Security

Is HyperPay Safe? Security You Can Verify

Named audits, institutional custody, and clear guidance on verifying you're using the real app — not vague reassurance.

Download Wallet

The wallet is downloaded from our official download page — installers for Windows, macOS, and Linux.

HyperPay's core app security centers on independent third-party audits from SlowMist and CertiK, plus institutional custody infrastructure via HyperBC for custodial assets. The core app's source code is not publicly available. The exception is Sealer2100, HyperPay's premium hardware wallet, which is fully open-source (Apache 2.0, public GitHub) and audited by CertiK and Kudelski Labs.

Audits & custody

  • Operating since 2017
  • Audited by SlowMist
  • Audited by CertiK
  • Institutional custody via HyperBC
  • No publicly reported major incident since 2017

How HyperPay Keeps Your Crypto Secure

Open Source Where It Counts Most

Sealer2100 is fully open-source, audited by CertiK and Kudelski Labs. The core app relies on named audits (SlowMist, CertiK) instead.

Published by CipherBC Hyperpay Pte. Ltd.

HyperPay is distributed from hyperpay.dev and official app-store listings under the CipherBC Hyperpay Pte. Ltd. publisher name.

Self-Custody Puts You in Control

Prefer to hold your own keys? HyperPay's self-custody mode removes custodial risk entirely.

What "audited" means, specifically

Security audits are frequently invoked and rarely explained. An audit is a time-boxed review by an external firm of a defined scope of code or infrastructure, producing findings that the vendor then fixes or accepts. It is evidence that qualified outsiders looked, not a guarantee that nothing was missed.

HyperPay's core app has been reviewed by two independent firms, SlowMist and CertiK, both of which are well known in the blockchain security industry. Sealer2100, the flagship hardware wallet, has been audited by CertiK and Kudelski Labs. We name the firms because a named auditor is checkable and the phrase "independently audited" on its own is not.

The honest framing is that audits reduce the probability of certain classes of defect. They do not make a wallet unbreakable, and any vendor implying otherwise is overselling what the process does.

Open source: exactly what is and isn't

The HyperPay wallet application is not open source. Its source code is not published for independent review, which means external verification of the app relies on third-party audits rather than on anyone being able to read the code themselves. That is a real limitation and we state it rather than working around it.

Sealer2100 is different. Its full codebase is published under the Apache 2.0 licence on public GitHub, and it has been independently audited by CertiK and Kudelski Labs. If verifiable software is a requirement for you, that is where HyperPay meets it: keys live on a device whose firmware you can read, audit and rebuild, with the wallet app acting only as an interface.

How custody risk differs by mode

In self-custody mode, private keys are generated and stored locally on your device. HyperPay cannot move, freeze or recover those funds — and neither can anyone else, including you, if the recovery phrase is lost. The dominant risk is your own backup discipline, not the provider.

In custodial mode, key management moves to HyperPay's infrastructure, with assets held through HyperBC. That removes seed-phrase loss as a failure mode and adds provider dependence. Neither model is universally safer; the wallet supports both.

Where HyperPay is published

HyperPay is published by CipherBC Hyperpay Pte. Ltd., a Singapore-registered company operating the wallet since 2017. Desktop build 5.6.210401 is distributed from hyperpay.dev, and mobile listings carry the same publisher name.

  • Publisher: CipherBC Hyperpay Pte. Ltd., Singapore, operating HyperPay since 2017.
  • Current desktop build: 5.6.210401 for Windows, macOS and Linux.
  • HyperPay support never asks for a recovery phrase.

Practical steps for your own setup

For balances where device compromise is a genuine concern, add hardware. HyperMate signs offline over Bluetooth, and Sealer2100 signs air-gapped via QR codes with iris-based access. Keep firmware current and split holdings.

  1. 1

    Back up your recovery phrase offline.

    On paper or metal, in at least two separate physical locations.

  2. 2

    Keep it out of digital storage.

    Never store it in a photo library, notes app or cloud drive.

  3. 3

    Test the restore first.

    Do this before you fund the wallet with a meaningful amount.

Where this fits

Security is one input into the wider picture; the HyperPay wallet overview explains how custody, the HyperCard and staking fit together once you have decided the security model works for you. For background on the custody model itself, read our guide to whether crypto wallets can be traced, and the HyperPay company background page names the team behind these commitments.

Security questions

Is HyperPay safe?

HyperPay has operated since 2017 with no publicly reported major security incident, is audited by SlowMist and CertiK, and holds custodial assets through HyperBC's institutional custody infrastructure.

Is HyperPay open source?

The core app is not. Only Sealer2100, the flagship hardware wallet, is open source — published under Apache 2.0 on GitHub and audited by CertiK and Kudelski Labs.

Has HyperPay ever been hacked?

There has been no publicly reported major security incident since the wallet launched in 2017. Independent audits by SlowMist and CertiK cover the wallet, and custodial balances sit with HyperBC.

Who publishes the HyperPay wallet?

HyperPay is published by CipherBC Hyperpay Pte. Ltd. at hyperpay.dev and under that publisher name on official store listings. Recovery phrases are never requested by HyperPay support. Start at the HyperPay download page.

Can HyperPay freeze or access my funds?

Not in self-custody mode, where keys stay on your device. In custodial mode, key management is handled by HyperPay's infrastructure, which is the trade that mode involves.