • A record used to verify your passcode is correct, without storing the passcode itself

None of this is your recovery phrase, and none of it is enough on its own to reconstruct your wallet.
​

What happens when you disconnect Quick Login
​

Disconnecting Quick Login is permanent. Here's what happens:

  • Your cloud backup itself is deleted, including the key part stored alongside it in your cloud account.

  • Solflare's part of the backup decryption key is deleted immediately. Since rebuilding the backup needs at least two of the three key parts, this means the backup can never be reconstructed again, even if a copy still exists somewhere.

  • Quick Login is also disconnected on any other device signed in with the same Google or Apple account.

  • Your wallet stays exactly as it is on any device where it's already been imported or restored. Disconnecting never touches the wallet itself, only the backup.

This step can't be undone, so you'll need to type your passcode to confirm it (biometrics aren't accepted here). It helps to already have your recovery phrase(s) and any private key(s) safely stored elsewhere before you disconnect.
​

Good to know

  • If you lose access to both your Google/Apple account and your passcode, Solflare cannot recover your wallet for you — this is what keeps it self-custodial.

  • Using Quick Login day-to-day still just means knowing your passcode — the same passcode you already use to unlock the app, nothing extra to remember.

  • Losing access to your cloud account loses your backup, but any wallet already imported or restored on your devices keeps working normally.

Did this answer your question?