How Holdix reads your wallet
A public address is all a wallet needs, and an exchange needs a read-only API key — Holdix can look, never move.
Only a public address
A wallet address is public: anyone can open it on a block explorer and see what it holds. That is all Holdix needs to track a wallet. Holdix never asks for your seed phrase (recovery phrase) or private key, and nobody from Holdix ever will. Anyone who asks you for one is trying to take your funds.
Read-only by nature
An address lets you read a wallet, never spend from it. Holdix cannot move, sign or approve anything in your wallet, and nothing you do in Holdix sends a transaction.
Where the data comes from
To read a wallet, Holdix looks the address up with public blockchain services: block explorers (Blockscout, Etherscan, Routescan) and public nodes for EVM networks, Blockstream for Bitcoin, TronGrid for TRON and TonAPI for TON. They see the address being looked up, just as they would if you opened it on their own site. Prices come from CoinGecko and are looked up by coin, never by your address.
What Holdix imports
— Balances on every network the wallet is tracked on. — The transaction history, as far back as the source provides it. — DeFi positions — lending and liquidity — on EVM networks. — NFTs from TON wallets. When you add an EVM wallet from the dashboard, Holdix first checks which networks it is used on and tracks those. You can change the networks later in the connection's settings.
Exchanges: a read-only API key
An exchange is connected with an API key. Create the key with read permission only — never trading, and never withdrawals. Holdix only reads balances and history; it never places orders or withdraws. Holdix does not check a key's permissions for you, so choosing read-only when you create the key is what makes it safe. Keys are encrypted with AES-256-GCM, under a key of their own for each user, before they are stored, and they are never sent back to your browser.
Removing a connection
Delete a connection on the Connections page and Holdix deletes its balances, transactions, Earn plans and DeFi positions, together with the stored API key. For an exchange, also delete the key on the exchange itself — that is the only place it can be revoked.
Related Articles
Create a read-only Binance API key to connect your account securely.
How to create OKX API keysCreate a read-only OKX API key with a passphrase to connect your account.
How to create Bybit API keysCreate a read-only Bybit API key with the correct permissions to connect your account.