Buy now

Rainbow is one of the better-designed ways to hold Ethereum and the assets built on top of it, and asking whether it's safe is the right question to ask before you move a balance into it. The short answer is that Rainbow gives you the keys and never holds them itself, which removes the company from the list of things that can lose your coins. What it can't do is make the device it runs on any harder to compromise, and Rainbow's own guidance is unusually clear about where that boundary sits.

What Rainbow is, and what it does well

Rainbow is an open-source, self-custodial wallet for Ethereum and the networks around it, shipping as an iOS and Android app and as a browser extension, with support for mainnet alongside Layer 2 networks including Arbitrum, Base, Optimism, Polygon and zkSync Era. Keys are derived using the standards rather than a house method: Walletbeat's technical review records that Rainbow uses BIP-39 to derive a seed from the recovery phrase and BIP-32 for hierarchical key derivation, and that both the recovery phrase and individual private keys can be exported.

That last detail is worth more than it sounds. A wallet that lets you export standard keys is a wallet you can leave, which means choosing it doesn't commit you to it. Combined with a public codebase that anyone can inspect, Rainbow clears the two bars that separate a non-custodial wallet from something that merely markets itself as one.

Where the keys live, and what that means

Being self-custodial answers the question of who can freeze your funds and leaves a different one open. Rainbow's keys sit on a general-purpose device that browses the web, installs software, receives messages, and syncs to a cloud account. Everything that can reach the phone can, in principle, reach the signing material on it, which is the defining property of a hot wallet regardless of how carefully the app itself is written.

None of this is a criticism of Rainbow's engineering, because an application cannot be more trustworthy than the operating system underneath it, and phone malware, a malicious extension, or a convincing signing request are all threats the wallet is positioned to lose against rather than win.

The audit picture, stated fairly

Here the public record is thinner than it should be, and the sources disagree. Walletbeat's assessment states that Rainbow has not undergone security audits, and adds that the project runs no bug bounty and offers no documented route for researchers to report a vulnerability. Other reviews describe an audit some years back carrying an unresolved medium-severity finding.

What can be said without overstating it is that Rainbow does not publish a current audit the way some competitors do, so a reader cannot check the work. Open source helps, because code anyone can read is code anyone can find flaws in, but published third-party review of a specific release is a different assurance, and its absence is a gap rather than evidence of a problem.

Cloud backup and the password nobody writes down

Rainbow's recovery model is where users most often create trouble for themselves. The wallet encrypts your recovery phrase with a password you choose and stores it in iCloud on iOS or Google Drive on Android, which is convenient and introduces two new things that have to survive: the cloud account, and the password protecting the backup inside it.

Walletbeat flags the consequence directly, noting that recovery becomes impossible if the user forgets the backup password or loses access to the cloud account. Rainbow's own support material recommends keeping a manual copy of the 12-word phrase in addition to the cloud backup, which is sound advice and quietly concedes that an encrypted file in a Google Drive isn't a backup you can rely on by itself.

Worth noting is that a cloud account can be part of a backup without being the whole of it. TapSafe Recovery also puts material in your iCloud or Google Drive, with one difference that changes the failure mode: what goes up there is half of what a restore needs, so losing the cloud account costs you one share instead of the wallet. Rainbow's model asks a remembered password and a cloud login to both hold up for as long as you own the coins.

Rainbow's own advice points at hardware

The most telling thing about Rainbow's security posture is a warning the team gives about its own product. Rainbow supports connecting hardware wallets directly, with Ledger over WebHID and Trezor over WebUSB, and it tells users never to import a hardware wallet's recovery phrase into a hot wallet like Rainbow or MetaMask, because typing those words into phone software undoes the reason for owning the device.

Read that advice for what it implies about the architecture. The wallet's makers understand that the phone is the weak surface, and their recommendation for a balance worth protecting is to put the key somewhere the phone can't read it and let Rainbow handle only the interface. That's the same conclusion the rest of this article arrives at, reached by the people who built the app.

What a signing device changes

Pairing an interface you like with keys the interface can't extract is a reasonable way to hold crypto, and it's the arrangement a hardware wallet exists to provide. For Rainbow that means Ledger over WebHID or Trezor over WebUSB. Ryder One is not one of those options: it has no USB data path at all, and it signs through the Ryder app rather than a third-party interface. So the comparison worth making is not Rainbow with a sturdier key store bolted underneath it, it is Rainbow's keys on your phone against keys on a device built to do nothing else. What settles that comparison is how much you can verify on the device itself, because a signing device that shows you nothing useful is a rubber stamp with extra steps.

On Ryder One the private key is generated inside an EAL6+ certified Infineon SLC38 secure element and never leaves the chip, so there is no exportable copy for phone malware to locate. Each transaction is rendered in readable detail on the 1.6-inch AMOLED touchscreen before you approve it, and the button that authorises a signature is wired directly to the secure element, so no software path can produce a signature without a deliberate press. Communication is NFC only, with no Bluetooth radio, no USB data transfer and no Wi-Fi, so the device is unreachable except while held against your phone. The firmware has been audited by Halborn and the full report is public, which is the specific assurance Rainbow's record is missing.

Recovery, and the single point of failure

Every wallet discussed here eventually reduces to one question: if the device in your hand stops working tomorrow, what brings the balance back? Rainbow answers with a cloud file and a password. A conventional hardware wallet answers with a phrase written down somewhere, which moves the problem rather than solving it.

Keeping a seed phrase on paper keeps it away from every network and then asks it to survive damp, fire and a decade of house moves. Stamping the words into steel meets those hazards well and still leaves your whole position resting on one object staying intact and unfound, which improves your chances without altering the shape of the risk. TapSafe Recovery was built to take that single point of failure out of the design: half of what a restore needs lives on the Recovery Tag, and half travels with your paired phone, held encrypted in your own iCloud or Google Drive rather than on the handset. Neither half reveals anything usable on its own, and the two together rebuild the wallet. Recovery Contacts are optional, hold a quarter share each, and can see no balances or addresses at any stage. The phrase stays reachable on the device as a last resort under the BIP-39 standard, so moving to other hardware is always available to you.

So, is Rainbow Wallet safe?

For everyday amounts and on-chain activity, Rainbow is a well-built, self-custodial wallet that keeps you in control and lets you export your keys whenever you want. Its limits are the ones every phone wallet shares, sharpened by a backup model resting on a remembered password. For a balance you'd be upset to lose, the wallet's own documentation gives the answer: connect a signing device and let the app stay an interface.

Ryder One is 149 USD for the Starter Combo and 179 USD for the Super Safe Combo, with a Recovery Tag, wireless charger and pouch in the box, and setup takes about 60 seconds across three NFC taps.

Meet Ryder One

Meet Ryder One
Meet Ryder One

The only crypto wallet you can install on a crowded subway.
Set it up in less than 60 seconds and just tap your phone to send, swap, and recover.

Learn More