SQRL
SQRL security
Last updated July 24, 2026
SQRL is non-custodial: signing keys are created or restored locally, encrypted at rest, and used by the extension worker. The hosted gateway supplies signed data and broadcast services but cannot sign for a wallet.
Core boundaries
- Recovery material and decrypted private keys remain local.
- Transaction bytes are reparsed and checked before signing and after returned results.
- Protected-asset and fee policies are enforced by the extension, not activated by remote metadata.
- Each site connection and signing request requires explicit approval.
- Unknown or unsupported marketplace signing contracts fail closed.
User safety
- Install SQRL only through the verified store link on this domain.
- Review the recipient, action, amount, fee, and protected assets before approval.
- Do not enter recovery words into websites, support forms, chats, or screenshots.
- Stop using SQRL and contact us if the extension identity, requested action, or transaction details change unexpectedly.
Report a vulnerability
Email contact@squirrelsystems.net with the affected version, environment, reproducible steps, and sanitized evidence. Do not test with valuable funds or reused recovery material, and do not include secrets in the report.