Wallet support

Where to get help with the XChain wallet, how to report a bug, and how to report a security problem. Every channel below is one we actually watch.

Before anything else: your seed phrase

Nobody can recover a lost seed phrase. Not us, not anyone. The XChain wallet is self-custodial, which means your keys are generated on your device and never leave it. There is no account, no password reset, and no copy of your wallet on any server we run. If the seed phrase is gone and the device is gone, the funds are gone, and anyone who tells you otherwise is trying to take them.

Nobody from XChain will ever ask for your seed phrase, your private key, or your wallet password. Not in a chat, not in an email, not in a form, not to "verify" you, and not to "restore" anything. There are no exceptions to this. Any message that asks is not from us, however convincing the name or the picture next to it.

The same goes for anyone offering to fix a stuck transaction, unlock a wallet, or recover funds in exchange for a fee or a phrase. Those offers are the most common way self-custody users are robbed.

Questions and help

Start with the written answers, which are faster than waiting for a reply:

If none of those answer it, ask in one of the community channels:

  • GitHub Discussions is the best place for anything technical, and the answers stay searchable for the next person.
  • Telegram is the general community channel.

These are public, community channels. Please do not post a seed phrase, a private key, or a screenshot containing either, and remember that anyone can send you a direct message claiming to be support.

Reporting a bug

Bugs go to the issue tracker of the repository they belong to, under the XChain Platform organization on GitHub. Wallet bugs belong to the xchain-wallet repository. If you are not sure which repository is involved, open it against the wallet and it will be moved.

What makes a wallet bug report actionable: which shell you were using (the web wallet, the browser extension, the desktop app, Android, or iOS), the version, which chain and network, what you did, what you expected, and what happened instead. Transaction IDs are useful and safe to share. Seed phrases and private keys are neither, and a report containing one will be deleted rather than answered.

Reporting a security vulnerability

Security reports do not go through the public channels above. The wallet's security policy is the current document: it names the private reporting route, the email fallback, what to include, what is in and out of scope, and the response timelines we hold ourselves to.

Please report privately first and give us the chance to ship a fix. Vulnerabilities in a self-custodial wallet put real funds at risk, and a public disclosure before a patch exists puts them at risk faster.

What we do not do

We do not hold your funds, so we cannot freeze, reverse, refund, or resend a transaction. Once a transaction is confirmed on Bitcoin, Litecoin, or Dogecoin, it is final, and no part of XChain has the ability to undo it. The explorer will show you the state of any transaction, which is the same view we would have.

We also do not run a staffed support desk, so we do not promise a response time on general questions. Security reports are the exception and carry the timelines written into the security policy above.

Privacy

What the wallet stores, what it sends, and to whom is written out in full in the wallet privacy policy.