Security & custody
Non-custodial by construction: Turnkey-secured keys, scoped signing, and exits that never depend on MORE.
Non-custodial by construction
Your savings wallet is created inside a dedicated Turnkey sub-organization that belongs to you. Keys are generated and stored in Turnkey's hardware-backed infrastructure and can only be used through your own authentication - Google, email, or passkey. MORE never sees or holds your private keys, and your funds sit in your wallet and in standard public contracts (USDC, WBTC, Morpho, Aave), never with MORE.
Two signing paths, clearly separated
- Your session. Sensitive actions - like exporting your private key - are signed with your own login session. MORE cannot perform them for you.
- Delegated collection signing. So savings can run on autopilot, you grant MORE a scoped delegation to sign collection transactions on your behalf. It is policy-gated through Turnkey: collections can route into the savings contracts, and nothing else.
Your exits never depend on MORE
- Key export, any time. Export your savings-wallet private key from the app and use it in any wallet.
- Move funds yourself. With your exported key (or your savings-wallet address) you can move any asset directly from any wallet, any time - never dependent on MORE.
- Standard contracts. Buckets settle as ordinary tokens and vault positions in your wallet. Even if MORE disappeared, your funds would not.
What MORE can and cannot do
| Action | Possible? |
|---|---|
| Access your private keys | No |
| Withdraw or hold your funds | No |
| Send your funds to an arbitrary address | No - delegated signing is policy-scoped to the savings contracts |
| Stop you from withdrawing or exporting your key | No |
| Route collections into your chosen buckets | Yes - that is the whole delegation |
The contracts
Collections route through MORE's BucketRouter and per-bucket adapters - deliberately small, purpose-built Solidity covered by an automated contract test suite. The contracts are live on Arbitrum One and Robinhood Chain; delegated collection signing is being enabled account-by-account during the staged rollout, and until your account is enabled no delegated transactions execute. The protocols underneath - Morpho, Aave, Uniswap, Chainlink - are long-running, widely audited infrastructure. MORE's own v2 contracts have not yet completed an external audit, and we will not pretend otherwise.
Risks, honestly
All of DeFi carries risk: smart-contract bugs (MORE's or the protocols underneath), third-party compromise (Turnkey, Morpho, Aave), and market conditions (a stablecoin depeg, BTC drawdowns in the Bitcoin bucket). Yield rates are variable and never guaranteed. MORE minimizes what it can - reviewed venues, pinned addresses, scoped signing - and names the rest.
Reporting
Found a security issue? Email security@more.ski.