NexFlow › Is Coinomi safe
Is Coinomi safe? The wallet that spell-checked a seed phrase
Coinomi's file contains the strangest vendor-side leak in the wallet corpus: in 2019 its desktop app's spellcheck sent users' seed phrases to Google's API. The leak was real, the vendor's patch was immediate, the claimed $60–70K theft was never proven — and the company's response posture is as much a part of the record as the bug. One of crypto's oldest multi-chain wallets, and the one whose failure mode was an autocomplete.
What Coinomi is
Coinomi is one of the oldest multi-chain wallets in crypto — founded 2014, non-custodial, supporting hundreds of chains and tokens across mobile and desktop, with built-in swap integrations. It predates most of the brands users compare it against, and its longevity is genuinely part of its file: a decade-plus operating history with no documented server-side breach or mass-drain on the platform itself.
The custody model is standard self-custody: keys are generated and stored on the user's device, and Coinomi never holds them. Which is what made its one famous incident so strange — the leak happened not at the vendor's servers, but inside the user's own desktop app, on the way to a third party nobody expected to be in the loop.
February 2019: the spellcheck incident
On February 22, 2019, security consultant Warith Al Maawali reported that Coinomi's desktop wallet — built on the jxBrowser plugin — sent whatever was typed into the 'Restore Wallet' field to Google's spellcheck API. In effect, entering a seed phrase caused the application to transmit the entire phrase to googleapis.com. He produced a replicable video, and developer Martin Habovštiak publicly confirmed the behavior was real.
The vendor-side corrections that followed are documented and matter for accuracy: the phrase traveled inside an HTTPS request (Google as the sole recipient, not plaintext on the wire); it was only transmitted when a user explicitly pasted a seed into the desktop restore field; the spellcheck requests returned error 400 Bad Request and, per Coinomi's account of Google's response, were not processed, cached, or stored; and mobile apps were never affected. A jxBrowser update had already disabled the default spellcheck six days before the report; Coinomi patched all desktop versions immediately on disclosure.
The theft claim — proven bug, unproven causation
Al Maawali attributed a ~$60,000–$70,000 loss from his wallets to the leak and built avoid-coinomi.com to document the claim. The honest record separates the two claims: the transmission was demonstrated and confirmed; the causation was never established. Google's position — that the malformed requests were rejected and never stored — leaves the theft without a proven path through the spellcheck endpoint, and alternative explanations (endpoint malware, an unrelated compromise) were publicly proposed. Coinomi paid a bounty, fixed the code — and publicly called the reporter's conduct blackmail.
That last sentence is the part users should weigh. The bug was exactly the kind of unforced error a security-literate team should never ship — a financial application sending its most sensitive field to a spellchecker because a UI plugin defaulted wrong. And the response posture — deny the plaintext framing loudly, credit HTTPS, call the reporter a blackmailer — was aggressive enough that it became part of the story, obscuring a genuine question the incident raised and the company never answered well: how did a spellcheck come to sit on the seed field at all?
The honest read seven years on
The incident aged into something unusual: a real vendor-side failure with zero proven victim. No database leak, no mass-drain, no second report of the same class — the spellcheck path died six days before anyone was told, and the HTTPS wrapper meant the exposure was Google-facing, not internet-facing. Coinomi's decade-plus record has no other entry like it.
But the file still teaches the right lesson, which is about a class of failure rather than this one bug: desktop wallets are applications assembled from third-party UI components whose defaults the vendor inherits. The seed field's confidentiality depended on a browser-plugin configuration nobody had audited — the same structural lesson the BitMart private-key and Coldcard entropy files carry: the catastrophic paths are the ones nobody thought to put on the threat model.
The residual risks
For a Coinomi user today the operative risks are the standard self-custody set, plus one the incident made concrete: closed-source components inside a security-critical application. Coinomi's core is not fully open — users cannot verify what their seed field does or where it phones — so the trust model includes the vendor's own review process catching the next jxBrowser. The closed-core objection is the same one the Exodus file prices; Coinomi's incident is the case study of why it is a real cost rather than a philosophical one.
User-side vectors dominate the loss data as always: seed-phrase phishing, fake installers (the unsigned-binary complaint Al Maawali himself raised), and support impersonation. The company's in-app swap integrations add the usual counterparty window between 'self-custody' and 'trade executed'. None of this is distinctive to Coinomi — but the 2019 file is the reason 'what does the app do with my seed' is a fair question to ask of every desktop wallet, and Coinomi is where that question was proven to matter.
Where Coinomi stands
In the wallet tier, Coinomi is the 'old name with one ugly entry' file — an otherwise clean decade-plus record carrying a single incident that was simultaneously a real failure and an overblown claim. The verdict the record supports: the spellcheck leak makes Coinomi a worse answer than its marketing suggests and a better one than the headline implies — the bug was patched, the exposure was narrower than reported, the theft was never proven, and no second incident followed. A user choosing it today is buying a mature closed-source wallet whose one documented failure was the kind that only happens when nobody audits the defaults — and whose handling of being told is worth remembering every time a vendor's first response to a researcher is a lawyer-shaped adjective.
Frequently asked questions
Did Coinomi really send seed phrases to Google?
Yes — confirmed by the company and independently reproduced. The desktop wallet's jxBrowser plugin had spellcheck enabled by default, so text in the 'Restore Wallet' field — including seed phrases — was sent to googleapis.com inside an HTTPS request. Mobile apps were unaffected.
Was the seed sent in plain text?
Not on the wire — it traveled inside an encrypted HTTPS request with Google as the sole recipient. Coinomi says Google rejected the malformed requests (error 400) and never processed, cached, or stored them. The exposure was real but narrower than 'plaintext to Google' implies.
Did the bug actually steal $60,000?
The claimed theft was never proven. Warith Al Maawali attributed his loss to the leak, but no path was demonstrated through the rejected requests, and alternative explanations were publicly proposed. The transmission was confirmed; the causation was not.
Is the spellcheck bug fixed?
Yes — jxBrowser fixed the default six days before the report, and Coinomi patched all desktop versions immediately on disclosure in February 2019. No second incident of that class has been documented since.
Why did Coinomi call the reporter a blackmailer?
The company publicly described Al Maawali's conduct — payment demands alongside the disclosure — as extortion; he built avoid-coinomi.com in response. The aggressive posture is part of the record: it did not change the bug's reality, but it shaped how little the incident taught publicly.
Is Coinomi open source?
No — its core is closed, which is the incident's real legacy: users could not verify what the seed field did, and the spellcheck sat inside a third-party plugin the vendor had not audited. Closed-core means trusting the vendor's own component review.