01 Nobody owns these contracts
Most apps that hold money have an administrator — someone with a master password who can freeze an account, reverse a payment, or move the money somewhere else. Usually that is a feature. It is also the single thing you are trusting when you hand money to a company: that nobody abuses the master password, and that nobody steals it.
Splitsy's contracts have no administrator. Not a locked-away one, not a committee-controlled one — the ability does not exist in the program. There is no function that changes the rules, so there is no key that could call it. This is checkable rather than promised: the code is public, and the three things below are absences you can confirm for yourself in §05.
- No owner, no admin
Nothing in these contracts asks who is calling and treats one address as special. A Splitsy employee has exactly the powers you do.
- No upgrade
The rules cannot be swapped out later. What the contract did the day it was published is what it will do forever. Changing anything means publishing a different contract at a different address, in public.
- No pause, no freeze
There is no stop button, because a stop button is something a person has to be allowed to press. Your ability to get your money out does not depend on Splitsy staying online, or staying in business.
- No way to empty the pot
There is no "withdraw everything" and no way to destroy a contract while holding funds. Money is only allowed to leave along the routes written into the program: back to whoever put it in, or on to the person they named. There is no third door.
02 Money held for someone who hasn't joined yet
You can pay someone who has never heard of Splitsy — you just type their email address or handle. But a person who hasn't signed in yet has no wallet, so there is nowhere to send the money. It waits in a contract called HandleEscrow until their first sign-in creates one.
This is the part people are rightly suspicious of, because for a while the money is in neither person's hands. So here is the whole arrangement. Four things are true while it waits, and none of them require trusting Splitsy to behave.
You can take it back, at any moment
One click, any time before it is collected. You need nobody's permission and there is no waiting period, no review, and no deadline after which you lose the right. The contract asks a single question — are you the person who put this money in? — and if the answer is yes it sends it straight back. Nothing can stand in the way of that: not Splitsy, not a server being down, not even someone who has stolen Splitsy's keys. It is the one door that is never allowed to be locked, which is exactly why it has no limits of any kind on it.
Paying it out needs a note that fits one deposit only
When the recipient signs in, Splitsy signs a short note that says, in effect: deposit number 41 goes to this one wallet, and this note stops working at this time. The contract will not pay out without it, and it checks every part. The note cannot be edited, cannot be pointed at a different wallet, and cannot be used twice — the moment it works, the deposit is erased from the contract, so a second attempt finds nothing there and fails.
Every deposit runs out
30 days after you pay in, the pay-out door closes permanently. From then on the only direction the money can move is back to you. In practice Splitsy returns unclaimed deposits long before that — but the deadline is written into the contract rather than into our habits, so it holds even if Splitsy stops running entirely. The point of it is that the amount sitting in here can never quietly pile up over years.
There is a hard ceiling on what can leave in a day
The contract will not pay out more than 2,000 USDC in any twenty-four hours. This is not a policy we follow — it is a wall the program enforces, and it applies to a genuine pay-out and a fraudulent one identically. If the worst case in §04 ever happened, this is the thing that would hold the damage to one day's worth, in public, while everyone else took their money back.
A deposit larger than that ceiling is refused when you try to make it, rather than accepted and then stuck. Better to be told no at the start than to find out later with the money already in.
03 Nothing moves without your approval
No Splitsy contract can reach into your wallet and help itself. Before any of them can move a single cent, you have to approve it, and the approval happens in your wallet's own prompt — a screen Splitsy does not control and cannot fake. If you never approve anything, nothing can ever be taken.
- An approval names one contract
You are not giving "Splitsy" permission. You are giving one specific program permission, for an amount you can see. Nothing else inherits it.
- You can cancel it
Set the approval back to zero at any time and the permission is gone. You do not need Splitsy's cooperation, or Splitsy's existence, to do it.
- A recurring tab can only ever pay one address
The address that gets paid is fixed when the tab is created and cannot be changed afterwards. A compromised Splitsy could not redirect your rent to itself.
- What you sign is what gets sent
When your own wallet signs a payment, our server compares the signed transaction against the one it asked you to sign, and refuses to broadcast if they differ. Without that check, someone could sign anything at all from their own wallet and have Splitsy record a debt as settled.
- An automatic payer spends only its own pocket money
If you set up an agent to pay a bill for you, it spends from a balance you transferred to it. Splitsy holds no permission on your own wallet on its behalf — so that balance is a hard ceiling no rule, bug, or broken server can go past.
- Nobody sees other people's debts
When you open a bill you are shown your own share. Amounts are on a public network and so are checkable by design, but the app does not put other people's business in front of you.
04 What could still go wrong
Everything above is what the contracts guarantee. A security page that stops there is a sales page. Here is the rest of it — the weak points we know about, described as plainly as the strong ones, because you cannot judge the first three sections without them.
The one key we hold, and exactly what it could do
Somebody has to decide which wallet belongs to alex@example.com, and that somebody is Splitsy. We hold a single key whose only job is to vouch for that link. It is the one piece of trust in the whole system that is placed in us rather than in the code.
So assume the worst: the key is stolen. What the thief gets is the ability to send money that is currently waiting in escrow to a wallet of their choosing. That is bad, and we are not going to dress it up. But it is worth being exact about the shape of it, because the boundaries are real and they are enforced by the contract rather than by us noticing in time:
- It cannot touch your wallet
The key has no power over your own balance, your approvals, or anything you have not already sent into escrow. It can only misdirect money the escrow is already holding.
- It cannot claw anything back
Payments that have already arrived somewhere are finished and out of reach.
- It cannot beat you to the exit
Taking your deposit back has no limits and needs nobody's approval. Anyone who reclaims gets their money, and that is the actual recovery plan.
- It cannot exceed the two walls
The daily ceiling and the expiry in §02 are not permission checks, so a stolen signature meets them exactly as a real one does. That is the whole reason they exist.
The honest version of our recovery plan: the key cannot be swapped out, because swapping it would require an owner and an owner is the thing we refused in §01. If it ever leaked, the answer is that everyone reclaims their deposits and we publish a fresh contract. That is a race, and somebody near the front of it could lose money. We would rather tell you that now than imply a safety net that isn't there. The planned improvement is to move the key inside sealed hardware so that not even we can read it — which changes where the key lives and nothing else.
The rest of the list
- No outside audit yet
The contracts have extensive tests of their own and are checked by automated analysis tools, but no independent security firm has reviewed them. Treat them accordingly.
- There is no undo
No pause, no rescue, no reversing a payment sent to the wrong person. Read §01 again if that matters to you — it is the price of the thing that makes the rest safe.
- An email address is not a wallet
To write down a debt against someone who hasn't joined, we turn their handle into an address. Nobody holds the key to that address — it does not have one. So it is used only to record what is owed, never to receive money. Money goes to the escrow in §02 instead.
- Receipt scanning guesses
The scanner reads a photo and works out the items. It gets things wrong. Check the numbers before you send a split — it is a time-saver, not an accountant.
- Your wallet is still yours to protect
Nothing here defends you against approving a payment you did not read, or against losing access to your own wallet. Read every prompt before you confirm it.
- Bridging depends on others
Moving USDC in from another network relies on your wallet signing each step and on Circle's own systems confirming it. Those parts are outside Splitsy.
05 Check all of this yourself
None of this needs taking on faith, and you do not have to be a programmer to check the parts that matter most. Every claim above is either in the code, which is public, or on the network, which anyone can read.
The contracts this site is actually using
These are read from the running configuration, not typed into this page, so they cannot drift from what the app really writes to. Open one and you can see every payment it has ever made.
Reading it yourself
- The source
Every contract, with the reasoning written into it as comments — contracts/.
HandleEscrow.solopens with a plain description of its own trust model, including the weakness in §04. We put it there before we put it here. - The tests
HandleEscrowSecurity.t.sol and HandleEscrowBounds.t.sol exist to prove the promises in §02 — including that a reclaim can never be blocked and that a reused note always fails.
- The two limits, live
The hold window and daily ceiling printed in §02 were read off the escrow itself when you loaded this page. Ask it the same questions and you will get the same answers.
- Your own receipt
Each bill carries a fingerprint of the receipt photo it came from. Before paying, the app recomputes it and shows you whether it matches what was recorded — so a split cannot be quietly edited after the fact. See bill verification.
If you find something wrong
Tell us before you tell anyone else and we will fix it. Reports go to security@splitsy.xyz — also published at /security.txt. If you believe a payment of yours has gone somewhere it shouldn't, reclaiming your waiting deposits is the first thing to do and it needs nothing from us.
