What is an embedded wallet? Who holds the key
An embedded wallet is one an app creates at sign-up. Who can sign with it, what you can export, and how the Cherry Wallet's screens describe its own key.
What is an embedded wallet? It is a wallet an app creates for you inside its own sign-up, usually behind a Google, Apple, email or passkey login, so you never install a separate wallet app. What differs from one to the next is who can produce a signature and whether you can take the wallet with you. Cherry, the wallet-to-wallet messenger and community app for crypto, creates one called the Cherry Wallet when you sign up in its web app with Google, Apple or X.
How an embedded wallet works
Providers’ developer docs, read in October 2026, describe three common ways to hold the key:
- Key shares split between your device and the provider. Dynamic keeps a user share on the device and a server share that takes part in signing inside a trusted execution environment, so no complete key sits in one place. It also offers optional password encryption of your share and warns that someone who loses the password cannot recover that share.
- A provider-run secure enclave. Privy stores keys as two encrypted shares and reconstructs a key only temporarily, inside a trusted execution environment.
- A passkey-controlled account. Coinbase’s docs say one passkey works across every Base-enabled app, with no seed phrase.
Among chat apps, dm.fun gave each user an embedded wallet made by Privy (as of January 2026), and Towns gave every account one (as of September 2026). Base App, renamed back to Coinbase Wallet on 10 September 2026, offered a Base Account smart wallet behind a passkey and an email (as of July 2026).
Who can sign: three models
| Model | Who can sign | How you move the wallet elsewhere |
|---|---|---|
| Your own wallet app | You, in software you run | Import the seed phrase or private key into another wallet app |
| Embedded wallet held through an app | You, through the app’s login and the provider’s service | Export the key where the app allows it; Privy’s docs let the app turn export off |
| Custodial account | The company | No key to move; the company sends the funds to an address you give it |
The exit test
Ask one question of any embedded wallet: can you export a phrase or key and sign with it in another wallet app? Privy’s docs let the user copy the full private key, unless the app turns export off, and point to loading it into MetaMask or Phantom. With no export, the wallet works only while the app does.
Example on Cherry
In the Cherry web app, a Google, Apple or X sign-up reaches a screen titled “Your Cherry Wallet”: “Every Cherry ID has a wallet for mini apps and tips.” You set a password (“Cherry can’t reset it, so keep it safe.”) and press “Create my wallet”. Its How it works list reads, as of October 2026:
- “Your password becomes the key. Cherry never sees it.”
- “Nothing leaves this wallet without your password or biometrics.”
- “So you can sign in on another device. Locked with your password; we can’t read it.”
A Google, Apple or X sign-up does not show the recovery phrase. In Settings, the wallet’s row reads “Save your recovery phrase to sign in with this wallet” with a “Save it” button. When the web app makes a Cherry Wallet during onboarding instead, its recovery-phrase screen says “Twelve words that restore the wallet on any device.” and warns: “Anyone with these words has your wallet. Cherry will never ask for them.” A “Download backup file” button sits beside it. Deleting your account brings the line “Save your recovery phrase first if you want to keep the wallet.”
The recovery screens name no other wallet app. Before relying on the phrase elsewhere, import it into a second wallet and check that the address matches.
Related terms
- Cherry ID : the account that holds the Cherry Wallet and your linked wallets.
- Seed phrase : the words that rebuild a wallet.
- Sign In With Solana : signing in with a wallet you already own.
- Seed Vault Wallet : the Solana Seeker’s built-in wallet.
- Wallet identity : how a wallet you bring becomes your profile.
- Cherry vs dm.fun : an embedded-wallet chat app compared.
FAQ
Is an embedded wallet self-custodial?
It depends on who can produce a signature and whether you can export the key. Coinbase’s and Dynamic’s developer docs call their embedded wallets non-custodial and say users can export their keys (October 2026); the test for any app is whether you can sign without it. For the Cherry Wallet, the Cherry web app’s sign-up screen says “Your password becomes the key. Cherry never sees it.”
Sources
Try Cherry
Sign in with a wallet, DM any address, and join token-gated and paid communities. No phone number, email, or KYC.