Is Abstract Global Wallet Safe? Where the Keys of an Email-Login Wallet Live
Abstract Global Wallet (AGW) needs no seed phrase written down, just an email login. That does not mean there is no private key: according to the official architecture docs, the key is split into three shards kept in different places. Here is how it works, what its security depends on and what to watch for.

What kind of wallet AGW is
AGW is Abstract's cross-application smart-contract wallet, built on the chain's native account abstraction. You sign up once with an email, a social account or a passkey, and the same account then works across Abstract apps, including the Abstract Portal and its XP program.
It works only on Abstract. The official FAQ explains that because of technical differences between Abstract and other EVM chains, its tooling is not chain-agnostic and runs only on Abstract.
If you sign in with email, where is the private key?
The architecture documentation describes a two-step setup. When you sign up, an ordinary wallet address (an EOA) is created for you in the background. A smart-contract wallet is then deployed with that address as its approved signer.
The ordinary wallet comes from a Privy embedded wallet: a secure random value becomes a 12-word mnemonic, and the private key is derived from it. The key is never stored whole in one place. It is split into three shards with Shamir's Secret Sharing, and any two of them can rebuild it:
- Device share: kept on your device; in a browser, in the local storage of Privy's embedded page.
- Auth share: encrypted and stored on Privy's servers, retrieved when you sign in with your original method.
- Recovery share: stored in a backup location you choose, typically a cloud account such as Google Drive or iCloud.
What its security depends on
No single shard can rebuild the key, and Privy holds only one, encrypted. Two combinations deserve attention:
- Your login plus your device together hold two shards. If the email or social account you sign in with is compromised while someone also controls your device, the wallet is at risk.
- On a new device, recovery uses the auth share plus the recovery share, so the security of your cloud account matters just as much.
Part of AGW's security therefore sits in your email, social and cloud accounts. Turn on two-factor authentication for each, avoid signing in on shared computers, and never sign in to AGW from a page you did not open yourself.
What app "session keys" are
Some games and high-frequency apps ask to create a session key. Once you approve it, the app can submit transactions on your behalf within a predefined scope of actions, without a confirmation prompt each time, until the key expires or is revoked.
According to the documentation, creating a session key requires your approval, keys expire after the duration set when they are created, and on mainnet an app must pass a security review before it is added to the session key policy registry. Even so, check the app, the scope and the duration before approving, and grant session keys only to apps you trust.
Transfers and where to keep funds
- An AGW address is a smart-contract account on Abstract. On other chains, the same address is not necessarily controlled by you, so do not send assets from other chains straight to it. Use an officially supported route or bridge to move funds across chains.
- AGW suits the funds you need for Abstract apps. Larger long-term holdings are better kept in a wallet whose seed phrase you hold yourself, or on a hardware wallet.
- Whatever wallet you use, never share a seed phrase, a private key or a login verification code with anyone.
Related reading: what a seed phrase is and why you never share it, token approvals and how to revoke them.