PayMe Wallet Security
20 August 2026
Protect where future payments are sent.
A plain-English guide to PayMe Wallet Security, Authenticator setup, recovery codes, receiving-wallet changes, and lost-wallet recovery.
The protection model
X identifies the profile. Wallet Security protects the destination.
A PayMe link joins a verified X identity to a receiving wallet. Wallet Security adds a separate approval layer before that wallet can be replaced. It is designed for the recipient who owns and manages the PayMe link; it does not change how a payer sends money.
Initial enrollment needs the current receiving wallet, a standard Authenticator app and confirmation of its six-digit code. Later wallet changes need the PayMe account, Authenticator or a recovery code, and a signature from the new wallet.
Set it up while you control the wallet
Four clear approvals. No payment transaction.
01
Connect the current wallet
Open Wallet Security from the PayMe account and connect the wallet that currently receives payments. A different wallet cannot approve enrollment.
02
Approve the one-time message
Sign the short-lived security message with the current receiving wallet. No payment transaction is sent and no funds move.
03
Add PayMe to Authenticator
Scan the QR code or enter the manual key in a standard TOTP Authenticator app, then enter the current six-digit code.
04
Save the recovery codes
Store every single-use recovery code somewhere private. They provide the backup route when the Authenticator device is unavailable.
If the wallet is on another device, copy the short-lived approval link into that wallet browser, sign there, and return to the original security page. The approval is limited to the pending enrollment and expires automatically.
Changing wallet later
The old wallet can be lost. The protection must already exist.
Open Wallet Security from the X-authenticated PayMe profile.
Enter a current Authenticator code or one unused recovery code.
Connect the new receiving wallet and sign its wallet-binding message.
Confirm the change. Future PayMe payments use the newly verified wallet.
The old wallet signs only when protection is first established. Requiring it again during recovery would make recovery impossible when that wallet is genuinely inaccessible.
Recovery scenarios
Know your route before you need it.
You control the current wallet and have not enabled Wallet Security
Enable it now. The current wallet must approve initial Authenticator enrollment.
The old wallet is inaccessible and Authenticator is already enabled
Use Authenticator or an unused recovery code, then sign with the new wallet. The old wallet is not required again.
The Authenticator device is unavailable
Use one saved recovery code. Each recovery code works once.
The old wallet is inaccessible and Wallet Security was never enabled
Self-service replacement is blocked. The existing PayMe link continues to use its current destination.
Authenticator and all recovery codes are lost
Self-service replacement is blocked.
Practical rules
Treat recovery codes like keys.
Save recovery codes before leaving setup. They are shown once and each one works once.
Do not keep the Authenticator secret and recovery codes in the same unprotected account that controls the PayMe profile.
Hilt never asks for a seed phrase or private key. Repeated invalid security-code attempts are rate-limited.
If a code expires, wait for the next code and try again. If a wallet approval expires, restart setup and use the newest approval link.