Skip to content
Defense-in-Depth

Security & Key Protection Architecture

Explore the controls behind wallet generation: cryptographic randomness, encrypted intermediate storage, and account protection.

INTRODUCING MY WALLET

Your coins.
Your keys. Your next move.

Import an existing private key, check coin and Ethereum or TRON token balances, and send or receive native crypto from your account. Your imported key stays in browser memory; transactions are signed in your browser.

Sign in to open your wallet, or create an account.

Five coins. One wallet workspace.

MAINNET
EthereumETH
TRONTRX
Bitcoin CashBCH
BitcoinBTC
DogecoinDOGE

Native coins only. Use the matching blockchain when sending or receiving; Ethereum and TRON token balances are also displayed; token sending is not supported.

Cryptographic Randomness (CSPRNG)

Keys created by the Wallet Generator are derived exclusively from operating system CSPRNG entropy sources (Linux /dev/urandom via PHP random_bytes(32)). We never use pseudo-random generators, timestamp seeds, or external centralized seed APIs.

Zero Plaintext Key Storage

The database never stores generated private keys. During queue processing, chunk files are protected by authenticated encryption with associated data (AEAD AES-256-GCM / CBC). Once the export file is compiled, all temporary chunk files are deleted from disk.

Admin Isolation Policy

Platform administrators, support staff, and automated monitors are programmatically barred from inspecting user private keys. Admin dashboards show only metadata (quantity, network, progress, error logs).

Anti-IDOR Download Protection

Export files reside outside the public web server directory. Downloads require authenticated session cookies, ownership validation, and expiration verification. Changing an export UUID in the URL results in an immediate 404 and security audit record.

Mathematical Proof

Consensus Algorithm Specification Matrix

Every generated keypair adheres to the exact cryptographic requirements established by protocol creators.

Asset Curve Standard Hash Algorithm Address Standard Key Format
Bitcoin (BTC) secp256k1 SHA-256 + RIPEMD-160 BIP-173 Native SegWit (bc1q...) WIF Compressed (K/L)
Ethereum (ETH) secp256k1 Keccak-256 (SHA-3) EIP-55 Mixed-Case (0x...) Raw 256-bit Hex
TRON (TRX) secp256k1 Keccak-256 + 2x SHA-256 TRC-20 Base58Check (T...) Raw 256-bit Hex
Litecoin (LTC) secp256k1 SHA-256 + RIPEMD-160 Bech32 (ltc1q...) / Legacy (L...) WIF Compressed (T...)
Ripple (XRP) secp256k1 SHA-256 + RIPEMD-160 XRPL Base58Check (r...) Raw 256-bit Hex
Dogecoin (DOGE) secp256k1 SHA-256 + RIPEMD-160 P2PKH 0x1E Base58Check (D...) WIF Compressed (Q...)
Ethereum Classic (ETC) secp256k1 Keccak-256 (SHA-3) EVM EIP-55 Mixed-Case (0x...) Raw 256-bit Hex
Ravencoin (RVN) secp256k1 SHA-256 + RIPEMD-160 P2PKH 0x3C Base58Check (R...) WIF Compressed (K/L)

Critical User Responsibility Notice

BC-Team does not retain backup copies of your exported private keys. Upon downloading your CSV or TXT export file, you must store it in a secure, encrypted offline cold-storage location. If you lose your keys, neither BC-Team nor any blockchain validator can recover your assets.