All posts

Crypto with Face ID: how a passkey vault works, and what happens if you lose your phone

Face ID doing the job of twelve words, the asterisk nobody puts on “without a seed phrase”, and the three things that can happen when your phone goes missing.

7 minute readPublished September 16, 2026
A hand holding a black smartphone
Photo: Dennis Cortés, CC0 1.0, via Wikimedia Commons
Short answer

A passkey vault lets you approve crypto transactions with Face ID or a fingerprint instead of typing a seed phrase. The key is created on your device, never leaves it in a form anyone can read, and is resistant to phishing because there is nothing to type. Fonte still makes you save a 12-word recovery key when you open a vault, because phones get lost. Day to day, there is nothing to type. For recovery, there are 12 words to keep private and offline.

Not financial advice.

Why seed phrases stop so many people

Ask people who gave up on crypto why, and many describe the same moment. An app showed them twelve random words, said that losing them meant losing everything forever, and offered no undo. Reasonable people close the tab.

The seed phrase exists because a normal blockchain account is a single private key, and that key has to live somewhere a human can restore it from. It is not good design. It is a consequence of how basic accounts work.

What a passkey actually is

A passkey is a public and private key pair generated by your own device.

This is the same technology that has been replacing passwords on major websites. Using it to control money on a blockchain is the newer part.

Why this took a while to arrive in crypto

Ethereum-style accounts sign with one elliptic curve (secp256k1). Passkeys sign with a different one (P-256, also called secp256r1). The maths is similar, but the two are not interchangeable, so a normal Ethereum account cannot check a passkey signature.

Base and several other networks now include a built-in function (a precompile) that verifies P-256 signatures natively and cheaply. That is what makes passkey-controlled wallets practical rather than merely possible.

How a Fonte passkey vault fits together

Three pieces, each doing one job:

  1. Your passkey, in your phone's secure element. It signs when you approve with Face ID.
  2. A signer contract on Base that stores your passkey's public key and answers one question: is this signature valid? It holds no funds.
  3. Your vault, a Safe smart contract wallet that holds the money. Its day-to-day owner is the signer contract, so in normal use only your passkey can authorise it.

And a fourth piece, which is easy to overlook:

  1. Your 12-word recovery key, set up as a second owner of the same vault. It sits unused until you need it.

Fonte's automation (the keeper) is not an owner at all. It holds a separate permission to lend, swap and rebalance, checked on-chain on every transaction. Every entry in that permission set is public and can be read on a block explorer, and you can revoke it yourself. The details, including the limitation that the fee amount is enforced in software rather than on-chain, are on the security page.

"Without a seed phrase" needs an asterisk

Here is the honest version. When you open a Fonte vault with a passkey:

There is no way to skip the recovery key. The setup does not report success until the recovery key is an owner of your vault on-chain.

So a passkey vault removes the seed phrase from everyday use, where it causes most of the harm (typing it into the wrong place, storing it in a screenshot). It does not remove the need to keep a backup. Write the 12 words on paper, store them offline, and never type them anywhere except the Fonte recovery page.

What happens if you lose your phone

There are three situations.

1. Your passkey synced to your new phone. Passkeys sync through your platform's keychain (Apple or Google), encrypted end to end. A new phone signed in to the same account can restore your access without the key ever being readable by anyone else.

2. Your passkey did not sync, but you have your 12 words. Go to app.fonte.finance/recover and enter the phrase. It is checked on your device first. The app finds the vault your recovery key owns and shows you the vault and its balance before you sign anything. You then create a new passkey, and the recovery key replaces the old signer with the new one. A wrong phrase costs nothing, because nothing is submitted until the vault is found.

3. You lost both the passkey and the 12 words. Fonte cannot restore access. Fonte is not an owner of your vault and holds no key to it, so there is no sign-in it can perform on your behalf. That is the trade you are making, and it is why the 12 words matter.

What gets better with a passkey

What gets harder, honestly

Does easy signup mean the company holds your money?

It should not, and you should check. Plenty of products make signup easy by holding your keys. Ease of signup and custody are separate questions.

The test is the same for any provider: ask what the operator is technically capable of, not how smooth onboarding felt. For Fonte, the vault address, the permissions module and every permission entry are public on Base and can be read on a block explorer. Our guide What non-custodial actually means shows how to run that check in a few minutes.

Who a passkey vault is not for

Try it without funding anything

You can open a Fonte vault with Face ID and fund it later, or never. Creating the vault takes about 30 seconds once you have saved your recovery key. Open a vault, or first read how Fonte works and what it charges.

Frequently asked questions

Is there a crypto wallet without a seed phrase?

Yes, for daily use. A passkey wallet signs with Face ID or a fingerprint using a key stored on your device, so there is no phrase to type. Fonte passkey vaults still require a 12-word recovery key as a backup owner, because a phone or passkey can be lost.

What happens to my crypto if I lose my phone?

With a Fonte passkey vault, a new phone can sign in if your passkey synced through Apple or Google. If it did not, you can use your 12-word recovery key at app.fonte.finance/recover to create a new passkey. If you lose both, Fonte holds no key and cannot restore access.

Can a passkey be phished?

A passkey is bound to the website that created it, so a lookalike site cannot request it and there is nothing to type into a fake page. It does not protect you if someone has your unlocked phone and your biometrics.

Does Fonte hold my keys?

No. Your passkey stays on your device, and your vault is owned by a signer contract only your passkey can authorise, plus your recovery key. Fonte's keeper is a separate on-chain permission used to manage the strategy, not an owner key, and you can read every entry in it on a block explorer and revoke it yourself.

Is the passkey signer contract audited?

Not independently. Fonte states on its security page that its passkey signer contract, which holds no funds but checks signatures, has not been independently audited. The Safe wallet, the permissions module and Aave are third-party contracts that are widely used and independently audited, although the way Fonte configures those permissions is Fonte's own work and is not.

Disclaimer: This article is general information, not financial, investment, legal or tax advice, and not an offer of securities. Crypto assets are volatile and you can lose money, including your entire deposit. Smart contracts can contain flaws. Keep your recovery key private and offline.