How HOLD works

Five locks.
You will meet two of them.

An account holding real money needs more than one way to stop someone else reaching it, and more than one way to let you back in. The trick is asking for the right amount at the right time — nothing while the account is empty, and more as there is more to lose.

What each one is for

They are not five versions of the same thing. Each one stops a different person, and the reason you are asked for several is that the attacker who gets past one of them is usually stopped cold by another.

Your passkey — stops someone with your password

It replaces the password rather than adding to it. Your face or fingerprint unlocks a key held in your phone's secure hardware, and nothing that could be stolen, guessed or phished is ever typed. Because it syncs through your Apple or Google account, a new phone signs in without a fuss.

Your PIN — stops someone holding your phone

Set during setup, checked when you open the app and again before anything that moves money. It never leaves the device and is not a login for anything. Face ID sits in front of it for speed; the PIN is what is underneath when Face ID will not read.

Two-factor — stops someone with your email

A six-digit code from an authenticator app on a separate device. Optional, strongly recommended, and it is what turns a stolen phone from a disaster into an inconvenience: it is required before anything that weakens the account or reveals your keys, and it lives somewhere the thief is not.

Recovery codes — stop you being locked out

Eight one-time codes, generated once and yours to keep. We store only a scrambled version, so we cannot read them back to you and neither can anyone who reads our database. Each works once. A fresh set retires any old ones you have not used.

Your device list — stops someone who is already in

Every session on your account, with the device and when it was last active. Sign out any of them from here, or all of them at once. The first time a device we have never seen signs in, you get an email about it without having asked.

Step-up — stops the panicked five minutes

Tightening your security never asks for anything. Loosening it always does: turning a protection off, raising a limit, revealing your phrase. It demands the strongest factor you hold, which is deliberate — the moments when someone talks you into weakening your own account are the moments worth slowing down.

Why we ask for more later

Security you are made to set up before you have anything to protect is security you click through. So the app scales what it asks for to what is actually at stake, by one written-down rule.

An empty or nearly empty account

Nothing beyond the passkey

There is nothing here to lose yet, and nagging you now only teaches you to dismiss us later.

Once you are holding around $50

One way back in

Real money, so one independent recovery method: recovery codes, a phone number, or your phrase if you use a mode that shows it.

Once you are holding around $1,000

Two independent ways back in

Enough that losing it would genuinely hurt. Two, so that any single accident — a lost phone, a closed email, a dead laptop — is survivable.

“Independent” is doing real work in that sentence

We count things that can fail separately, not boxes ticked. Two passkeys that both live in the same iCloud account are one method, not two — lose the Apple account and both are gone at once. So the second thing we ask for is always somewhere else entirely. It is the difference between two locks on one door and two doors.

Approximate figures, in US dollars, and they may be tuned. The app shows you exactly where you stand and what is missing.

What none of this stops

The limit

Somebody who has your recovery phrase does not need the app.

Every lock on this page is a lock on HOLD. The phrase reaches your money from any wallet ever written, and someone holding it simply uses one of those and never comes near our PIN, our two-factor or our device list.

Which is why the default mode never shows you the phrase, and why the app asks for your strongest factor before revealing it in the modes that do. If anyone ever asks you for those words — support, a giveaway, someone helpful in a chat — that is the whole attack, and there is no version of it that is legitimate.

The limit

Your Apple or Google account is part of your security now.

Passkeys sync through it, which is what makes a new phone painless. It also means whoever controls that account controls a passkey. It is worth having strong two-factor there too — and it is the specific reason your second recovery method must not live in the same place.

The limit

We cannot reset any of it for you.

Not the two-factor, not the passkey, not a recovery code you did not keep. There is no support process that ends with us letting you in, because a support process that could do that is a process someone else can talk their way through — and account takeover through support is one of the most common ways people lose money at companies that do offer it.

The trade is honest and it is not free: nobody can take your money, including us, and the price of that is that nobody can rescue you either.

The questions people actually ask

Why can I not skip the passkey?

Because the alternative is a password, and passwords are how almost every account in the world gets taken. A passkey cannot be phished — it will not work on a site that merely looks like ours — cannot be reused across services, and cannot be leaked in someone else's data breach, because there is nothing to leak. It is also faster than typing. If the setup genuinely fails on your device, we let you carry on and ask again later; what we do not offer is a Skip button, because a skip you can take in three seconds during setup is a skip almost everyone takes.

What is the difference between my PIN and my two-factor code?

The PIN opens the app on the phone in your hand. The two-factor code proves it is you signing in to the account from anywhere at all. They protect against different people: the PIN is about someone holding your unlocked phone, two-factor is about someone in another country who has your email. Having one is not having the other.

Someone knows my PIN. How bad is that?

Bad, but not unlimited, and this is exactly the case two-factor is for. Anything that would weaken your security or expose your keys — turning off protections, raising a spending limit, revealing your recovery phrase — asks for your authenticator code, not your PIN. That code is generated on a different device, so someone who watched you type your PIN still cannot strip the account down. Without two-factor set up, that same request falls back to the PIN, and they can.

Where should I keep the recovery codes?

Anywhere that is not your email and not the phone the app is on. A screenshot in your photo library is inside the thing you are protecting against. Paper in a drawer is unfashionable and genuinely good. A password manager on a different account is good. The test is simple: if someone got into your email right now, would they find them?

Can I use one code twice?

No. Each of the eight is consumed the moment it works, so a code that helped you in once is dead. Generating a fresh set retires every unused code from the old set, which is what you should do if you ever think one has been seen.

Do you email me when someone signs in?

The first time a device we have never seen appears on your account, yes. You can also open the device list at any point, see every session with when it was last active, and end any of them — or all of them but the one you are holding, which is the right move if you are unsure and want to start clean.

Do you have my passkey?

No, and the design does not permit it. What we hold is the public half, which is only useful for checking a signature your device produced. The private half stays in your phone's secure hardware or your Apple or Google keychain, and never reaches us. This is also why we cannot recreate one for you.