Recently, we received an email notification that our snap was flagged as “potentially malicious” and changed to private status. We would like to politely dispute this flag, as “ukey-wallet” is a completely safe, fully decentralized (non-custodial) crypto wallet.
Here is some context regarding the nature of our application that might have triggered the automated scanner:
Fully Non-Custodial: All user private keys and seed phrases are generated and stored locally on the user’s device using industry-standard cryptography. We never upload or collect any sensitive user data.
Network Requests: The wallet needs to interact directly with decentralized blockchain RPC nodes to broadcast transactions and fetch balances, which may have flagged the network activity monitor.
Local Encryption: The application uses local system storage to keep encrypted wallet data, which may request standard storage plugs.
We have absolutely no malicious intent. We are fully willing to cooperate with the security team:
If the snap requires any specific interface adjustments (plugs/slots), please let us know.
If you need to audit our source code or reproducible build process, we are happy to provide it.
Could you please review our snap revision or provide detailed feedback on what specific content/behavior triggered the restriction?
Thank you for your time and help in keeping the ecosystem safe.
Thank you for reaching out. You will need to become a Verified Account in advance to publish legitimate crypto related snaps. You can follow the process below.
Thank you for the clarification and for providing the Verified Publisher policy.
Our Snap developer account was registered using UKey Wallet’s legal company information, and our company details have already been submitted.
We understand that developer account registration is separate from Verified Publisher status. We will create a new post in the policy-requests category and provide our snap package details, company name, role, shared group email address, and relevant information about our relationship with Canonical and Snapcraft.
As we have not yet established a formal partnership with Canonical, we would appreciate guidance on how to start this conversation and satisfy the requirements for publishing a legitimate cryptocurrency wallet.
Raising a request for verified accounts is the start of establishing partnership with Canonical . Please go ahead with creating that request and policy-reviewers (don’t forget to tag them in your request) will review it.