Lithosphere News Releases

Thanos Wallet Has No ‘Forgot Password’ Email Link — and That’s the Point

Every web2 account trains users to expect a password reset email as the safety net. Thanos Wallet has no such flow, because the only entity that could send that email would be a third party holding a copy of the user’s keys — which is exactly what self-custody is built to avoid. Most people’s instincts…

Every web2 account trains users to expect a password reset email as the safety net. Thanos Wallet has no such flow, because the only entity that could send that email would be a third party holding a copy of the user’s keys — which is exactly what self-custody is built to avoid.

Most people’s instincts around account access were formed by decades of web2 software. Forget a password, click a link, receive an email, set a new one, and the account is accessible again. This pattern is so consistent across email providers, banking apps, and social platforms that it has become an assumed baseline for what account recovery is supposed to look like. A new Thanos Wallet user, encountering a wallet for the first time, may reasonably expect something similar to exist — and may be surprised, even concerned, to discover that it does not.

The reason it does not exist is structural, not an oversight. A ‘forgot password’ email flow only works because the service on the other end holds something that lets it verify identity and restore access — typically a copy of the account data, or at minimum the authority to reset the credential gating access to it. For that flow to exist in a wallet, the wallet provider would need to hold a copy of the user’s keys, or hold the authority to reset access to them. Either of those conditions describes a custodial relationship. It is precisely the relationship self-custody is built to avoid.

Thanos Wallet does not hold a copy of the user’s keys. The mnemonic and the keys derived from it are generated and stored locally, on the user’s device, inside the AES-encrypted vault. There is no server-side record Thanos Wallet could consult to verify who is asking for access, and no account database it could use to issue a reset. This is not a missing feature relative to what a web2 service would offer. It is the direct consequence of the wallet not custodying anything on the user’s behalf in the first place — there is nothing on Thanos Wallet’s side to reset, because there was never anything on Thanos Wallet’s side to lose.

The actual recovery mechanism in Thanos Wallet is the 12-word BIP39 recovery phrase established when the wallet is first set up. This phrase is the account, in every sense that matters for access. It is generated on the user’s device, it never leaves that device during normal use, and it is the only credential capable of restoring access if a device is lost, an app is reset, or a password is forgotten. There is no secondary channel, no backup authority, and no override — which is uncomfortable to a user accustomed to web2 safety nets, but is the honest shape of what self-custody actually requires.

This is why the recovery phrase, and not the wallet’s password, is the credential that actually matters. A forgotten password inside Thanos Wallet is a minor inconvenience, resolved with the recovery phrase. A lost recovery phrase with no backup is not resolvable by anyone — not by Thanos Wallet, not by KaJ Labs, not by any support channel, because no one besides the user ever held a copy of it to restore from. The absence of a password reset email is not really about the password at all. It reflects a wallet where the recovery phrase, not a login credential, is the only thing standing between a user and permanent loss of access — and that is exactly how a self-custody wallet is supposed to work.

Understanding this distinction changes how a new user should treat the recovery phrase from day one. It is not a password that a support team can reset if forgotten. It is not a credential recoverable through an email link. It is the entire account, existing in exactly one place until the user chooses to write it down somewhere else — and the absence of any fallback for losing it is not a gap in Thanos Wallet’s design. It is what makes the wallet genuinely self-custodial rather than custodial with extra steps.

 

Source: https://lithosphere.network/thanos-wallet-has-no-forgot-password-email-link-and-thats-the-point/