We read the contract
before you sign it.
Every transaction gets simulated. You see "you'll lose 0.5 SOL, gain 78 USDC" in plain English. Lookalike addresses get flagged. Unlimited approvals get rewritten to the exact amount. Crypto's $200M/year approval-drainer problem is just not FOB's problem.
Self-custody, dressed in friendly clothing.
FOB never touches your private keys. Not on our servers. Not in our enclaves. Not anywhere we could reach.
Your keys, your phone, always.
Your 12-word recovery phrase is generated on your device, encrypted with a PIN only you know, with FaceID standing guard. Encrypted ciphertext at rest is on our relay (so you can roam across devices); we never see the plaintext.
The wallet you carry on a keychain — not the one Stripe runs for you.
Recover with friends, not paper.
Pick 3 Telegram friends as your guardians. Lose your phone? They each tap "yes" in a bot DM — you're back in.
Argent invented this pattern for Ethereum. We made it work for normal people — because we have your Telegram contacts.
Sign with both eyes open.
you'll gain 78.12 USDC ($78.12)
you'll pay 0.000045 SOL gas (~$0.011)
// route: Jupiter v6 · Raydium CLMM · 12 hops · 8ms quote
FOB shows a unique color-glyph fingerprint per address. First-time recipients require extra confirmation. Same-letters-different-end never gets through.
A second tap from a second place.
Every transaction above your set limit needs a second tap from @fob_2fa_bot — a separate Telegram bot, on a separate session, with separate encryption.
- Set your limit ($100, $1,000, $10,000) in Settings
- Anything above → second tap required, in the 2FA bot DM
- If your phone is stolen, attacker still needs the 2FA bot session
- Both sessions wipe on PIN-fail-three-times
You're sending 2.4 ETH ($6,124) to a new address. Limit is $1,000.
Five attack classes. Zero hits.
Approval drainers
Unlimited approvals get rewritten to exact amounts. Malicious approval pages get blocked at simulation.
Address poisoning
Color-glyph fingerprint per address. Lookalike addresses get a "Lookalike" red stamp.
Phishing sites
FOB doesn't connect to web. There's no WalletConnect surface to exploit.
SIM swap
Telegram-contact recovery is independent of SMS. SIM swap doesn't help an attacker.
Bot impersonation
Only verified @fobwallet_bot can produce inline-pay cards. Telegram's bot verification system protects this.
Lost phone
Three recovery paths: 12-word phrase, 2-of-3 guardians, PIN re-auth. Pick your paranoia.