SECURITY & CUSTODY

You Hold the Key. Once.

Photon is non-custodial, which sounds reassuring until you notice what it means in practice: the private key appears on screen exactly once, nobody can restore it for you, and the fastest way to lose everything is landing on a clone of the site. All three are covered here.

The One-Time Private Key Reveal

When you sign up, Photon generates a dedicated Solana wallet and shows you its private key a single time, behind a reveal slider. There is no second chance to view it, no recovery phrase flow and no account-recovery process. Copy it into offline storage and confirm you have it before you navigate away from that screen.

Tiny Astro's Terms of Use are explicit about the consequence: the company "has no way of granting you access to the site if you lose access to, or control of, your Wallet," and you are "solely responsible for maintaining the security of your account and control over any usernames, passwords, public and/or private keys." Read that as written. There is no support ticket that undoes a lost key.

One nuance worth flagging as unverified: Photon is reported to hold an encrypted session copy of your key so it can sign trades fast enough to be useful. The mechanism is not documented anywhere in Photon's own material, so we cannot describe it accurately and neither can anyone else. Treat the practical implication as the safe one: this is a hot wallet in a browser, not cold storage, and it should hold trading capital rather than savings.

Exporting to Phantom

The key you saved is a normal Solana private key, and importing it into Phantom works. That is not a workaround, it is the documented flow: Photon publishes no native iOS or Android app, and its own mobile documentation says the terminal "is best experienced on the Phantom Wallet Browser," meaning you import the key into Phantom and open Photon from Phantom's in-app browser. The same import is how you move funds out to somewhere you control more fully.

A practical setup that costs nothing: keep a separate long-term wallet, ideally on hardware, that never touches Photon, and treat the Photon wallet as a float you top up. Photon supports up to five wallets per account with archiving and split deposits, so segmenting inside the platform is easy too. Wallet-to-wallet transfers are not taxed by Photon, so moving profits out costs only network fees.

Fake Photon Sites Are Real and Documented

Security researchers at PCRisk have published a write-up of a fake-Photon website operating at speedtrade[.]icu. It mimics the real interface, and connecting a wallet triggers a silent drainer. That same write-up identifies photon.tinyastro.io as the genuine platform. A second suspected impersonator has surfaced at a lookalike domain reusing Photon's exact tagline, "Your Trusted Platform for Token Discovery & Trading."

Every genuine Photon deployment sits under tinyastro.io: the Solana terminal at photon-sol.tinyastro.io, plus BNB Chain and Base deployments on their own subdomains. There is no official photon.trade. Watch for the hyphen-versus-dot trick specifically, where a phishing domain swaps photon-sol for something like photon.sol and counts on you not looking.

Before you connect anything: read the hostname character by character, not the page. A drainer clone looks identical by design. Bookmark the real URL once and use only the bookmark, never a search result, a DM link or an ad. And remember there is no Photon token, so any "claim," "presale" or "airdrop" page using the name is a scam by construction.

What Has and Has Not Happened to Photon

No hack or exploit of Photon itself has been documented. Searches for a Photon or Tiny Astro breach return nothing, and the August 2022 Solana wallet drain that occasionally gets attached to Photon in search results traces to a seed-phrase leak in the Slope wallet, affected roughly 8,000 wallets, and predates Photon entirely. There is also no sourced allegation that Photon sandwiches its own users; Solana MEV is a real and well-documented phenomenon, but nothing ties it to this platform.

Two commonly repeated security claims do not survive checking. Third-party reviews say Photon offers two-factor authentication; it appears nowhere in the Terms of Use, Settings or mobile documentation, so treat it as unverified. And some negative reviews describing missing deposits may well come from users who were on a phishing clone rather than the real site, which is a reason to read complaint threads carefully rather than a reason to dismiss them. Where a fix is genuinely in your hands, the troubleshooting section covers it.

Wallet Hygiene That Actually Matters Here

  • Save the private key offline at signup. This is the only irreversible step in the whole setup.
  • Never paste the key into a website, a form, a support chat or a DM. No legitimate Photon channel will ask for it, and the official X account is @tradewithPhoton.
  • Keep the Photon wallet funded like a float, not like a vault. Sweep profits to a wallet that never touches a browser terminal.
  • Verify the domain every single time. Bookmark it and stop using search results to get there.
  • Use the multi-wallet feature to separate strategies, so one compromised session does not expose everything.
  • Assume anything promising a Photon token, airdrop or claim page is a scam, because there is no token.

Check the Domain, Then Sign Up

Photon's genuine deployments all sit under tinyastro.io, and a documented drainer clone is operating elsewhere. Our link goes to the real Solana terminal, and the fee is a flat 1% each way with or without it.

Open Photon