Security
What happens to the money your customers send, who can move it, and how your integration can check that every message really comes from us. This page describes what exists today, nothing more.
How your balance is held
easyway is a custodial gateway. Payments arrive on addresses controlled by easyway; once confirmed, the amount (minus the fee) is credited to your balance in our ledger, and it stays with us until you withdraw it to a wallet of your own. If you prefer not to hold a balance with us, withdraw regularly, by hand or through the API.
Funds are split between a hot wallet, which pays out day-to-day withdrawals, and a cold wallet on a hardware device that never touches a server. Everything above what the hot wallet needs is moved to cold storage.
Keys stay off the API server
The server that answers the API and the dashboard holds only watch-only public keys: it can derive a fresh deposit address for every invoice, but it cannot spend from any of them. Transactions are signed by a separate signer process on its own machine, which accepts no inbound network connections and only picks up withdrawal jobs that the API has already checked.
When a payment counts as paid
A payment is credited only after enough blocks have been built on top of it for the network to consider it final. For TON, the Bitcoin family, the XRP Ledger and Solana, a payment is additionally confirmed against a second, independent data source before it is credited.
| Network | Confirmations | How payments are matched |
|---|---|---|
| TRON | 19 | A new address for every invoice |
| BNB Smart Chain | 15 | A new address for every invoice |
| TON | 1 | One address, comment per invoice |
| Ethereum | 12 | A new address for every invoice |
| Bitcoin | 2 | A new address for every invoice |
| Litecoin | 4 | A new address for every invoice |
| Dogecoin | 6 | A new address for every invoice |
| XRP Ledger | 1 | One account, destination tag per invoice |
| Solana | 1 | A new address for every invoice |
| Polygon | 64 | A new address for every invoice |
| Avalanche | 10 | A new address for every invoice |
| Dash | 4 | A new address for every invoice |
Who can withdraw
Two-factor authentication
Accounts support time-based one-time codes (TOTP, RFC 6238), which work with Google Authenticator, Authy, 1Password and similar apps. In live mode, a withdrawal, adding a withdrawal address, and creating an API key that can send payouts all require 2FA to be switched on and a fresh code.
Address whitelist
Live withdrawals can only go to addresses you have added to your whitelist in the dashboard, and each new address triggers an email notice to the account owner. A withdrawal requested through the API is held to the same list, so a leaked API key cannot send your balance to anyone else's wallet.
Activity log
Sensitive actions (API keys created or revoked, whitelist changes, 2FA changes, withdrawals requested) are recorded with the time and IP address, and you can review them in the dashboard.
API keys
Secret keys are shown once, when you create them, and stored only as a keyed hash. Each key carries scopes (for example invoices:write without payouts:write) and an optional IP allowlist. Test and live keys are separate, and test keys never touch a blockchain.
Signed webhooks
Every webhook carries an X-Webhook-Signature: t=…,v1=… header: an HMAC-SHA256 of the timestamp and the raw body, made with your endpoint's secret. Checking it (and rejecting old timestamps) proves the event came from easyway and was not replayed. Failed deliveries are retried 8 times with growing delays over about 45 hours. Verification code for Node.js, PHP and Python is in the webhooks documentation.
Reporting a vulnerability
If you find a security problem, email support@easyway.cash with the details and how to reproduce it. Please give us a chance to fix it before telling anyone else.