Account recovery

Regain control without surrendering secrets.

Recovery must replace identity authority through a verified policy. This page never asks for a seed phrase, private key, email code, or sensitive evidence.

Recovery service unavailable

Recovery sequence

A new root needs more than a familiar screen.

  1. Resolve the current policy

    Read the signed threshold, delay, delegates, and revocation epoch.

  2. Collect authorized proofs

    Use only the methods named by that policy; never improvise secret collection.

  3. Finalize and verify rotation

    Confirm the replacement root and invalidate authority from the prior epoch.

No recovery started

Secret entry is intentionally absent.

Until recovery-policy reads, authorized proof verification, transaction simulation, explicit confirmation, and finality checks are wired, no recovery request can be created.

Never share

Seed phrases stay offline

No legitimate recovery screen should ask a person to paste a wallet seed phrase.

Delay

Time to stop an attacker

High-risk rotations need visible delays and a current-root cancellation path.

Epoch

Old delegates expire together

A completed root rotation invalidates authority minted under the previous epoch.