Security & Transparency

Verify.
Don't trust.

Check that the ERA Wallet app on your phone is the build we published — signed with our key, on hardware-backed keys, on a locked device. The answer appears here, in your browser. Never inside the app.

Run the check

····-····
 

How it works

  1. 1
    Open ERA Wallet → Settings → Verify app

    Needs the app that came with this feature — version 1.12 or newer.

  2. 2
    Scan this code with the app — or type it inType this code into the app

    The app's scanner reads the QR on the left. Letters and digits only; case doesn't matter.

  3. 3
    Wait for the answer here

    Your phone creates a hardware-backed key bound to this code and sends the attestation to our server. This page shows what was measured.

Getting a code…

Read this before you trust it

What this proves. And what it doesn't.

A genuine install answered this code

That is what a pass means. Not necessarily the phone in your hand: a counterfeit app could relay the code to a real installation elsewhere. The attack costs real effort, but we cannot rule it out — treat a pass as strong evidence, not a guarantee.

The result counts only here

Only this page, on our domain, in the browser you started the check from. Anything the app itself displays is not proof — a fake app can draw a green screen.

“Not confirmed” is not “fake”

Phones without a hardware keystore, custom ROMs such as GrapheneOS, and builds installed outside the stores cannot be confirmed automatically. Compare the signing fingerprint by hand instead — see below.

iPhone: received, not verified yet

iOS answers with Apple App Attest. We record it but do not verify it yet, so an iPhone check reads “not yet verified” for now. Use the App Store / TestFlight source and the bundle id below.

This checks the app, not the wallet

To check the hardware wallet itself, open Settings → Authenticity check in the app: the wallet signs a challenge with its factory key.

One code, five minutes, nothing stored about you

The code is spent on first use. The page never learns which installation answered; the server keeps a summary of the check for an hour and then deletes it.

Check by hand

The facts we publish. Compare them yourself.

Android
Package
io.hwlt.era_sw
Google Play — app-signing certificate, SHA-256
50:1D:9C:28:92:DE:A5:7E:5E:32:43:56:48:42:79:F2:74:A9:47:64:EA:1C:F9:29:50:DA:37:69:44:3F:65:63
Builds we hand out directly (outside Google Play) — SHA-256
9A:95:DB:16:C7:DE:DD:47:40:F2:37:EF:41:E9:BF:8C:FF:78:6D:D7:4C:BE:ED:A8:7F:41:62:3C:56:1F:ED:47

Read the installed app's certificate with AppVerifier on the phone, or with apksigner verify --print-certs app.apk on a computer, and compare the SHA-256 line with the one above. On the genuine listing, Google Play shows Installed.

iPhone
Bundle
io.hwlt.sw
Apple Team ID
PQ4ZD292P5 · HWLT FZE
Distributed only through
App Store and TestFlight — the beta is listed as “ERA SW”

Every iOS build is signed by Apple for our Team ID; an app that arrived any other way is not ours. In TestFlight, open the app's page and check the developer name.