PayMe Wallet Security
Wallet Security adds a second approval layer to changes that affect where future PayMe payments are sent. Your X account identifies the PayMe profile. Your current receiving wallet proves that the person enabling Wallet Security still controls the existing destination. A standard Authenticator app or a saved recovery code then protects future wallet changes.Wallet Security does not move funds, send a transaction, reveal a seed phrase, or give Hilt signing authority. A receiving-wallet change affects future PayMe payments only.
What it protects
Without Wallet Security, access to the verified X account is not enough to replace the receiving wallet. Once protection is enabled, a wallet change requires:- access to the PayMe profile
- a current six-digit Authenticator code or one unused recovery code
- a signature from the new receiving wallet
Before you start
You need:- an active PayMe link
- access to the wallet that currently receives payments
- a standard TOTP Authenticator app
- a safe place to store the recovery codes shown at the end
Set up Authenticator protection
- Connect the current receiving wallet. Choose the wallet already shown on the security page. Hilt checks that it matches the active PayMe destination.
- Start Authenticator setup. Hilt creates a short-lived, one-time wallet approval.
- Approve with the current wallet. Sign the security message. This is a message signature, not a payment transaction.
- Add PayMe to your Authenticator app. Scan the QR code or enter the manual setup key.
- Enter the six-digit code. Use the current code from the Authenticator app to finish enrollment.
- Save every recovery code. Each recovery code can be used once if the Authenticator app is unavailable. Hilt does not show these codes again.
Approve from another wallet browser
If the current receiving wallet is on another device or in a wallet browser, choose Copy link for another wallet browser. Open that short-lived link in the current receiving wallet’s browser and sign the one-time security message. Return to the original PayMe security page afterward. It detects the approval and reveals the Authenticator setup automatically. The approval link expires and cannot be used to change the receiving wallet. It authorizes only the pending Authenticator enrollment.Change the receiving wallet
After Wallet Security is enabled:- Open pay.hilt.so/me/security from the PayMe account.
- Enter a current six-digit Authenticator code or one unused recovery code.
- Continue to the new wallet step.
- Connect the new receiving wallet.
- Sign the wallet-binding message with the new wallet.
- Confirm the change in the authenticated PayMe browser.
Recovery scenarios
Security boundaries
- An X account on its own cannot enable Authenticator protection without approval from the current receiving wallet.
- Control of the current receiving wallet on its own cannot replace the destination without the authenticated PayMe flow and the required second factor.
- Recovery codes are single-use. Store them offline or in a trusted password manager.
- Repeated invalid Authenticator or recovery attempts are rate-limited.
- Hilt never asks for a seed phrase or private key.
- Hilt does not sign payment transactions for a payer.

