AllSwap| Crypto Swap
FAQ

Who holds the private key or controls the assets at a one-time deposit address?

Under the currently confirmed product architecture, AllSwap does not generate an order's one-time deposit address and does not hold its private key or equivalent authority to transfer assets on-chain. The paying user does not own that key either. Transfers are authorized and executed by the on-chain settlement mechanism of the underlying market-maker network. Its specific technical design and controlling legal entity have not been publicly disclosed, so this arrangement must not be described as “controlled by no one” or “absolutely safe.”

How is private-key control different from AllSwap's ability to manage an order?

A private key is the secret credential normally used to sign a transaction from an externally owned blockchain account. Assets governed by a smart contract may instead move according to contract rules, administrator permissions, or another equivalent form of execution authority; there may not be a single conventional private key for the address. The practical question is therefore broader: who has the actual ability to initiate or authorize an on-chain transfer of the funds?

In the current AllSwap flow, the application layer aggregates quotes, creates and displays orders, presents the one-time deposit address and any required Memo, reads settlement status, and helps coordinate with the underlying settlement network when something goes wrong. Being able to display an address, retrieve an order status, or coordinate an investigation does not give the application the ability to sign for the address or redirect its assets.

The confirmed technical boundary is that AllSwap neither generates nor stores the key for the one-time deposit address. Its application code has no signing wallet or execution path that can unilaterally transfer, freeze, or pause the deposited funds. The underlying settlement network generates the address for the particular order and returns it, while its on-chain mechanism executes subsequent asset movements. The AllSwap security overview explains this application-layer non-custodial boundary. However, the fact that the application cannot transfer the funds must not be expanded into a claim that the underlying layer has no controller or authority.

Who controls the assets at each stage?

Swap stage or addressWho has practical controlWhat it means for the user
Source wallet before paymentThe holder of the source wallet's private key or account permissionsThe assets have not left the wallet, so the user can choose not to pay. Creating an AllSwap order or seeing a countdown does not transfer control to AllSwap.
One-time deposit address and funds in settlementThe on-chain settlement mechanism of the underlying market-maker network holds the private key or equivalent transfer authorityThe user cannot use the source wallet key to withdraw the deposit, and the AllSwap application cannot move it. The funds proceed through settlement, refund, or exception handling for that order.
Destination assets after a successful swapThe controller of the destination recipient address entered by the userIf it is the user's self-custody wallet, the user controls the received assets. If it belongs to another person or an exchange, that address or account controller has control.
Refund when a refund address was enteredThe controller of the refund address specified in the orderControl passes to that address holder only when the actual refund transaction reaches the address on-chain.
Refund when no refund address was enteredAllSwap's platform fallback refund address receives it first, creating an operational control stepThe user must contact official support and provide genuine, verifiable proof of payment. After the claim passes review, the platform manually sends the refund. Completion is determined by actual on-chain receipt at the user's final address.

Two distinctions are particularly important. First, control of the source wallet before payment does not mean the sender can cancel a transfer after it has been confirmed on-chain. Most confirmed blockchain transfers cannot be recalled by the sender, and AllSwap has no signing authority to reverse a user's source-chain payment. Second, the application layer's inability to move funds at the one-time address does not mean AllSwap has no operational role in every possible outcome. When an order has no refund address, funds first reach the platform fallback address, and the later proof review and manual refund clearly involve platform operational control.

What underlying control details remain undisclosed?

There is not enough public, verifiable evidence to determine whether each one-time deposit address and route uses any particular one of the following arrangements:

  • a single on-chain key or institutional wallet;
  • multiparty computation (MPC) or multisignature authorization;
  • a smart contract executing predefined rules;
  • a solver, market maker, or another settlement participant with control;
  • a combination of those mechanisms, including the identity of anyone holding administrator, pause, or emergency permissions.

These architectural choices can produce different exposures to settlement failure, compromised keys, smart-contract vulnerabilities, human intervention, and misuse of privileged permissions. In the absence of a published architecture, permission inventory, or independently verifiable audit evidence, users should not infer that the underlying process is fully automatic, beyond intervention, absolutely decentralized, or free of custody-related risk. AllSwap's non-custodial statement establishes that its application layer does not hold the private key for the one-time address or have a unilateral transfer path. It does not eliminate the need to assess the underlying settlement network, blockchain congestion, liquidity conditions, and operational risk. The AllSwap risk disclosure provides more context on those boundaries.

How can a user verify control and the final result?

  1. Use only the address returned by the current official order. Confirm that the browser hostname is allswap.io, then check the order ID, source network, source asset, exact amount, one-time deposit address, and countdown. If the order returns a deposit Memo or Tag, both the address and Memo/Tag must be correct. Do not use an address sent separately through a social-media message, search advertisement, or an unverified support account.
  2. Keep source-wallet credentials private before payment. A normal payment only requires the user to sign the outgoing transaction in the source wallet. Neither AllSwap support nor a settlement investigation requires the wallet's private key, seed phrase, password, one-time authentication code, or remote access to the device. Anyone requesting those credentials may be trying to take control of the source wallet.
  3. Preserve source-chain evidence after payment. Save the order ID, one-time deposit address, and source-chain transaction hash (TxID). On a trusted block explorer for the relevant network, verify that the recipient, token contract, amount, and any Memo match the order. The source-chain TxID proves that the payment occurred; it does not by itself prove that the destination assets were delivered.
  4. Use the final transaction to establish where control ended up. For a successful order, verify the destination-chain TxID and actual recipient address. For a refund, verify the final refund TxID. If no refund address was entered, an inbound transaction to the platform fallback address does not mean the user has received the refund. The user must complete order ownership and payment-evidence review, then confirm the later on-chain transfer from the platform to the user's final address. See the AllSwap refund process for the applicable procedure.
  5. Stop sending additional funds if there is an exception. If a confirmed payment is not recognized, an order remains in processing for an unusually long time, a successful order has not arrived, or a refund status has no corresponding final transaction, do not pay the one-time address again. Preserve the order details, transaction hashes, and redacted screenshots, then use an official channel listed in the AllSwap Help Center to request an investigation.

In short, AllSwap's ability to view an order and coordinate exception handling is an application service. The ability to sign for a one-time deposit address, or otherwise move its funds under an on-chain mechanism, is an underlying settlement authority. Separating these two types of authority helps users understand AllSwap's non-custodial boundary without overlooking the real control risks in settlement and in the platform fallback refund route.