How Custody Works
Who controls my funds?
Who controls my funds?
You Do — Kash Is Self-CustodialHere’s the actual model:
- When you sign up, a Privy-powered embedded wallet (a standard EOA) is created for you
- That wallet is the signer for an ERC-4337 smart account — the smart account is what holds your funds
- Only your wallet can authorize transactions from your smart account
- Kash cannot withdraw your funds. The platform prepares transactions; they execute only under permissions you authorize
Is there a seed phrase? How does recovery work?
Is there a seed phrase? How does recovery work?
No Seed Phrase to Manage
- Your embedded wallet is secured by Privy’s infrastructure and unlocked by your login — there’s no 12-word phrase to write down or lose
- Recovery: regain access through your login method (X, Google, email, or wallet) plus your recovery email if you’ve set one in Settings
- Independent backup: exporting your key from Settings gives you access to your wallet no matter what happens to your Kash login
How secure is the Kash platform?
How secure is the Kash platform?
Security Model
- Self-custodial wallets: you control your funds; Kash can’t withdraw them — trades execute only under permissions you authorize
- ERC-4337 smart accounts: your funds live in an audited account-abstraction smart account on Base
- Privy wallet infrastructure: enterprise-grade embedded wallet security
- Base network: built on an established Ethereum Layer 2
- Gasless transactions: gas is sponsored via a paymaster, so you never handle ETH for gas
- Multisig-secured contracts: privileged protocol actions require multi-party approval
Account Security Best Practices
How do I secure my Kash account?
How do I secure my Kash account?
Security ChecklistLogin security (most important):
- Enable 2FA on the X or Google account you sign in with
- Use a strong, unique password on your login provider
- Add a recovery email in Kash Settings
- Always verify the app.kash.bot domain before signing in
- Only trust the verified @kash_bot account on X — and only trust a trading account that @kash_bot itself links to
- Review your transaction history and notifications regularly
- If you export your wallet key, store it offline and securely
- Never share your exported key with anyone — including anyone claiming to be Kash support
What happens if I lose my device?
What happens if I lose my device?
Device Loss Recovery
- From another device, change the password on your login provider (X/Google/email) and enable 2FA
- Sign in to app.kash.bot from the new device — your wallet, balances, and history are restored automatically after authentication
- Monitor your account for unauthorized activity and contact support@kash.bot if anything looks wrong
Common Security Concerns
Can Kash access my funds?
Can Kash access my funds?
No.
- What Kash can do: prepare transactions for your approval, sponsor gas, resolve markets, and execute payouts to your own smart account
- What Kash cannot do: move your funds without your authorization, see or use your exported key, or freeze your wallet
How do I identify phishing attempts?
How do I identify phishing attempts?
Recognizing and Avoiding ScamsRed flags:
- Anyone asking for your password, exported key, or a “wallet validation”
- Lookalike accounts imitating @kash_bot or Kash’s trading account, or DMs from either — the real accounts never DM you first; only trust a trading account linked from the verified @kash_bot profile
- Lookalike domains — the only official domains are kash.bot (marketing site) and app.kash.bot (the app)
- Token scams: Kash has not launched a token; anyone selling “$KASH” is a scammer
- Urgent demands for immediate action
- Don’t click links or provide information
- Report the account to X and email support@kash.bot
- Warn the community in Discord
Who can use Kash?
Who can use Kash?
Eligibility and Geo-Blocking
- 18+ only: you must be at least 18 years old (or the legal age in your jurisdiction)
- Geo-blocking: access from OFAC-sanctioned regions is blocked
- Compliance restrictions are enforced at the platform level and updated as regulations change
Reporting Security Issues
How do I report a vulnerability?
How do I report a vulnerability?
Responsible Disclosure
- Email security@kash.bot with a detailed description, reproduction steps, and impact assessment
- Please allow time for the team to review before any public disclosure
- Smart contract vulnerabilities are in scope for the protocol bug bounty — see the Bug Bounty page
Account Security
Learn about account protection
Bug Bounty
Report security issues