A software wallet is an app on a phone or computer that holds keys and talks to blockchains. The best ones feel almost boring: they show a balance, they make you write down words, they ask you to confirm a send. The worst ones feel exciting: they hide networks, they push “dapps”, they bury the fact that a signature can empty an account.
This review is of the category as it stands for a careful beginner in 2026, not a league table of logos. Brands change their UIs. The failure modes do not.
Setup and recovery
We want the phrase shown once, with a test that you wrote it down, and no suggestion to screenshot it. We want a clear warning that support will never ask for it. We want the restore flow to work on a second device. If a wallet offers cloud backup, we want to know who encrypts it and with what. “Convenient recovery” that is just your Apple or Google account is a trade: easier life, broader blast radius if that account is taken.
Everyday sending
Network selection should be explicit. Fees should be visible before you commit. Address books help, but they should not hide the full string. A preview on the same device that might be compromised is weaker than a preview on a second screen. For software-only use, we still want a forced pause: a summary you have to scroll.
The dapp problem
Connecting to websites is where software wallets earn their drama. A clear simulation of what you are signing — especially token approvals — is now table stakes. Unlimited allowances should look scary. Blind signing should be off unless you know why you turned it on. If the wallet’s business model is to funnel you into swaps, we notice. Affiliates are allowed; dark patterns are a score hit.
Privacy and the vendor
Many apps resolve balances through their own infrastructure. That can leak IP addresses and wallet lists. It is not automatically malicious. It is also not “trustless”. Read the privacy policy like an adult. If there isn’t one, that is a review finding.
Updates and the supply chain of trust
Phone wallets update through app stores. That is good for patching holes and good for a compromised vendor account to push a bad build. Delay non-critical updates a day if you are moving a large sum; do not delay forever. Watch the vendor’s status page more than their marketing blog.
Open-source wallets can be inspected; almost nobody inspects them. What you are buying, even in a free app, is a reputation and a release process. We score that process, not the GitHub star count.
Who it is for
People learning, people moving small sums, people who will actually practise recovery. If you are holding a sum that would change your housing, this category is a front door, not a vault. Pair it with habits from our security checklist, or step up to a hardware device and accept the friction.
Scores reflect a composite of leading apps we keep on the lab bench, not a single SKU. Try the official build, not a lookalike. This is not financial advice and not a promise that any app will keep you safe if you hurry.





