Bitcoin Education

Theya iPhone Mobile Key

An iPhone mobile key is one signing authority in a TBA collaborative 2-of-3 vault. Your iPhone holds a key. It does not hold the keys to your Bitcoin.

Losing your phone should mean restoring a key, not recovering your Bitcoin. Your iPhone key is designed to be recoverable. The other two keys are there so that failure of that recovery process does not have to be fatal.

Your iPhone

Client signing key for ordinary transactions. Protected by device security. Restorable from iCloud Keychain when backed up.

TBA

Independent signing authority. Normal second approval after you initiate a send.

Theya recovery key

Independent third signing authority reserved for recovery and exceptional circumstances in the TBA operating model.

Any two of the three keys must approve before Bitcoin can move. How collaborative security works →

Definition

What exactly is an iPhone mobile key?

Theya calls this a mobile key. In TBA vaults it is an iPhone signing key: one of three independent keys in your collaborative vault. TBA does not use Android for this client-key role.

Theya protects the active mobile key using the iPhone’s Secure Enclave and device security architecture. Face ID or your passcode authorises use of the key. Use a strong passcode and do not disclose it. Face ID can fall back to that passcode, so the passcode matters.

Theya can also use an iPhone mobile key for a standalone singlesig wallet. In that configuration the mobile key is the only signing authority, so its security characteristics are very different. This guide focuses on its use in TBA collaborative 2-of-3 vaults.

Design choice

Why we use iPhone mobile keys

Most TBA vaults use an iPhone mobile key as the client signing key. That is deliberate.

  • Low signing friction. You approve ordinary sends from the device you already carry.
  • Clients can operate the vault. A key people will actually use beats a more isolated key they leave in a drawer.
  • No separate device for day-to-day sends. Ordinary transactions do not require packing a hardware signer.
  • The mobile key is not the whole wallet. Usability does not require making the phone a single point of failure.

The objective is not to make one key perfect. It is to design the vault so that no one key needs to be perfect.

Architecture

Four layers that protect you

Keep each layer in its lane. Device security protects the active key. Backup makes that key recoverable. Apple Account hardening protects the restore environment. 2-of-3 makes failure of the whole client-key recovery path survivable.

1. Device protection

Theya protects the active mobile key using the iPhone’s Secure Enclave and device security architecture. Face ID and your passcode authorise signing.

2. iCloud Keychain backup

Provides recoverability of that client signing key if the phone is lost or replaced. This is the intended recovery mechanism. It is not the security foundation of the vault.

3. Apple Account hardening

Protects the recovery and account layer against takeover. Security keys add phishing resistance. They do not encrypt the backup themselves.

4. 2-of-3 collaborative security

Ensures that failure of the entire client-key recovery path does not automatically become loss of the Bitcoin. Emergency resilience, not the routine substitute for a backed-up client key.

Boundaries

What your phone cannot do

  • Your iPhone does not control your TBA vault by itself.
  • It cannot move Bitcoin without a second independent signature.
  • Losing your phone does not remove the other signing authorities.
  • Someone obtaining your phone does not automatically obtain control of the vault.
  • Neither TBA, Theya nor Apple holds or controls your Bitcoin on its own.
Restore path

What iCloud backup actually does

Three different things are easy to mix up. Separate them:

Active key

Protected on the iPhone by device security. This is what you use to sign.

Encrypted backup

Stored through iCloud Keychain so the key can be restored onto a replacement iPhone. Apple designs Keychain for end-to-end encryption.

Apple Account authentication

Controls access to the Apple ecosystem and recovery processes. Can be hardened with security keys. That is account defence, not what encrypts the backup.

When the phone is lost or replaced and the backup is available, restore the iPhone key and resume the normal signing path. Without a recoverable iCloud Keychain backup, loss or failure of the iPhone may require the emergency vault-recovery process instead of simple key restoration. A still-working phone with backup off is not yet an emergency.

Security keys materially improve resistance to Apple Account phishing and takeover. They protect the account and recovery environment, not the Bitcoin vault by themselves. YubiKey Security Guide →

Day to day

How signing normally works

Primary signing path: you sign with your iPhone key; TBA provides the normal second approval.

In the normal TBA workflow, you initiate the transaction. Two independent signing authorities must then approve it before the Bitcoin can move.

Theya holds an independent third signing authority that is reserved for recovery and exceptional circumstances in the TBA operating model. The Theya recovery key is not part of ordinary day-to-day recovery. How signing works →

Scenarios

What happens if…

If the iPhone key can be restored safely, restore it. Do not invoke the recovery key merely because the phone was lost, replaced or damaged.

Losing one mobile key does not by itself give someone the ability to move Bitcoin from a TBA 2-of-3 vault. The designed response is still to restore that key when you can.

Routine recovery

Lost phone, damaged phone, or a planned replacement. First objective: recover your iPhone key, not bypass it.

  1. Secure or lock the old device (Find My).
  2. Get a replacement iPhone.
  3. Restore the iPhone mobile key from iCloud Keychain.
  4. Confirm access.
  5. Continue using the normal iPhone + TBA signing path.

Contact your adviser if you need help confirming the setup. See the Lost iPhone Guide for the first-hour checklist.

Security event

A phone in the ocean and a stolen phone with a known passcode are not the same event.

Stolen phone or passcode exposure

Lock or erase the device remotely. Review Apple Account alerts. If the key is not believed compromised, restore-first still applies after you have a secure replacement. If you suspect the key was used or exposed, treat it as untrusted and contact TBA for vault recovery. Do not promise yourself that “Bitcoin is safe.”

Suspected key compromise

Treat that key as untrusted. This is vault recovery, not restore-and-resume. Contact TBA. Do not improvise.

Phishing or Apple Account compromise

Secure the Apple Account first. Contact your adviser. A compromised account can threaten Keychain restore even when the vault’s 2-of-3 policy still requires a second signature to move Bitcoin.

Lost iCloud access

If you still hold the original iPhone, the active key may continue to work. Keychain restore onto a new phone may not. That is when the emergency vault-recovery path becomes relevant.

iPhone key cannot be recovered

Contact TBA. Do not improvise. Invoke the documented collaborative recovery process. Remaining signing authorities rotate or rebuild the vault as appropriate. Key restoration failed; this is vault recovery.

Hygiene

How to secure your iPhone

In this order:

  1. Strong iPhone passcode (do not disclose it)
  2. Face ID
  3. Current iOS
  4. Find My enabled
  5. Verified iCloud Keychain mobile-key backup
  6. Strong Apple Account protection
  7. Security keys for enhanced phishing resistance (optional advanced hardening)

Passcode and device hygiene come before account gadgets. Backup is operational: it is how you return to the normal signing path after a lost or replaced phone.

Trade-offs

iPhone mobile key versus hardware signing device

Compare properties. Do not rank devices as simply “more secure.” The amount of Bitcoin is not what makes an iPhone key appropriate; the architecture around it is.

iPhone mobile key Hardware signing device
High usability Greater dedicated-device isolation
Usually with you Separate device
Cloud-restorable in the Theya model Seed/recovery procedure varies
General-purpose connected device Purpose-built signing device
Works as one authority in 2-of-3 Works as one authority in 2-of-3

Neither device choice changes the fundamental TBA security property: one client key cannot move the Bitcoin by itself. Hardware Wallet Guide →

Continuity

Your estate

A beneficiary should not need to understand Secure Enclave internals. They need the restore-first path and the documented vault-recovery path, plus clear records of which vaults use an iPhone mobile key and whether iCloud Keychain backup is enabled.

We document this in your Estate Plan Protocol. Estate Plan Protocol →

FAQ

Common questions

What happens if I lose my iPhone?

Restore the iPhone key from iCloud Keychain when you can. Resume iPhone + TBA. Do not invoke the Theya recovery key merely because the phone was lost. See Routine recovery.

Is iCloud Keychain backup required?

It is the intended restore path. Without a recoverable backup, loss or failure of the iPhone may require emergency vault recovery instead of simple key restoration.

Does a YubiKey make the mobile key safe?

Security keys harden Apple Account authentication. They protect the account and recovery environment, not the Bitcoin vault by themselves.

Is an iPhone key less secure than a hardware device?

Different properties, same 2-of-3 role. One client key cannot move Bitcoin by itself in either case. See the comparison.

What if the iPhone key cannot be restored?

Contact TBA. Do not improvise. That is vault recovery. See iPhone key cannot be recovered.

Review your iPhone mobile key

Already a client? Not sure how your iPhone mobile key is configured? Ask your adviser to review it with you.

Not yet a client? Book a consultation to learn how collaborative security works.

Educational only: no financial, tax, or legal advice. Seek appropriate licensed professionals where required. Device and backup behaviour follows Theya and Apple documentation as publicly described; internal cryptographic details of Theya’s Secure Enclave integration are not independently verified here.