Skip to content
buybitcoinsmart

Zengo review

Last reviewed 2026-08-25

Security warning

There is no private key to steal and no seed phrase to phish, because neither ever exists in one place: Zengo's model splits signing between a share on your phone and a share on its server. The flip side is a live dependency on Zengo as a company, and a recovery path that runs through your email, your cloud storage and your face rather than through something you can write on paper and lock in a safe. Zengo also states that deleting your account is irreversible and takes the addresses with it.

Pick Zengo if losing or leaking a seed phrase is the risk that actually worries you, and go in understanding what replaces it. There is no recovery phrase in Zengo at all. Using threshold cryptography, it creates two independently generated mathematical secret shares instead of one private key: one lives on your phone, the other on Zengo's server, and by Zengo's own description they are never exposed to each other. Signing a transaction is a conversation between the two in which neither reveals its secret, so Zengo cannot move your money on its own, and you cannot sign without Zengo's server being there. That last clause is the trade. A seed phrase works offline forever; a share needs its counterparty.

Recovery is three factors, not a phrase: your email, a recovery kit file you keep in your own iCloud, Google Drive or Dropbox, and a 3D FaceLock selfie. Zengo stores an encrypted copy of your device share and says it cannot use it; your cloud file holds the code that decrypts it, and the face scan releases it. You need all three, which is why Zengo lets you register a second email, a second cloud copy and a second trusted selfie. It is candid about the limits too: it notes that an identical twin who also had your email and recovery file would be a moderate risk, and that deleting your Zengo account is permanent, taking the addresses and any funds in them with it.

The headline claims are Zengo's own. Its homepage says "Never hacked" and "2+ million wallets secured since 2018", and its help center says the MPC cryptography is open source, audited and peer reviewed while the wallet app around it is not. Nothing independent confirms the clean record; it is a company saying so on its own site, which is worth exactly what that is worth.

As a bitcoin wallet it is fine and unremarkable: bitcoin sits among the thousand-plus assets it supports, buying runs through partners like MoonPay, Banxa, Paybis and Transak, and the app has since grown a prediction markets feature. Mobile only, no desktop, and support is inside the app around the clock.

Made by
Zengo
Type
Software wallet
Runs on
iOS, Android
Who holds the keys
self-custodial MPC, with no seed phrase: one secret share on your phone, one on Zengo's server, never combined
Bitcoin only
No, multi-asset
Released
2018
Coin support
Bitcoin among 1,000+ assets, including Ethereum, Solana, TRON and stablecoins

Pros and cons

What works

  • No seed phrase exists, so there is nothing to write down, photograph, or be tricked into typing
  • Two independently created MPC shares, one on your phone and one on Zengo's server, that are never combined
  • Three factor recovery, with a documented option to register a backup for each of the three
  • Zengo says its MPC cryptography is open source, audited and peer reviewed
  • Support is available 24/7 from inside the app, which is rare in self-custody

What to watch

  • Signing requires Zengo's server, so the wallet depends on the company staying reachable in a way a seed phrase does not
  • The wallet app itself is closed source; only the cryptography underneath it is published
  • Recovery runs through your email, your cloud account and a face scan, which is three dependencies instead of one piece of paper
  • Never hacked and 2+ million wallets are Zengo's own claims on Zengo's own homepage, with no independent confirmation
  • Mobile only, with no desktop app and no hardware signing

Worth comparing

Frequently asked questions

Does Zengo use a seed phrase?

No. Zengo replaces the private key with two mathematical secret shares, one on your phone and one on its server, so there is no phrase to write down. Recovery uses your email, a cloud recovery kit and a face scan instead.

Can Zengo access my crypto?

No. Zengo's help center states that only you can initiate a transaction and that it cannot access the device share on your phone, which is required to sign. It also stores an encrypted copy of that share for recovery, which it says it cannot use on its own.

How do I recover a Zengo wallet on a new phone?

You need all three of your original factors: the email you signed up with, the recovery kit file in your iCloud, Google Drive or Dropbox, and a successful 3D FaceLock scan. Zengo supports moving between iPhone and Android using the Google Drive copy.

Is Zengo a good place to keep bitcoin savings?

It removes the most common way beginners lose coins, which is mishandling a seed phrase, and that is a real benefit. For savings you do not touch, a hardware wallet keeps the key fully offline and depends on no company at all.