How secure is Xumm? (2024)

It is a crazy time in the crypto world, how secure is Xumm?

There are several ways to view security when it comes to your XRP Ledger account.

Your first line of security starts with your phone.

Here are the top 9 security threats to your phone.

  • Social Engineering
  • Data Leakage via Malicious Apps
  • Unsecured Public WiFi
  • End-to-End Encryption Gaps
  • Internet of Things (IoT) Devices
  • Spyware
  • Poor Password Habits
  • Lost or Stolen Mobile Devices

Source: https://auth0.com/blog/the-9-most-common-security-threats-to-mobile-devices-in-2021/

So, here are some things to consider:

  • Is your mobile device up to date with all security and OS updates?
  • Do you use a VPN?
  • Do you have an anti virus program that is up to date?
  • How often do you use public wifi?
  • Do you have a firewall on your phone?
  • Do you have strong passwords?
  • How often do you change your passwords?

If your phone is not secure, the best software wallet in the world (aka Xumm) will not be able to protect your assets. Starting out with a modern, up to date, secure mobile device is essential when it comes to securing your assets.

No problem. My phone is secure.

So your phone has no spyware or malware installed. It is up to date. You use a top of the line VPN, anti-virus software and firewall. You have installed Xumm and you used Xumm to create your XRP Ledger account. Well done!

Xumm can generate three hundred and forty undecillion, two hundred and eighty-two decillion, three hundred and sixty-six nonillion, nine hundred and twenty octillion, nine hundred and thirty-eight septillion, four hundred and sixty-three sextillion, four hundred and sixty-three quintillion, three hundred and seventy-four quadrillion, six hundred and seven trillion, four hundred and thirty-one billion, seven hundred and sixty-eight million, two hundred and eleven thousand, four hundred and fifty-six different accounts using the secret number standard. Xumm will provide you with one of those possible accounts.

It is hard to imagine how many accounts that actually is, so maybe this will help.

If you had a job that paid you 390 trillion euros per hour, you would have to work 24 hours per day, 7 days per week, 365 days per year for about 99 quadrillion years to earn 340 undecillion euros.

It is unimaginably difficult for someone to guess your account number out of 340 undecillion possible accounts. you would need to make 390 trillion guess per hour for 99 quadrillion years to guess them all.

How is that different from a cold/hard wallet?

It is no different. Whether an account is generated off line or online, there is no difference in the total number of possible accounts. The chances of guessing your account secret is the same.

There must be some difference...

It comes down to entropy. How well does the software generate randomness? How does it pick from the 340 undecillion possibilities?

Is that why you are always telling people to protect their Secret Numbers?

Exactly! The only way someone can access your account is if they know your Secret Numbers. The chances of someone figuring them out are 1 in 340 undecillion.

What about the 6 digit passcode to access Xumm. That is only 1 million possibilities. Anyone could guess that.

You are absolutely right. Let's say that someone has acquired your phone and somehow circumvented your password and now has full access to it.

An attacker launches Xumm and tries to hack your 6 digit passcode. Six digits is only 999,999 possible combinations, (000000, 000001, 000002 -> 999997, 999998, 999999), so they start entering various passcodes at a rate of 1 one passcode per second and about 11 days later they have tried all of the possible combinations. So now they have access to Xumm.

Except for one small countermeasure we implemented in Xumm. We have configured Xumm to only allow 5 attempts before Xumm starts to add time to the next attempt. After the ninth wrong entry, Xumm requires a delay of 2 hours to input again. That means 12 attempts per day. Now instead of 11 days to try all of the possible combinations, it would take about 83,332 days to try them all... Or about 228 years.

Ha! So now its down from 99 quadrillion years to 228 years!

However, let's say someone manages to guess your 6 digit passcode in under 228 years, now they have to figure out your signing password. Honestly, how hard can that really be right? Well, we set the limit for the number of characters you can make your password to a mere 2,091,752 terabytes. In other words, you could make your password so long, it would take up all of the storage space on your 512GB phone and about 4 million other 512GB phones before you ran out of space to store it. Provided that you selected a strong signing password, this could take awhile to guess.

Basically you're saying it is impossible. Why would I need the Xumm Tangem cards then?

It is basically impossible to guess the Secret Numbers in your lifetime and if your phone is lost or stolen, you have plenty to time to move your assets to another account. The Xumm Tangem cards are the perfect way of mitigating the risk of a compromised phone, especially if you follow our recommend guidelines here:

Although we believe that your phone is secure and that it will never get lost/damaged or stolen, having a pair of cards will ensure that even if your phone was compromised, your XRPL account is safe. Here's how...

A Xumm Tangem card will generate a set of private keys on the card. They never leave the card. No one will ever see them, (including you) and there is no way to access them. You can never be tricked into giving your account secret away and the only way to access your account is by having the card with you.

This sounds better than a cold wallet.

You're right. Most cold wallets give you the account secret (Secret Numbers/Family Seed/Mnemonic) so you can be tricked into giving it away. This can not happen with the Xumm Tangem cards. Your private key (keypair) is generated by a chip inside the Tangem card. The keypair cannot be extracted or wiped from the card. The key generation by the chip inside the card is very secure and has been audited. There is no way for you to access them so you can never give them away. Like we said, the account secret is on the card and the only way to access you account is by physically having the card with you.

Could someone hack the card?

Just like Xumm, the chances of guessing the account secret is 1 out of 340 undecillion.

Here are some more facts about the cards.

  • Contains $0 & 0 XRP in value upon delivery: the card will generate a keypair when first used with Xumm, and the newly generated keypair (and r-address on the XRPL) will have to be activated with 10 XRP as per XRP Ledger requirement first.
  • Card dimensions: 85.60 mm x 54.00 mm x 0.80 mm
  • Weight: about 4 grams
  • S3D350A microchip from Samsung
  • Common Criteria EAL6+ Assurance Level
  • Uses 3DES, AES, RSA, & ECC cryptography
  • Arm SecurCore SC000Core
  • Compatible with Android 5.1+ or iPhone with NFC (select models, iOS 13+)
  • Firmwareauditedby Kudelski Security

I want to know more about the cards.

Of course. check out this article.

What about if I connect Xumm to a "questionable" website or I scan an untrusted QR code?

Xumm will never share your private keys with a third party website or application. The website/app will deliver a sign request to Xumm and Xumm will display the sign request for you to approve or deny. Once you approve it, Xumm signs it locally on your phone and returns only the signature to the website/application. Your private keys never leave your phone. Xumm only signs after approval, locally, and then only returns the end product: the signed transaction.

...and a Trust Line? Can I be hacked by creating a Trust Line?

It is not possible for someone to access the tokens in your XRPL account via a Trust Line. A token issuer can freeze or misconfigure their own Trust Line though, which would make their issued tokens unusable, but they can not access your account. It is also possible that a token issuer could send you messages via the XRPL (once they know your r-address) and somehow convince you to send them your secret numbers. While not really considered a "hack", the results are pretty much the same.

What about spam transactions? Are they dangerous?

Unfortunately there is nothing that can be done to stop prevent spam on the XRP Ledger. There are no "spam filters" yet, so when we identify a spam transaction or a transaction that is coming from a fraudulent address, XUMM will alert you with a warning message about the sender of the transaction.

Although annoying, most people are choosing to ignore the messages.

If you are interested in learning more about spam on the XRPL, check out this article:

https://support.xumm.app/hc/en-us/articles/6156825861394-Spam-on-the-XRP-Ledger

Can the government freeze my funds via Xumm? What happens if the government seized XRPL Labs?

The XRP Ledger is a decentralized blockchain. A governmental agency might be able to shut down some of the XRPL validators and nodes in a particular region, but a single government could not shut down all of them all over the world. The XRPL servers are distributed around the planet to form a global network. In other words, the XRP Ledger will still run and validate transactions regardless if a bunch of servers were shut down. That is part of the idea behind decentralization.

Another feature of the XRPL is that no one, not a government or an exchange or even us can access your non custodial XRPL account. You are the only one with the account secret, so without that, there is no way to confiscate or freeze your XRP.

Finally, Xumm will run regardless if XRPL Labs exists or not. Xumm does not need our backend servers to function. All of the XRPL communication and signing happens locally on your mobile device, from within Xumm. It does not need our backend servers for that.

...plus, if worse came to worse, you could always take your account secret and just use another wallet if you wanted to.

Ok. Summarize it for me.

  • Keep your phone safe, up to date and free of spyware and malware
  • Never give your account secret (Secret Numbers/Family Seed/Mnemonic) to anyone, for any reason
  • Xumm is designed with security in mind. Security is number one priority (but Xumm can't be safer than your device and your own practices are)
  • Xumm Tangem cards are the best solution for maximum security

Additional reading

Notes

We understand that you might have additional questions regarding this topic so you are welcome to contact us any time via the Xumm Support xApp in Xumm or you can simply scan this QR code with Xumm and be directed there automatically.

How secure is Xumm? (1)

How secure is Xumm? (2024)

FAQs

Is Xumm safe to use? ›

Is Xumm Wallet safe? Yes. Xumm Wallet is regarded as a secure, non-custodial wallet.

Can my xumm wallet be hacked? ›

A Xumm Tangem card will generate a set of private keys on the card. They never leave the card. No one will ever see them, (including you) and there is no way to access them. You can never be tricked into giving your account secret away and the only way to access your account is by having the card with you.

Who owns xumm wallet? ›

XRPL Labs founder and XUMM Wallet creator Wietse Wind explains why self-sovereign identity is the future for non-custodial wallets.

How do I cash out on Xumm? ›

In Xumm, press the Send button on the main screen.
  1. Enter the amount of XRP you would like to send and press the Next button.
  2. Enter the r-address that your exchange provided you and press the Next button..
Dec 19, 2022

What is the safest crypto wallet in the world? ›

We chose Trezor as best for security because it comes with the strongest security features and track record of any reviewed hardware wallet. Trezor, like Ledger, is a name synonymous with crypto cold wallet storage. Its Model T is the second generation of hardware wallets it's created.

What is the safest way to store XRP? ›

For instance, if you're a first-time user wanting to buy or keep a small quantity of XRP, a mobile or desktop wallet will provide you with a good balance of security and ease of use. On the contrary, a hardware wallet may be preferred by a more experienced user.

Which crypto wallet has never been hacked? ›

ZenGo is unlike any other crypto wallet:

ZenGo is the self-custodial wallet of the future: Never hacked and always recoverable thanks to 3 industry-pioneering technologies.

Can I sell my XRP on Xumm? ›

we offer an On/Off-Ramp service to our Xumm Pro users. You can buy and sell XRP from our On/Off-Ramp xApp and send funds back and forth between Xumm and your bank account.

What are the benefits of Xumm? ›

Xumm removes the barrier between a user and their assets. Unlock the app with a passcode or bio-metrics (fingerprint, face ID) and the user has full, direct control. Xumm allows you to generate new XRP Ledger accounts and allows you to import your existing accounts.

Can Xumm wallet hold Bitcoin? ›

No. Our focus is the XRP Ledger.

What coins can Xumm hold? ›

Xumm is exclusively an XRP Ledger wallet. It supports XRP and all of the 8300+ tokens issued on the XRPL.

What is the purpose of Xumm wallet? ›

Xumm is a non custodial client (wallet) for the XRP Ledger, with superpowers. Xumm allows you to interact with the XRP Ledger and 3rd party tools while keeping your keys super safe.

How do I add USD to my Xumm wallet? ›

Click "WALLET" on the left. Select the wallet you want to deposit into (blue drop-down menu in the upper-left corner of the screen). Set the appropriate trust line (e.g. if you are depositing GateHub's USD set the USD trust line). Click the "Add Funds" button.

How do I deposit XRP into my Xumm wallet? ›

Switch to the GateHub account and click "Wallet" on the left.
  1. Select the wallet you want to send funds from (blue drop-down menu at the top left).
  2. Click "Send Payment".
  3. Select "XRP Ledger" for XRP transfers (enter your GateHub password and 2FA if requested).
Jan 18, 2023

What is the safest crypto wallet in us? ›

7 best hot wallets
Crypto.com Defi Wallet4.6
Guarda4.6
Exodus4.5
Coinbase Wallet4.3
MetaMask3.7
2 more rows
7 days ago

Are crypto wallets safer than banks? ›

But even the biggest crypto enthusiasts would struggle to describe it as safe. Crypto is less regulated, more volatile, and ultimately, a lot riskier than traditional banking.

What is the least safe place to keep your cryptocurrency? ›

Conclusion: In conclusion, keeping your cryptocurrency on an exchange is the least safe option. It is recommended that you store your cryptocurrency in a hardware wallet or a cold wallet. These wallets are offline and offer better security for your cryptocurrencies.

Can I leave my XRP on Coinbase? ›

Any XRP in your account remains securely stored in your Coinbase account. Though you're unable sell your XRP or trade/convert it for fiat and withdraw the fiat to your linked bank account, you do have the ability to view any XRP balance, deposit XRP to your account, and send XRP to a wallet outside your account.

What will happen to XRP if it is a security? ›

In particular, the regulatory body has the authority to levy a fine on Ripple Labs and demand that the business register XRP as a security. As a consequence, a judgment of this kind would certainly result in XRP being treated in the same manner as conventional securities, which may restrict both its adoption and usage.

Is XRP going to be used by banks? ›

Despite many challenges posed by adopting blockchain technology for international banking, XRP holds a strong position in this industry. There are many use cases for the blockchain, and it is used by many banks due to its operational benefits.

Which crypto cannot be hacked? ›

The short answer, from a lot of experts, is that the blockchain itself cannot be hacked. But blockchain-adjacent processes certainly can be hacked in a number of ways. Blockchain transactions can be manipulated. Blockchain assets can be stolen.

What happens if my crypto wallet gets hacked? ›

Once you know your device is malware-free, it's paramount that you transfer any existing funds from your compromised wallet to another wallet. Hackers will often wipe your account of funds immediately, but if you're lucky and they have not done this yet, it's time to take immediate action.

Can someone steal my crypto wallet? ›

The concepts behind blockchain technology make it nearly impossible to hack into a blockchain. However, there are weaknesses outside of the blockchain that create opportunities for thieves. Hackers can gain access to cryptocurrency owners' cryptocurrency wallets and exchange accounts to steal crypto.

Can my XRP be confiscated? ›

First, the developer notes, XRP is a decentralized cryptocurrency and cannot be seized without forcing key holders.

Do I need an XRP tag for Xumm wallet? ›

Enter your r-address from Xumm, (No XRP Tag is needed.) ...

Do I need a tag to send XRP to Xumm wallet? ›

Before you can proceed, you need to make sure you have this information: an exchange r-address that you can deposit XRP to. a destination tag for your account.

Does Xumm have a stable coin? ›

With Stably Ramp, users can buy and deposit stablecoin in their wallets with the Xumm Wallet using ACH, card, SWIFT, and instant bank transfers.

What are the cons of XRP? ›

XRP Weaknesses
  • Ripple Labs is currently being sued by the U.S.Securities and Exchange Commission (SEC) for not registering XRP with the agency and illegally selling a security. ...
  • XRP is not required (and scarcely adopted) by banks to settle transactions within the Ripple protocol.

Can you delete a xumm wallet? ›

Sign in with Xumm using the account you want to delete. Select the "Account Delete" option. Enter the r-address where you want your funds to be delivered. Sign the transaction.

Can I buy crypto on Xumm? ›

New Xumm Partnership Allows Users To Buy & Sell XRP With 40+ Fiat Currencies.

Is Xumm on the XRP Ledger? ›

Xumm, a noncustodial client (wallet) for XRP Ledger, saw a major update in March, with the release of Xumm 2.4.

Is the Xumm wallet decentralized? ›

Due to its nature as a decentralized exchange, the platform allows users to buy, sell and carry out trades for any asset on XRPL without the need for a central authority. The Xumm team has also noted that all processes come with no extra fees from them.

What are the best crypto coins to hold forever? ›

5 Best Long-Term Cryptocurrencies
  • Bitcoin (BTC)
  • Ethereum (ETH)
  • Cardano (ADA)
  • Polkadot (DOT)
  • Chainlink (LINK)
Apr 3, 2023

What wallet supports the most crypto? ›

Coinbase Wallet can store popular coins, such as Bitcoin, Litecoin, Dogecoin and BNB, as well as all ERC-20 tokens and tokens on EVM-compatible blockchains, which amounts to more than 5,500 supported digital assets — one of the biggest numbers on our list.

How many XRP tokens are left in circulation? ›

The current circulating supply of XRP is 51.99B. This is the total amount of XRP that is available.

How much is Xumm pro? ›

The Xumm on/off-ramp is only available for Xumm Pro wallet users. Notably, pro features attract a yearly fee of $60 with an additional $5 for the on/off-ramp service.

What is a Xumm trustline? ›

Trust Lines are a fundamental part of the XRP Ledger in that they allow an account to hold non-XRP assets (tokens) issued on the XRPL. Each Trust Line has a unique r-address which helps to identify it but it can be confusing for new users and sometimes people mix up the various tokens and issuing accounts.

How do I cash out cryptocurrency without paying taxes? ›

Instead of cashing out your cryptocurrency, consider taking out a cryptocurrency loan. In general, loans are considered tax-free. If you need liquidity immediately, you should consider using your cryptocurrency as collateral to take a loan through a decentralized protocol.

How do I cash out a large amount of crypto to my bank? ›

Cashing out Bitcoin is best done via a third-party broker, over-the-counter trading, or on a third-party trading platform. You can also trade it peer-to-peer. Cashing out a massive amount of Bitcoin comes with limited restrictions on daily withdrawals.

Can I cash out from Crypto wallet? ›

You can use a crypto exchange like Coinbase, Binance, Gemini or Kraken to turn Bitcoin into cash. This may be an easy method if you already use a centralized exchange and your crypto lives in a custodial wallet. Choose the coin and amount you'd like to sell, agree to the rates and your cash will be available to you.

Can you use Xumm on a laptop? ›

Xumm App. Using Xumm together with XRP Toolkit is the most convenient way to store and manage your crypto assets on the XRP Ledger. For the best user experience, we recommend accessing XRP Toolkit from a laptop or desktop computer and connect the Xumm app from a separate phone or tablet.

How do I sell XRP to USD? ›

Multiple options exist for selling XRP in exchange for USD. A direct route includes trading XRP directly for USD on an XRP-compatible exchange. A less straightforward option might be swapping XRP for a different crypto asset and then transferring that crypto asset to a compatible exchange to sell it for USD.

Where can I convert XRP to USD? ›

XRP to USD Exchange Platform: CEX.IO as a Pioneer. The easiest way to get any cryptocurrency is to buy it from an exchange.

How do I cash out XRP from Xumm? ›

In Xumm, press the Send button on the main screen.
  1. Enter the amount of XRP you would like to send and press the Next button.
  2. Enter the r-address that your exchange provided you and press the Next button..
Dec 19, 2022

Can I send XRP from Coinbase to Xumm? ›

Open the Coinbase app, select the "Send" button. 2. Enter the amount you would like to send to your XRP Ledger account Xumm then press, "Continue".

How do I transfer XRP to my bank account? ›

How to Withdraw Ripple (XRP)
  1. Tap 'Transact'
  2. In 'From:' select 'Ripple' beneath 'Crypto networks'
  3. Enter amount.
  4. In 'To:' enter any Ripple network address.
  5. Tap 'Preview' then 'Confirm'

What is the safest crypto mobile wallet? ›

Best for Beginners: Coinbase Wallet. Why we chose it: We chose Coinbase Wallet as the best crypto wallet for beginners because it's an intuitive and highly secure wallet backed by a well-known exchange. Coinbase Wallet is an excellent wallet for beginners with little to no experience with crypto.

What is the safest free crypto wallet? ›

  • 1) ZenGo – Most Secure Non-custodial Wallet.
  • 2) Binance – Best Wallet with Multiple features.
  • 3) Ledger Nano X – Best Cold Wallet for those on a Budget.
  • 4) Trezor Model T – Best Hardware Wallet for those on a Budget.
  • 5) Pionex – Best for Crypto Trading for Beginners.
  • 6) Coinbase Wallet – Best Wallet for Beginners.
May 25, 2023

Can I earn XRP on Xumm? ›

Can I earn rewards using Xumm? Since the XRPL does not offer an incentivization model for holders and all fees charged by the XRP Ledger are destroyed, there is no way generate returns from the network and Xumm is a self-custodial wallet that is completely free to use.

Which type of crypto wallet is the most vulnerable to hackers? ›

Hot wallets are cryptocurrency wallets that store digital assets in a device connected to the internet. They offer fast access to the funds for frequent trading and allow users to easily manage their crypto holdings. However, due to its connection to the internet, this type of storage has lots of vulnerabilities.

How secure are mobile crypto wallets? ›

If you lose it, your crypto accounts are locked, and there's no locksmith to open them for you. As long as you keep track of it, hardware wallets are very secure. Most models are equipped with malware- and virus-proofing security features. Software wallets are downloaded and internet-connected mobile or desktop apps.

How many crypto wallets should I have? ›

In general, it's good practice to divide your cryptocurrency holdings among multiple wallets, depending on your investment strategy and risk tolerance. For example, you could use one hot wallet for day-to-day transactions, a hardware wallet for long-term storage, and a paper wallet for an extra level of security.

Which crypto wallet has no withdrawal limit? ›

CoinSwitch is one of the top cryptocurrency exchanges that require no KYC verification since it allows you to trade crypto at the best rates. They allow you to trade 400+ cryptos, cryptocurrencies, and tokens without having to create an account on any exchange. Additionally, there is no withdrawal limit on CoinSwitch.

Does xumm have a stable coin? ›

With Stably Ramp, users can buy and deposit stablecoin in their wallets with the Xumm Wallet using ACH, card, SWIFT, and instant bank transfers.

Top Articles
Latest Posts
Article information

Author: Maia Crooks Jr

Last Updated:

Views: 6561

Rating: 4.2 / 5 (43 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Maia Crooks Jr

Birthday: 1997-09-21

Address: 93119 Joseph Street, Peggyfurt, NC 11582

Phone: +2983088926881

Job: Principal Design Liaison

Hobby: Web surfing, Skiing, role-playing games, Sketching, Polo, Sewing, Genealogy

Introduction: My name is Maia Crooks Jr, I am a homely, joyous, shiny, successful, hilarious, thoughtful, joyous person who loves writing and wants to share my knowledge and understanding with you.