Your digital wealth, private and tamperproof.
OISY is a sovereign wallet that works in any browser. It holds crypto, stocks, commodities, collectibles, and encrypted notes, and it lets you trade, earn, borrow, and pay. You sign in with your face or fingerprint, and the network signs on your behalf using threshold cryptography, so the key that authorizes your assets is never assembled anywhere, by anyone.

One secure wallet that holds your digital wealth, keeps it private, and puts it to work.
It opens in a browser tab on any device you have signed in on. Every asset you hold sits in one place across eight networks, setting up asks nothing about you, and the things people usually leave the wallet to do can be done inside it.
Your whole portfolio in one place
Crypto, stablecoins, tokenized stocks and commodities, collectibles, and encrypted personal notes, held across eight networks and shown as a single balance. The assets are the real thing rather than wrapped substitutes.
Private and tamperproof
Sign in with your face, fingerprint, or a security key. Setting up asks for nothing about you. Hide every balance on screen with one keystroke, and every connected application waits for your explicit confirmation before anything moves. Invisible, if you need it to be.
Earn, borrow, and trade
Put assets to work, borrow against what you hold, or trade at a price you set, with an assistant that prepares and schedules transactions from plain instructions and waits for your confirmation.
What we set out to build.
Three goals: one wallet across every network you use, a security model that retires the secret you are asked to guard, and the ease of an ordinary consumer application.
The first goal was the multichain problem. Holding assets on several networks has meant a separate wallet for each one, a separate extension to install, and a separate phrase to write down and protect. Almost none of that work has anything to do with owning something, and all of it falls on the holder.
The second was harder. Self custody has asked people to guard a secret perfectly for years and to trust software they installed from a store, and those two requirements are where most losses come from. OISY is built so that neither is needed: your identity is the passkey already on your device, and the key that authorizes your assets exists only as shares held by independent machines that never bring them together.
The third was that it should feel ordinary. OISY opens like a website, works the same way on a phone as on a desktop, and covers what people actually do with digital wealth in one interface. It was incubated at the DFINITY Foundation and released as open source, so anyone can read the code, audit it, or run their own copy.
Manage
Crypto and stablecoins across eight networks, tokenized stocks and commodities, collectibles, and encrypted personal notes that open only on your own device. One balance covers all of it, with a per-network breakdown a click away. Saved contacts and addresses reduce the most common expensive mistake in this field, which is sending money to the wrong place.
The eight networks are Bitcoin, Ethereum, the Internet Computer, Arbitrum, Base, BNB Smart Chain, Polygon, and Solana, which covers BTC, ETH, SOL, ICP, and the tokens and stablecoins issued on each of them, including USDC and USDT wherever they are held. The tokenized stocks come from Ondo Global Markets and xStocks on Ethereum and Solana, where each token is backed one for one by a real share held with a regulated custodian. Everything sits in one list, and moving between networks is a matter of choosing a destination rather than learning a new tool.
Trade
Swap takes the best price available at that moment across more than 100 liquidity sources. OISY Trade adds limit orders, so you can name the price you are willing to accept and wait for it, rather than taking whatever the market offers. Both settle on the network, so nobody holds your money while an order sits open.
Earn and borrow
Put assets to work through a short list of vetted products, or borrow against what you already hold instead of selling it. Rates, terms, and the health of a borrowing position are shown in the wallet itself. Your assets stay under your own control throughout, and you can withdraw on the terms stated before you commit.
Spend
OISY Pay settles ordinary purchases with a range of the assets you already hold in the wallet, rather than with one currency chosen for you. In Switzerland that includes groceries at SPAR, paid by scanning the code at the till. The merchant and the amount are shown before you confirm.
Ask and schedule
A built-in assistant takes plain instructions. Ask it what you hold, tell it to send 5 ICP to Satoshi, or set a transfer to repeat every month, and it prepares the work for you to check. Every transaction waits on your confirmation, including the scheduled ones. Balances, addresses, and amounts are assembled inside OISY on your own device and stay there, out of the model’s view.
Reach
A phone app reaches you through a store that can restrict it by country, hold up a release, or remove it altogether. OISY reaches you through the network, which keeps the same wallet open on a phone, tablet, or desktop, in any country, for as long as you want to use it. Nobody stands between you and your own assets, because there is no channel left for anyone to close.

Wallets break in four different places.
The cryptography behind crypto holds. What fails sits around it: the screen you approve on, the code you install, the phrase you are told to guard, and the holder.
Crypto is usually described as secure, and the mathematics itself largely is. The losses come from everything arranged around it. Chainalysis found that compromised private keys were the single largest source of stolen crypto in 2024, accounting for 43.8% of all value taken. Of the $1.1 billion lost across 212 verified incidents in the first half of 2026, Blockaid attributes 74% to failures around the code rather than in it: compromised devices, privileged credentials, private keys, signing systems, and off-chain infrastructure. The key is the biggest single category. It is not the only one, and in the largest theft on record the key was never touched.
One: the screen shows one thing, the transaction does another
On 21 February 2025, roughly $1.5 billion left a Bybit cold wallet. No contract was broken and no key was cracked. Attackers had compromised a developer’s laptop two weeks earlier, reached the servers behind the signing interface Bybit’s team used, and quietly altered the code those servers were sending out. The screen showed a routine transfer. The transaction that was actually signed rewrote the wallet’s logic and handed control to the attacker. Two minutes after it cleared, the altered code was removed again.
Every signer did their job. They approved what they were shown. This is the oldest trick in the book performed on software: a protected key is worth little if the display in front of you is under somebody else’s control.
Two: the software you install is assembled from strangers
A browser extension or a phone app is code running on your own machine, built from hundreds of third-party components you never chose and cannot inspect. In September 2025, attackers took over the publishing account of a single maintainer and pushed altered versions of 18 widely used packages, downloaded more than 2 billion times a week between them. The added code did one thing: watch for a crypto transaction in the browser and silently replace the destination address with the attacker’s. Everything on screen looked normal.
The stores that distribute this software are a weak filter. In July 2026, three people sued Apple over a counterfeit Bitcoin wallet listed on the App Store. According to the complaint, the app stayed available for more than a week after a $875,000 theft was reported, and a second user lost about $840,000 to it before it came down. The allegations have not been tested in court. The same gatekeepers hold the other end of that power: they can geo-restrict a wallet, delay it, or remove it from your device entirely, on their own initiative.
Three: a secret that nobody can recover for you
A seed phrase is 12 or 24 words that serve at once as your only proof of ownership and your only backup. Write it down and it can be found. Keep it on a device and it can be read. Forget it and the money is gone, with no appeal and nobody to call. Chainalysis research has put the number of permanently unreachable Bitcoin at between 2.8 and 3.8 million, lost along with the keys behind them. Ledger’s own chief executive has said plainly that self custody will never scale while the next hundred million users have to save 24 words.
Four: the owner becomes the easiest way in
A key you hold personally makes you personally worth attacking. Confirmed cases of holders being physically coerced into surrendering their keys reached 72 in 2025, up 75% in a year, with losses above $40.9 million. Once one person can hand over everything, that person is the attack surface.
Hardware answers one of the four
A hardware wallet protects the key well, which is the third failure. It does not confirm that what appears on your screen is what you are about to approve, which is the first. It does not help when the software connecting the device to an application is the part that was compromised: a 2023 attack on Ledger’s own connection library drained more than $600,000 through a fake prompt, while every device involved worked exactly as designed. And it makes the fourth failure sharper rather than softer, because the whole key now sits with one person in one room.
Owning your own assets is the right goal. The way we have been asked to do it, with a secret to guard and software to install and trust, is the part that keeps breaking.
OISY began with these four failures and was built to answer all of them at once. The wallet is served by the network rather than installed on your machine, your identity is the passkey already on your device, and the key that authorizes your assets exists only as shares held on independent machines that never come together in one place. The next section is how that works.
Why such a wallet could only be built on the Internet Computer.
Four properties have to be true at the same time for this to work: network custody of the key, a complete application that is tamperproof and always-on, sign-in without a password, and native reach across other networks. Only one place offers all four.
Network custody
Every wallet needs a key to authorize a payment. The real question is where that key lives. In an ordinary wallet it lives in one place: a file, a phrase on paper, a chip in a device. Wherever it lives is what an attacker goes after, and what you can lose.
OISY distributes the key instead of storing it. When you create a wallet, the Internet Computer generates it already split into shares, spread across independent machines run by different operators in different jurisdictions. The complete key is never assembled, not for an instant, and not even during setup. To produce a signature, enough of those machines run a cryptographic protocol together, each contributing part of the answer, and what arrives on Bitcoin or Ethereum is an ordinary, valid signature.
This answers the third and fourth failures. A single theft, a single accident, or a single person under pressure reaches one fragment, which on its own authorizes nothing. Commercial custody services split keys into shares too, but the shares sit with parties one company selects, on terms that company sets and can revise. Here they sit with independent node operators on a public network, and the signer that brings them together answers to the network’s own governance rather than to a provider.
A complete application, tamperproof and always-on
The Internet Computer runs the whole wallet: the screen you look at, your data, and the part that signs. There is nothing to install. When you open oisy.com the network sends you the wallet itself, so everyone is looking at the same version.
Two things decide whether your assets can move: the sign-in that proves you are you, and the signer that puts your approval on a transaction. The network runs both of them, under rules its own users vote on, rather than a company. So your assets move when you say so and not otherwise, and OISY and the DFINITY Foundation cannot move them at all. Anyone can read the code.
This answers the first two failures. There is no copy of the wallet on your machine, so the altered package that quietly swaps a destination address has nothing to slip into, and nothing to search for in an app store, where the counterfeit sits beside the real thing. And because the network keeps serving it, the wallet stays reachable in every country and on every device, with no store to approve it, geo-restrict it, or take it away. Ordinary infrastructure gets you part of this at best: the frontend still sits on a company server that somebody can change, and the mobile app still passes through a gatekeeper.
Even the web address is not load-bearing. oisy.com is a signpost to the wallet, and your assets sit on their own networks rather than inside OISY. If the domain expired or was hijacked tomorrow, the wallet and the assets would be unaffected, because neither of them lives there.
Sign in with what you already have
Access runs through Internet Identity, which replaces the password with a passkey held on your own device and released by FaceID, TouchID, or a security key. You can also start from a Google, Apple, or Microsoft account you already use. Personal information stays out of it, and each application you sign in to with Internet Identity sees a different pseudonym, so your activity stays unlinkable from one service to the next. Because access is tied to your identity rather than to one machine, the same wallet opens on your phone, tablet, and desktop.
Multichain, natively
Because the network holds keys and signs with them, it can sign directly on Bitcoin, Ethereum, Solana, and the other networks OISY supports. The Bitcoin in your wallet is Bitcoin, sitting on Bitcoin. The alternative everywhere else is a bridge or a custodian standing in for the asset, which is a second thing that can be attacked and a second party to trust. Holding the real asset across eight networks in one balance is a direct consequence of the network being able to sign for itself.
Take any one of these four away and the wallet reverts to the model described in the previous section. Together they are what make OISY possible, and the Internet Computer is where they exist at the same time.
Create your OISY wallet in under 60 seconds.
Go to oisy.com and choose Open or Create. Sign in with a passkey, or with a Google, Apple, or Microsoft account. The wallet exists straight away, ready to receive, with the setup handled by the network on your behalf. Open the same address on another device, sign in, and the same wallet is there.
To use OISY alongside other applications, connect through WalletConnect or the Internet Computer signer standards. Teams building their own application can integrate OISY with IdentityKit for React or the signer SDK, both covered in the documentation.
Discover more unique apps built on the Internet Computer.
Caffeine
Build apps and websites by chatting with AI. The platform writes the backend in Motoko, deploys to the Internet Computer, and guarantees no silent data loss.
Read about CaffeineOpenChat
Sovereign social networking. Real-time messaging running entirely inside the Internet Computer, controlled by its community via SNS DAO.
Read about OpenChat