Wallet & security
Deposits, withdrawals, recovery phrases and account protection.
Fees, timeouts and confirmation counts on this page are read from the running platform configuration.
What is my QTC wallet?
An ordinary Quantus account with its own 24-word recovery phrase, created by the platform when you first sign in. The phrase is stored encrypted (AES-256-GCM) under a key the platform holds, and decrypted in memory only to sign a transfer or to show you an export.
Your balance is read from the chain, not from an internal ledger: what the explorer shows at your wallet address is what you have.
How do I deposit QTC?
Send QTC from any wallet to the address shown in the app. It counts after 6 Quantus confirmations. There is no deposit fee and no memo.
The available balance is the on-chain balance minus the account minimum Quantus requires and a small reserve for network fees.
How do I withdraw?
From the wallet page: enter a destination Quantus address and an amount, plus the 6-digit code from your authenticator app if you turned two-factor on. The destination must differ from your platform wallet address. The transfer is signed from your wallet; linked Telegram accounts receive a withdrawal notification. Two-factor authentication is optional.
Limits: 10,000 QTC per rolling 24 hours, one withdrawal in flight at a time, and a 24-hour hold after a security change: two-factor enabled, Telegram link changed, password reset. QTC locked in an open trade cannot be withdrawn.
Can I export my recovery phrase?
Yes (with your authenticator code if two-factor is on). The 24 words import into the official Quantus wallet. The export is logged, notified in Telegram, subject to the same 24-hour hold as withdrawals, and unavailable while one of your trades is waiting for its lock to confirm.
Anyone with the phrase controls the wallet, and the platform keeps its copy: exporting gives you a way out, it does not remove the platform’s access. To hold QTC that only you control, withdraw it to a wallet you created yourself.
How does two-factor authentication work?
It is a standard time-based code (Google Authenticator and compatible apps). It is optional. Once on, it is asked to withdraw, to export your phrase, to change your Arbitrum address and to disable two-factor itself. Telegram only notifies; it never authorises a withdrawal.
Enabling it gives you 10 single-use recovery codes, shown once: keep them offline. 5 wrong codes lock the check for 15 minutes.
I lost my authenticator. What now?
Use one of your recovery codes wherever a 6-digit code is asked. Each works once. With it you can disable two-factor and set it up again on a new device, which gives you a fresh set of codes.
Setting it up again starts the 24-hour hold on withdrawals and exports. Trading is not affected.
Without the app and without a recovery code there is no self-service reset: write to support, and expect to prove the account is yours. A phrase you exported earlier still opens the wallet in the meantime.
How are sessions handled?
A sign-in creates a random session token kept in an httpOnly cookie; only its hash is stored. Sessions expire after 30 days without activity. Settings lists your active sessions and lets you revoke any of them. Every Telegram sign-in is announced in your chat with the bot.
Telegram sign-in uses a one-time code shown by the bot. Email and password sign-in is available only when enabled by the deployment; the app shows the available methods.