Decentralise · Wallets & Digital Assets

A wallet is a key-management problem wearing a product interface

User-facing wallet, portfolio and transaction experiences across mobile and web. The interface work is real, but the decisions that matter are custody, recovery and what the product does at the moment an action becomes irreversible.

What the work covers

Custody model

Custodial, non-custodial or multi-party. The choice determines your regulatory position, your support burden and what happens on the worst day, so it is decided first and deliberately.

Key management and recovery

Generation, storage, backup, rotation and the recovery route for a user who has lost a device. Recovery design is the difference between a product and a trap.

Portfolio and transaction views

Balances, history, valuations and statements that reconcile, presented so a person can understand their own position without a block explorer open beside it.

Transaction safety

Confirmation design, simulation, address verification, spending limits and approval flows. Most user losses are authorised by the user, which makes this an interface problem.

Integration points

On and off ramps, exchanges, price sources, identity checks and the accounting systems that eventually have to agree with what the wallet says.

Mobile and web delivery

Native iOS and Android and web interfaces, with secure local storage, biometrics and the device-level behaviour these products depend on.

Four design principles

Written from the failure modes, not from a style guide

Irreversible actions need friction

A transfer cannot be recalled. The interface should be hardest at exactly the moment a mistake becomes permanent.

Recovery is a product feature

Not a support process. Design it before launch, and design it for the least technical person who will hold the app.

Show what will happen

Simulate and state the outcome before signing, in ordinary language. Approval screens that nobody can read are consent in name only.

The books have to agree

Whatever the wallet shows must reconcile with the chain and with your finance records. Three versions of a balance is an incident waiting for an auditor.
The decision that shapes everything

Custody is not a technical preference

Holding a user’s keys makes recovery straightforward and places you in a position of responsibility with consequences well beyond engineering. Not holding them removes that position and removes the safety net at the same time. Multi-party approaches sit between the two and bring their own operational obligations.

None of those is right in general. The right one follows from who your users are, what they are holding, and what your organisation is prepared to be accountable for. Where the answer carries a regulatory question, that belongs with your advisers rather than with us.

Usually part of a larger product

Wallet and portfolio functionality is frequently one surface of a wider financial or platform programme: accounts, planning, reporting, administration and adviser tooling across mobile and web, with the digital-asset capability sitting alongside conventional features rather than in a separate application.

That is engineering work in both practices at once, which is a large part of why they sit in one firm.

FAQs

Questions worth answering

What is the difference between a custodial and a non-custodial wallet?

In a custodial model the operator holds the keys and can act on the user’s behalf, which simplifies recovery and support but places the operator in a regulated position of responsibility. In a non-custodial model the user holds the keys, which removes that responsibility and removes the safety net with it. Multi-party approaches sit between the two. The choice is a risk and operating decision and should be made before the product is designed.

What is the hardest part of building a wallet?

Recovery and transaction safety, not the chain interaction. A wallet is a key-management system with a product interface on it: what happens when a user loses a device, and how clearly the interface communicates an irreversible action before it is signed, determine whether the product is safe to use.

Can a wallet be part of a wider product rather than a standalone app?

Yes, and frequently it should be. Wallet, portfolio and transaction functionality is often one surface of a larger financial or platform programme across mobile and web, with the digital-asset capability sitting alongside conventional account, reporting and administration features rather than in a separate application.

Building something that holds value?

Tell us who holds the keys, what a user does when they lose their phone, and what the product shows them before they sign. Those three answers set the architecture.