How sign-in keeps you safe
What you sign
A plain text message that names this site, your address, a one-time code and an expiry. It is the EIP-4361 (Ethereum) or Sign-In With Solana standard. Signing it cannot move funds, approve tokens or interact with a contract. If a wallet ever shows a transaction or an approval during sign-in, reject it.
What we store
Your wallet addresses, a handle, an optional display name and label per wallet, a coarse device label per session (browser and operating system) and a 30-day log of sign-ins. We do not store email addresses, IP addresses (only a salted daily hash used for rate limiting), or anything from your wallet beyond the address. You can download or delete all of it from your account page.
How the session works
Signing in sets a short-lived, HTTP-only cookie for cryptoopsec.com and its subdomains, so every CryptoOpsec app recognises you without asking again. It is renewed silently from this site and ends when you sign out, from any app, on this device or everywhere.
Good habits
- Use a hot or fresh wallet for signing in; it needs no balance.
- Check the domain in the message is
accounts.cryptoopsec.com. - Link a second wallet so you can still sign in if you lose one.