Mobile crypto wallets
Who holds the keys, whether the code is open, whether development is alive. The score is ours and made only of things that can be checked.
Phone applications. 8 entries
| Name | Score | Code | Last update | Code reviews | Keys |
|---|---|---|---|---|---|
| BlueWallet | 8/10 | MIT | August 30, 2026 | — | With the user |
| Muun | 8/10 | MIT | August 27, 2026 | — | With the user |
| Phoenix | 8/10 | Apache-2.0 | August 28, 2026 | — | With the user |
| Trust Wallet | 8/10 | Apache-2.0 | August 29, 2026 | — | With the user |
| Blockchain.com | 2/10 | Closed | — | — | With the user |
| Exodus | 2/10 | Closed | — | — | With the user |
| imToken | 2/10 | Archived | September 9, 2024 | — | With the user |
| TokenPocket | 2/10 | Closed | — | — | With the user |
How this kind works
The phone keeps the key in the system's secure storage, which is built more carefully than an ordinary file and does not hand the key to other apps. The weak point is not storage but reading: the screen is small, the recipient address is long, and checking a transaction by eye is harder than on a large display. A phone is also the thing most often lost and most often resold. So writing down the recovery phrase matters more here than anywhere else: the device is replaceable, the phrase is not.
What the score is made of
Wallet: open code 3, development in the past three months 3 (within a year 1), code review 2, keys with the user 2.
A low score means «we could check little», not «this one is a bad choice». Closed code offers nothing to look at — that is an absence of proof, not an accusation.
Open code and development from GitHub, code reviews and networks from DefiLlama. The list itself is ours.