creepsby Swissquote

Your keys.
Swissquote's protection.

A self-custody crypto wallet that keeps the client inside Swissquote.

Swissquote Wallet Challenge · test networks onlycreeps.jojoserv.com

1 · The problem

Self-custody means leaving Swissquote

Today
Swissquoteholds the keys
→withdraw
External walletno rules, no help

To own their keys, the client must take the money out. Swissquote loses the client, the client loses the protection.

With creeps
Clientowns the private key
+
Swissquotesecurity and compliance

The client owns the key and can use it anywhere, but the wallet lives in the Swissquote app, with its checks and its help.

Goal: give the client their private key without making them leave Swissquote.

2 · Options we considered

Why not the usual answers?

Rejected

Seed phrase

12 words on paper. Lose them or get phished: the money is gone. Exactly what clients fear.

Rejected

Swissquote keeps the key

That is today's custody. The client never really owns anything.

Rejected

Smart account (ERC-4337)

The wallet is a smart contract, unlocked by Face ID. Elegant, but Ethereum only: it does not exist on Bitcoin.

Rejected

Key rebuilt in a TEE

The key is cut in pieces, then put back together to sign, inside a sealed server chip (TEE). The full key exists again, at each signature.

Chosen

MPC: the key is never whole, not at creation, not when signing. It works the same on Bitcoin, Ethereum and Solana.

2 · The technology

What is MPC?

The private key is never created whole. Each side generates its own secret piece, and the two pieces compute a signature together without ever being shown to each other. Only the address is public.

Piece 1on the client's phone, encrypted with their passcode
+
Piece 2at Dynamic, stored encrypted, only used inside a TEE
=
Signaturethe full key never exists, anywhere

To send money, the client needs all three:

Passcodeopens piece 1
+
PasskeySwissquote's OK, so Dynamic uses piece 2
+
MPCboth pieces sign together

2 · Our provider

Why Dynamic

1 · True MPC

The key is never put back together, not even inside its secure chip. Other providers, like Privy, rebuild the full key to sign.

2 · Bitcoin, Ethereum, Solana

One account, three wallets, the same security everywhere. Smart accounts only cover Ethereum.

3 · Swissquote keeps the veto

Dynamic accepts the Swissquote sign-in, and signs only with Swissquote's one-time OK. Tested: without it, Dynamic refuses.

4 · The client can leave

Built-in key export: the client can take the full key at any time. That is what makes it real self-custody.

About the TEE. Dynamic adds a secure chip around its own piece only, as an extra lock. The security does not rely on it: even if that chip were broken, the attacker would hold one piece, useless without the client's.

3 · How it works

Getting started in one minute

1
Swissquote

Sign in

The client signs in with their Swissquote account. Swissquote vouches for them to Dynamic.

2
Client

Choose a passcode

A secret only the client knows. It locks their piece of the key. Swissquote never sees it.

3
Dynamic

Create the wallets

Three wallets, Bitcoin, Ethereum and Solana, created directly in two pieces.

4
Client

Add a passkey

Face ID or fingerprint, registered with Swissquote. It will approve every transfer.

Two secrets, two roles.  The passcode opens the client's piece of the key. The passkey (Face ID) proves to Swissquote that it is really them.

3 · How it works

Sending money

Client
1Requestaddress and amount
3Face IDconfirms it is them
5Piece 1signs on the phone
Swissquote
2Checklimits, blacklist, rules
4Green lighta one-time ticket, 2 minutes
Dynamic
5Piece 2signs only with the ticket
No ticket, no signature.We tested it on the real Dynamic service: without Swissquote's ticket, it refuses.

4 · Freedom and protection

Whatever happens, the money is safe

"I want to leave"

Use a dApp Swissquote does not allow, or another wallet.

Face ID + passcode
Swissquote's OK to export
full private key shown on the phone only

Free to go, anytime.

"I lost my phone"

New phone, same wallet.

sign in + approve by email
passcode opens the piece of the key
new Face ID after a security delay

Same wallet, same addresses.

"My account was hacked"

A thief has the email and the password.

no passkey: Swissquote holds any new passkey behind a delay
no passcode, no passkey: the secret key piece stays locked
Swissquote can block the new passkey, so the account stays locked

The thief leaves with nothing.

New passkey requestedSecurity delay: the real client is alerted and can cancelAccepted

5 · Compliance

Swissquote can say no

Transferaddress + amount
→

Swissquote's rules

Limits per transfer and per day
Blacklist of sanctioned addresses
Approved addresses only, if the client wants
→
OK: the ticket is given, the transfer is signed
Refused: no ticket, nothing can be signed

Checked before

The rules run before the signature, not after the money has left.

Can block, cannot send

Swissquote has no piece of the key: it can refuse a transfer, never make one.

Everything recorded

Each decision goes into an audit log that cannot be edited quietly.

6 · Business model

Why Swissquote wins

Keep

Clients stay

Today, a client who wants their own keys leaves with their crypto. With creeps, they get their keys and stay: the wallet sits one tap from their Swissquote account.

Attract

New clients come

Crypto users who refuse to leave their keys with a bank finally have a reason to join: their keys, with a Swiss bank's protection.

Possible revenue

A subscription where Swissquote pays the gas fees: clients send crypto without first buying ETH or SOL.

creepsby Swissquote
FreedomProtectionTrust

creeps
by Swissquote

Live demo: create → send → lose the phone → recover.

creeps.jojoserv.com · test networks onlyPrototype for the Swissquote Wallet Challenge. Not an official Swissquote product.