A phone-first, non-custodial wallet. Your keys are generated and held on your own device — quantum-ready by default. Accounts, transfers, full staking, full governance, native multisig. No backend of its own. No trackers. No ads.
no app store · no download · it lives at mobile.xx.network
Through thirteen countdown screens it said Settings. Settings moved to a gear — because the last tab belongs to Memos: private, end-to-end encrypted memos between wallet holders, carried over the xx mixnet. Not a messenger bolted onto a wallet — the secure channel a wallet was always missing.


Every screen from the countdown — retaken on mainnet, plus a few we couldn't fit in thirteen posts.
















New wallets are generated with the audited Sleeve reference: a standard phrase for daily use plus a quantum-secure master phrase — created entirely in-browser, with zero network calls.
Bond, nominate in one signature, manage a position, unbond with the 28-day lock shown up front — or run a validator end to end, commission and cMix node identity included.
Every Gov1 surface, readable and actionable: vote with conviction, second, delegate, propose treasury spends and bounties — consolidated for mobile.
Proposals decoded locally from the on-chain bytes — never from a description someone supplied. Share call data by mixnet, QR, file, or paste. No central server anywhere.
Turn multisig into a second factor: a protected account that needs a second device to approve any spend, with an offline backup key. Enforced by the chain itself.
Hardware accounts whose key never enters the browser — with mandatory on-device address confirmation. Desktop Chromium and Android Chrome over USB.
Direct, end-to-end encrypted memos to other wallet holders over cMix — confirm addresses, coordinate transfers, pass multisig call data. One-to-one by design.
Optional app lock (PIN + biometrics). An indexer-privacy toggle that turns off every outbound query without breaking your ability to sign and move funds.
Add it to your home screen and launch it like a native app. Works offline once installed — new-account generation included.
The wallet leans on primitives the xx network already provides — not a new server, not homegrown cryptography.
Keys are generated and encrypted on your device. The wallet talks to public xx network infrastructure — it operates no server of its own.
Multisig calls, governance preimages, and proposals are decoded locally from on-chain bytes. What you sign is what the chain will execute.
Friendly labels always appear beside the real address fragment — a label can never disguise where funds go.
Account generation uses the audited Sleeve reference. Memos ride the xx network's cMix protocol. Same chain, same foundation tools.
Nothing is tracked, measured, or sold. There is nothing to opt out of.
The code is public and inspectable — see for yourself.
In your phone's browser — Chrome on Android, Safari on iPhone. Nothing to download, nothing to sideload; the wallet is served as a website and runs entirely on your device.
Android: menu (⋮) → Add to home screen. iPhone: Share → Add to Home Screen. It gets its own icon and a full-screen window — and keeps working offline from then on.
Generate a fresh quantum-ready wallet with Sleeve, import an existing recovery phrase or wallet.xx.network keystore, or connect a Ledger over USB.
Write both recovery phrases somewhere safe and offline — shown once, stored never. Then, if you like, turn on the app lock (PIN or biometrics) in Settings.
A PWA installs straight from the web — no store account, no gatekeeper between you and your wallet. Same app, fewer middlemen.
Yes — install via Safari's Add to Home Screen. (Ledger over USB is desktop and Android only; iOS doesn't expose the APIs.)
Your recovery phrases restore every account on a new device. A protected account stays safe even then — one device alone can never spend.