Onboarding · login mechanics
Sign up and login, when there is no password to reset
In a self-custodial app, “login” does not mean what it means at a bank. There is no password on a server to reset, and no support agent who can let you back in. Here is what actually controls access — and how to keep it.
Read the recovery section before you create the account, not after. It is the only part of this page that is difficult to fix retroactively.
Before, during, after
- Before — Check eligibility, then install Confirm that your country of residence can use the features you want — the card in particular — and install only from links on the company’s own domain.
- During — Authentication, not a password A passkey or device credential replaces the password. Your face or fingerprint unlocks a key; it is not sent anywhere and cannot be reset by anyone.
- After — Second device, then funds Establish a working second device before you deposit anything larger than pocket change. That is your login recovery, and it is the step people postpone forever.
Next step
Create the account properly, in eight steps
Follow the order. Steps one, five and six are the ones that prevent the failures we see most often, and none of them involve money.
- Your phone
- A spare device or tablet
- A hardware security key or authenticator app
-
Check eligibility for the features you actually want
Wallet features are generally available; card programmes are not. Confirm your country of residence before submitting identity documents anywhere.
-
Harden the platform account first
Remove SMS recovery from the Apple or Google account that will sync your passkey. Add a security key or authenticator. Everything after this step inherits the strength of this step.
-
Install only from the official domain’s store links
Type the address yourself, follow its link, and check the developer name on the store listing. Never install from an ad, a search result or a code page.
-
Create the account and set up the passkey
Use an email you can reach from two devices. Let the passkey be created on-device and synced to your hardened platform account.
-
Configure every recovery factor the app offers
Guardians, additional devices, exportable backups — all of them, now, while it is boring. This is the step whose absence turns a lost phone into a lost balance.
Write the model on paper: which factors exist, where each lives, and how many are needed. Store it with your passport, not in the app.
-
Log in on a second device with the first one switched off
The test, not the theory. If you needed the powered-off phone to complete this, fix the setup before continuing.
-
Deposit a trivial test amount and send it back out
Deposit proves connectivity. Withdrawal proves control. Do both before you deposit anything you care about.
-
Only now complete card verification, if you want the card
Identity verification is a one-way disclosure. Do it once you know the account works and you have decided you want the fiat-adjacent features.
What “done” looks like
Two devices can log in. One index card describes your recovery. A test amount went in and came back out. You are now safer than most people who have used crypto for five years.
What each access factor actually controls
| Factor | What it unlocks | If you lose it | Where yours is |
|---|---|---|---|
| Email or social identifier | Account identity, notifications, support tickets | Annoying — usually recoverable | Fill in |
| Device passkey | Day-to-day login and signing on that device | Recoverable if it syncs, or via another factor | Fill in |
| Platform account (Apple / Google) | Passkey sync and restore on a new device | Serious — this is often the real key | Fill in |
| Second logged-in device | Independent access and recovery | Reduces you to a single point of failure | Fill in |
| Guardian or recovery share | Threshold recovery when devices are gone | Removes your last resort | Fill in |
| Exported backup, if offered | Portability to an independent wallet | Ties your access to this app existing | Fill in |
Note what is absent from this table: a password a company can reset. In self-custody, that row does not exist — which is the whole trade you accepted.
Two-line security reminder
Nobody — no support agent, no admin, no giveaway bot — ever needs your seed phrase or recovery share. Anyone who asks for it is stealing from you.
What “login” means when nobody holds your password
Two different systems get called login. Confusing them is how people end up locked out of money that is technically still theirs.
At a bank or an exchange, logging in proves to a server that you are the account holder. The server holds your balance, so it can also hold your password, reset it, and lock you out temporarily. Recovery is a customer-service process.
In a self-custodial app, logging in unlocks a key on your device. The balance is not on a server; it is on a blockchain, controlled by that key. Authentication is local, which means the failure mode is different: nothing is locked, but if no device can produce the key material, nothing can be signed either.
Tria sits in the second category while presenting the ergonomics of the first: a familiar sign-in screen, biometrics, no twelve words to transcribe. That is a genuine improvement for most people. It also means the mental model has to change — you are not remembering a credential, you are maintaining custody of one.
The sentence to keep in mind
If you can log in on a device you do not currently hold, you have an account. If you cannot, you have a session — and sessions end.
What you need before you start
A phone you control and keep updated, because the operating system is now part of your security model. An email address you can access from more than one device. A platform account — Apple or Google — with strong recovery settings, since that is where a passkey will sync.
If you intend to use the card, add two more requirements: an identity document, and a country of residence the card programme accepts. Independent card databases currently list the United States, China, India and Russia as excluded from Tria’s card, while Tria markets availability across 150+ countries. Verify your own case before you upload a document, because a rejected application still leaves your data with a verification provider.
One thing you do not need: money. Create the account, complete recovery setup, prove you can log in from a second device, and only then decide what to deposit.
- Device Updated phone, screen lock enabled, unique passcode.
- Platform account Apple or Google account with SMS recovery removed and a security key or authenticator added.
- Email Accessible from a second device; ideally protected by the same standard as the wallet.
- For the card only Identity document and an eligible country of residence.
The sign-up flow, and what each screen is really doing
The first screen creates or connects an identifier — an email, a phone number, or a social login. This is your handle within the app, not your custody. Losing access to it is inconvenient; losing your key material is fatal. Do not conflate them.
The second screen sets up authentication. A passkey is created on the device and, if your platform syncs passkeys, backed up into your Apple or Google account. This is where the strength of that platform account becomes the strength of your wallet.
The third stage — often optional at first — is where recovery factors are configured: additional devices, a guardian, or an exportable backup. Skipping this is the single most common onboarding mistake, because everything works fine until the day it doesn’t.
Verification for the card sits outside the wallet flow and typically comes later, when you order a card rather than when you create the account. That separation is normal and useful: you can hold and move crypto without ever submitting a document, and only the fiat-adjacent parts require identity.
Three settings to change in the first ten minutes
Defaults are chosen for onboarding conversion, not for your worst day. These three take minutes and remove most realistic attack paths.
First, harden the platform account that holds your passkey. Remove SMS as a recovery method, add a hardware security key or authenticator app, and check which devices are currently signed in. A SIM swap should not be one step away from your wallet.
Second, enable every notification for transactions and logins. Unexpected activity is only useful information if it reaches you within seconds. Silence is the attacker’s ally.
Third, review connected sites and session permissions, and revoke anything you do not recognise. In a smart-account wallet, a session key or approval is a standing permission that keeps working long after you have forgotten granting it.
If the app offers a spending limit, use it
Programmable accounts can enforce per-transaction or daily ceilings at the account level. A limit that matches your actual habits converts a catastrophic compromise into a survivable one, and costs nothing on the days when nothing goes wrong.
When you cannot log in
Work through causes in order of likelihood, because panic tends to skip the boring ones. Is the app updated? Is the device signed into the correct platform account — people commonly have two Google accounts and authenticate against the wrong one? Is biometric unlock failing at the OS level rather than in the app?
If the device is lost or replaced, this is not a login problem, it is a recovery problem: install the app on the new device and run the recovery flow with your remaining factors. Whether that works was decided weeks ago, when you either tested it or did not.
If a passkey has genuinely disappeared — deleted from the platform account, or a platform account you can no longer access — your remaining options are the other factors in the scheme: a second device, a guardian, an exported backup. If none exist, no support desk can help, and any message offering to help is an attack.
The lockout scam
People who post publicly about being locked out receive direct messages within minutes. Every one of them is a thief. Real support never initiates contact, never needs your recovery factors, and never asks you to share a screen.
Adding a second device — the step that makes the rest work
Treat a second logged-in device as a requirement rather than a convenience. It is simultaneously your recovery path, your test that recovery works, and your escape route if a phone is stolen while you are travelling.
Do it while your balance is small. Install the app on a tablet or spare phone, complete the flow with the primary device switched off, and confirm you can both see the balance and sign an outbound transaction. Being able to view a balance is not the same as being able to move it, and only the second one counts.
When you retire a device, remove it from the app’s device list and from the platform account. Old devices sitting in a session list are the reason people discover a compromise months late.
Fake login pages, and why they work
Crypto login phishing has moved on from misspelled domains. Current campaigns buy search ads on the app’s own name, clone the interface pixel for pixel, and ask for exactly what a real flow would ask for — plus one extra field, or one extra signature.
Two habits defeat almost all of it. Reach the app only through a bookmark you created yourself or the store listing you verified once; never through search results or ads. And treat any request that appears after an unexpected prompt — “re-verify your wallet”, “migrate your account”, “confirm ownership” — as hostile until proven otherwise.
Passkeys help here in a way passwords never could: a passkey is bound to a domain, so it will simply refuse to authenticate on a lookalike site. That protection only holds if you use the passkey rather than typing something into a form because the passkey “didn’t work”.
Closing the account, and what stays behind
Deleting an app account is not the same as deleting your on-chain history. Addresses, balances and transactions remain public permanently, and if you completed card verification, the identity link created during KYC persists in the records of the verification provider and the issuer under their retention obligations.
Before you leave, move funds out to a wallet you control independently, revoke approvals granted from those addresses, and export your transaction history for tax records. Then close the account through the app’s own settings rather than by simply deleting it from your phone, which leaves the account intact and unmonitored.
The verdict
The verdict on onboarding
Passwordless onboarding is a real improvement: it removes the seed phrase people lose and the password they reuse. It also relocates your risk into a platform account most people have never hardened. Spend twenty minutes on the account that syncs your passkey, establish a second device, and the rest of the flow is genuinely easy.
What works
- No seed phrase to transcribe, photograph or misplace.
- Biometric login is faster and far more phishing-resistant than a password.
- Wallet features work without identity verification; KYC is required only for card and fiat rails.
- Passkeys are domain-bound, so lookalike login pages simply fail.
What does not
- Your wallet inherits the recovery weaknesses of your Apple or Google account.
- No password reset exists, so an untested recovery setup is a silent single point of failure.
- Card verification permanently links identity to funding addresses.
- Session keys and approvals persist until revoked, and the list is easy to ignore.
- First crypto account of your life
- Good starting point — but do the second-device test the same evening you sign up.
- Migrating from a seed-phrase wallet
- Keep the old wallet for savings. Use this one for spending, and do not merge the two address sets.
- You share devices with family
- Do not. Biometric unlock on a shared device is not an access control.
- You travel constantly
- Second device is mandatory, and leave it at home. A stolen bag should not be a total loss.
FAQ
Frequently asked questions
How do I log in to Tria without a password?
Authentication uses a passkey or device credential unlocked by biometrics, rather than a password checked by a server. There is nothing to remember and nothing to reset — access depends on your device and the platform account that syncs the passkey.
What happens if I lose my phone?
You recover on a new device using your remaining factors: a synced passkey, a second logged-in device, or a guardian share. Whether this works is decided in advance, which is why establishing and testing a second device is part of the setup rather than an optional extra.
Do I need KYC just to create an account?
No. Wallet features in a self-custodial app do not require identity verification. KYC becomes necessary when you order a card or use fiat rails, because those are operated by regulated partners.
Can support reset my login?
No, and this is the defining property of self-custody. No support desk can restore access, which also means no support desk can be tricked into giving your access to someone else. Anyone offering to reset it is attempting fraud.
Is signing in with Google or Apple safe for a crypto wallet?
It is as safe as that account. Remove SMS recovery, add a hardware security key or authenticator app, and review signed-in devices. Once the platform account is properly protected, this model is safer for most people than a seed phrase in a drawer.
Can I use the same account on two phones?
Yes, and you should. A second logged-in device is your recovery path and the only reliable way to verify that recovery works. Set it up while your balance is still trivial.
How do I spot a fake Tria login page?
Reach the app only via your own bookmark or a verified store listing, never through ads or search results. A genuine passkey refuses to authenticate on a lookalike domain, so if a login page asks you to type something instead of using your passkey, close it.
How do I delete my account?
Move funds to a wallet you control, revoke approvals from those addresses, export your transaction history for tax purposes, then close the account in the app’s settings. Deleting the app alone leaves the account open and unwatched, and your on-chain history remains public regardless.