DREY
DREY security
Last updated August 24, 2026
DREY is non-custodial: signing keys are created or restored locally, encrypted at rest, and used by the app or extension on your device. The hosted gateway supplies signed data and broadcast services but cannot sign for a wallet.
Core boundaries
- Recovery material and decrypted private keys remain local.
- Transaction bytes are reparsed and checked before signing and after returned results.
- Protected-asset and fee policies are enforced on the device, not activated by remote metadata.
- Each site connection and signing request requires explicit approval.
- Unknown or unsupported marketplace signing contracts fail closed.
User safety
- Install DREY only through the verified store link on this domain.
- Review the recipient, action, amount, fee, and protected assets before approval.
- Do not enter recovery words into websites, support forms, chats, or screenshots.
- Stop using DREY and contact us if the app or extension identity, requested action, or transaction details change unexpectedly.
Report a vulnerability
Email drey@squirrelsystems.net with the affected version, environment, reproducible steps, and sanitized evidence. Do not test with valuable funds or reused recovery material, and do not include secrets in the report.