Guarda Wallet review
Last reviewed 2026-08-25
Security warning
Guarda is a competent multi-chain wallet with an unusually honest incident report, and that report points straight at the thing to be careful about. On December 30, 2020, an attacker took over Guarda's account at its domain registrar, GoDaddy, repointed the DNS for guarda.co and guarda.com, and put up a page "designed exactly like our homepage" whose only feature was a backup upload form. Users of the desktop, web and Chrome extension versions who uploaded a backup handed over their addresses and private keys. Mobile app users saw only transaction delays, because the mobile app's resources sat on subdomains the attacker had not repointed.
Guarda's CEO published the timeline himself, with the registrar's own logs attached: two factor authentication removed at 11:55 with no login event recorded before it, then the email address, phone number and PIN all changed. Guarda notified users on social media within minutes, sent documents to GoDaddy inside half an hour, filed statements with the Estonian Cyber Police and Financial Police, and says its engineers kept the phishing page erroring for around 90% of the window before it recovered the account that evening. It pointed at KrebsOnSecurity's reporting on GoDaddy staff being used in attacks on cryptocurrency services as the likely explanation.
Note what was not breached: nothing of Guarda's own. The lesson is structural, and it survives the incident. A wallet whose flow includes "upload your encrypted backup to our website" is one DNS record away from a convincing fake, and no amount of local encryption helps when you hand the file over yourself. If you use Guarda, use the desktop or mobile app, and never enter or upload a backup on a web page, whatever the address bar says.
The product today is broad. Guarda has been operating since 2017 and claims on its own site more than 70 blockchains, over a million supported tokens and over a million active users. It runs on Windows, macOS and Linux, on iOS and Android, as a web app and as a Chrome extension. It buys with cards and Apple Pay, stakes on 14 networks, supports multisig, lends against holdings, and now carries third party perpetual futures and prediction markets inside the wallet. Bitcoin is supported, but this is a wallet for people who hold a lot of different things.
- Made by
- Guarda
- Type
- Software wallet
- Runs on
- iOS, Android, Windows, macOS, Linux, Browser extension
- Who holds the keys
- self-custodial, keys generated on your device and encrypted under a password you choose
- Bitcoin only
- No, multi-asset
- Released
- 2017
- Coin support
- Bitcoin plus more than 70 blockchains, by Guarda's own count
Pros and cons
What works
- Guarda's CEO published a dated, detailed account of the 2020 attack, including the registrar's own logs
- Runs on Windows, macOS, Linux, iOS, Android, a web app and a Chrome extension
- Keys are generated locally and encrypted under your own password, and Guarda never holds them
- Staking on 14 networks, multisig support and 24/7 live support, per Guarda's own site
- Buying built in with cards and Apple Pay across a wide asset range
What to watch
- The web and extension flow involves uploading your backup file, which is precisely what the 2020 phishing page was built to collect
- The 2020 breakdown came through a domain registrar account, a dependency Guarda does not control and cannot audit
- Third party perpetual futures and prediction markets now sit inside the wallet, which is more moving parts than holding bitcoin needs
- The user, token and blockchain counts are Guarda's own figures, published on its own homepage
- A hot wallet with no hardware signing of its own
Worth comparing
- ExodusThe best looking wallet on this list, from an NYSE listed company, with closed source apps and swap rates starting at 0.5%.
- Trust WalletUse the phone app, think twice about the extension: an attacker published a malicious build of it on December 24, 2025.
- ElectrumThe oldest bitcoin wallet still in active development, and the one whose users are hunted by a fake-update scam running since December 2018.
Frequently asked questions
What happened to Guarda in 2020?
On December 30, 2020, an attacker took control of Guarda's GoDaddy account, changed the DNS records for guarda.co and guarda.com, and served a copy of Guarda's homepage whose only function was a backup upload form. Users who uploaded a backup had their keys stolen.
Were Guarda mobile users affected by the 2020 attack?
No. Guarda's disclosure says mobile app users only experienced transaction delays, because some of the app's resources sat on subdomains that were unavailable. The theft hit desktop, web and Chrome extension users who uploaded their backups to the fake page.
Is Guarda non-custodial?
Yes. Keys are generated on your device and encrypted with a password you choose, and Guarda states it never has access to them. Nothing about the 2020 incident involved Guarda holding user keys.
Is Guarda safe to use now?
No further compromise has been disclosed since December 2020, and the failure then was at its registrar rather than in the wallet. Use the installed desktop or mobile app rather than the web version, and never upload a wallet backup to any web page.