Open Photon →

Is Photon Safe? Custody, Key Security & the Fake Photon Sites (2026)

By Concept211 (@Concept211)Updated: August 6, 202611 min readLast reviewed: August 2026
Table of Contents

"Is Photon safe" is really four separate questions wearing one coat: does the platform hold your money, has it ever been breached, does it treat your trades honestly, and can you tell the real site from a copy. Three of those have reasonably clear answers. One of them is where almost all the actual losses happen, and it has nothing to do with Photon's code.

This page works through each in turn, sourced to Photon's own documentation, its Terms of Use, and the security research that exists on fake Photon sites. Where the sources conflict or where a claim could not be verified against a primary source, that is stated rather than smoothed over.

Disclosure: this site carries referral links to Photon. Using them costs you nothing extra.

Photon is non-custodial. It generates a Solana wallet for your account, shows you the private key exactly once, and then has no mechanism to recover it for you. That design removes platform custody risk and replaces it with key-management risk, which is now entirely yours. No documented hack of Photon exists. Documented fake Photon sites do.

The custody model, in plain terms

When you sign up at photon-sol.tinyastro.io, Photon generates a dedicated Solana logo - the chain Photon trades on Solana wallet tied to your account. The private key for that wallet is displayed once, behind a reveal slider, during signup. You copy it down or you do not. There is no second showing built into the flow as a safety net.

That key is exportable, and Photon's documented mobile path depends on it: you retrieve the key from Photon and import it into Phantom logo - Solana wallet used to import an exported Photon key Phantom, then use Photon inside Phantom's in-app browser. There is no native Photon mobile app, so this import is the mobile experience. It is also the proof that you genuinely hold the keys, because a key you can export into a wallet of your choosing is a key the platform does not control exclusively.

Photon's Terms of Use are blunt about where that leaves you:

"the Company has no way of granting you access to the site if you lose access to, or control of, your Wallet"

and

"you are solely responsible for maintaining the security of your account and control over any usernames, passwords, public and/or private keys."

Read those two lines as the whole security policy, because functionally they are. There is no account recovery and no support queue that ends with someone restoring your wallet. The getting started guide covers the signup and key reveal step by step, and the single most important minute of that process is the one where the key is on screen.

The key reveal happens once

Do not click through the reveal slider until you already know where the key is going. Have your password manager open, or a pen and paper in hand, before you start. Once that screen is gone, Photon has no mechanism to bring it back, and neither does anyone else.

One mechanism deserves a flag rather than an explanation. Photon is reported to retain an encrypted session copy of your key so that trades can execute at terminal speed without a wallet prompt on every fill. We could not verify that in Photon's documentation, and we are not going to describe how it works, because we do not know. Treat it as unverified. What it does mean, if true, is that an active Photon session is a meaningful thing to leave open on a shared or compromised machine. Sign out on any device that is not yours.

Has Photon ever been hacked?

No public source documents a hack, exploit or drain of Photon itself. Searches for a Photon exploit, a Photon drain event, or a Tiny Astro breach return nothing. That is an absence of evidence rather than a security audit, and it should be read as exactly that much: nobody has published an incident, and Photon has been operating since January 2024 with enough volume through it to be a worthwhile target.

There is one incident that gets misattributed often enough to be worth clearing up. In August 2022, roughly 8,000 Solana wallets were drained of somewhere between $5.8M and $8M. That was the Slope wallet seed phrase leak: Slope's mobile app transmitted seed phrases to a logging service, and whoever read those logs emptied the wallets. Elliptic's analysis traces it to Slope. It predates Photon's launch by well over a year and has no connection to any trading terminal. If you find a page implying Photon was involved, that page is confusing two unrelated things.

The two-factor question nobody can source

Several third-party review sites state that Photon offers two-factor authentication. It appears nowhere in Photon's Terms of Use, nowhere in the Settings documentation, and nowhere in the mobile sign-up, login or trading pages. We could not resolve the contradiction, so here it is unresolved: the claim exists, the primary-source confirmation does not.

The practical stance either way is the same. Plan as though your private key is the only credential that matters, because in a non-custodial model it is. A 2FA prompt protects a login session. It does not protect a key that has already leaked.

Open the real Photon, not a copy of it

Sign up through this link and you land on photon-sol.tinyastro.io, the domain Photon actually operates. Bookmark it once you are there and never reach the site through a search result again.

Open Photon

Fake Photon sites are the documented risk

Every documented loss connected to the Photon name traces back to somebody typing or clicking their way onto a site that was not Photon.

A crypto drainer operating at speedtrade[.]icu copies Photon's interface closely enough to pass a glance. Connect a wallet to it and a silent drainer begins moving assets out, with no confirmation prompt that reads like a theft. PCRisk documented it in a removal guide updated 2025-12-15, and that write-up explicitly names photon.tinyastro.io as the genuine platform being impersonated.

A second site, wwwphoton.com, surfaced using Photon's exact tagline, "Your Trusted Platform for Token Discovery & Trading." We have not confirmed what it does, so we are calling it what the evidence supports: a probable impersonator, unverified. Treat it as hostile until somebody proves otherwise.

The trick to watch for is the hyphen-for-dot swap. Photon's real Solana domain is photon-sol.tinyastro.io, which already contains a hyphen. That makes it unusually easy to fake, because a variant like photon.sol.tinyastro.io or photon-sol-tinyastro.io looks correct to an eye that has stopped reading and started pattern-matching. Read the domain right to left instead: the last two labels before the first slash must be tinyastro.io.

Canonical domains versus known fakes

DomainStatus
photon-sol.tinyastro.ioReal. Solana deployment, the primary one
photon.tinyastro.ioReal. Generic entry point, named by PCRisk as the genuine platform
photon-bnb.tinyastro.ioReal. BNB Chain deployment
photon-base.tinyastro.ioReal. Base deployment
Ethereum deploymentRetired. Returns a 301 permanent redirect
speedtrade[.]icuConfirmed drainer. Mimics the Photon UI, empties any wallet that connects
wwwphoton.comProbable impersonator, unverified. Uses Photon's exact tagline
Anything not ending in tinyastro.ioNot Photon

One line covers it: every real Photon deployment lives under tinyastro.io. A domain that does not end there is not Photon, regardless of how the page looks. There is no photon.trade, and no official app on any other registrable domain we could find.

Search ads are a phishing channel

Do not reach Photon through a search engine. Paid placements above organic results are bought by whoever pays, impersonators included, and the displayed URL in an ad is not a guarantee of the destination. Reach the real site once, verify the domain character by character, bookmark it, and use only the bookmark from then on. This single habit defeats nearly every phishing variant described on this page.

Does Photon trade against its users?

The accusation shows up in forum threads: that a terminal with visibility into pending orders could sandwich its own users. For Photon specifically, no sourced allegation exists. We found no research, no on-chain analysis and no credible report that Photon runs a sandwich bot against the flow it handles.

MEV on Solana is genuinely large, which is why the suspicion is plausible in the abstract rather than specific to Photon. One bot known as "arsc" extracted roughly $30M in two months through sandwich arbitrage, per FXStreet. None of that is attributed to Photon.

What Photon does document is Smart-MEV Protection, and it is worth understanding precisely rather than trusting as a label. It governs how your bribe reaches validators:

ModeRouting rule
Fast ModeBribes under 0.001 SOL route direct to Jito logo - Solana MEV infrastructure and tip routing Jito; larger bribes route via Bloxroute
Secure ModeSame logic with the threshold set at 0.002 SOL
Default SpeedStandard priority fee and bribe handling
Auto SpeedAdjusts priority fee and bribe from recent successful transactions

Source: Photon's Smart-MEV Protection page. That is a routing policy, and it changes how your transaction reaches a block producer. It is not a guarantee that you will never be sandwiched, and Photon does not claim it is. The trading guides cover how the modes interact with the S1, S2 and S3 presets, and the fee guides explain why the bribe you set is not a Photon fee at all.

Regulation, KYC and what that implies

Photon requires no KYC, which is standard for the Solana terminal category and is part of why signup takes under a minute. No regulatory action against Photon was found, and no regulator has published a statement naming it in either direction. That is neutral information, not a clearance.

What it means practically is that there is no deposit insurance and no supervisory body to appeal to. Photon's own Terms already said as much. Your recourse if something goes wrong is the blockchain record and your own key management, which is the same recourse you have with any self-custodied wallet.

Photon's operator is also opaque. No corporate registry entry, incorporation jurisdiction, named founder or funding round could be located. That is normal in this category, where BullX and Trojan were equally anonymous, but normal is not the same as reassuring. The about page explains how this site handles claims we cannot source, and the ecosystem section covers the related question of why any token claiming to be "the Photon token" is a scam.

Non-custodial means nobody can freeze your funds, and it also means nobody can return them. Every protection you get on Photon is one you set up yourself, before you need it.

What users actually complain about

Trustpilot reviews of Photon include a recurring pattern of deposit shortfalls, phrased along the lines of "deposited 0.15 SOL, only 0.12 arrived," alongside complaints about slow or absent support.

Both deserve context rather than amplification. A deposit gap can be a genuine platform problem, or it can be network fees plus the 1% trade fee being read as a missing deposit, or it can be something else entirely: a user who was never on the real platform. Given a confirmed drainer that clones Photon's interface, a share of any "my funds vanished" report in this category belongs to the phishing clone rather than to Photon. Nothing in these reviews rises to confirmed platform fraud, and we are not going to present it that way. The troubleshooting section walks through the ordinary causes of balance discrepancies, which resolve most of these cases.

The support complaints are more consistent and easier to credit. Assume that if something goes wrong, you are solving it yourself. That assumption should shape how much you keep in the account.

Set the wallet up properly the first time

Sign up, save the key somewhere durable before you fund anything, and send a test amount first. Getting the custody hygiene right at minute one is the whole job.

Try Photon

A key-security checklist that holds up

Save the key to a password manager, not to your camera roll. A screenshot in cloud photos is the worst common option: it syncs to every device on the account, and photo libraries get shared, backed up and restored to new phones without anyone thinking about what is inside them. A password manager entry is encrypted, searchable, and does not end up in a shared album by accident.

Write it on paper as the backup to the backup. Two copies, two physical locations, neither of them a sticky note on the monitor. Paper survives the failure mode a password manager does not: losing the master password.

Never type the key into anything except a wallet you opened yourself. No support agent will ask for it and no airdrop claim needs it. Any request for that string is theft in progress.

Fund the Photon wallet like a hot wallet, because that is what it is. A browser-resident key used for fast trading is exposed to browser extensions, clipboard managers and whatever else runs on the machine. Put in what you are willing to lose on a bad week, and top it up rather than parking a portfolio in it. The fee guides make the same point from a different direction: turnover is what costs you on Photon, so a large idle balance in the trading wallet earns nothing and risks everything.

Keep long-term holdings behind hardware. Anything you are not actively trading belongs in a wallet whose key has never touched an internet-connected device. Ledger logo - hardware wallet for holdings kept off a hot trading wallet Ledger and Trezor logo - hardware wallet for holdings kept off a hot trading wallet Trezor are the two established options; either keeps the signing key inside the device, so a compromised browser can request a transaction but cannot sign one without physical confirmation. The separation is the point. Trading capital in the hot wallet, savings in cold storage, and a deliberate transfer between them.

Bookmark the domain and stop searching for it. Covered above, and it is the highest-value item on this list.

Rotate after any exposure. If a key was ever pasted into a browser field, sent in a message, stored on a machine you later suspect, or typed on a device that is not yours, treat it as burned. Create a new Photon account, move the funds, abandon the old wallet. Keys do not get un-leaked.

The threat model for Photon is not the platform. It is your clipboard, your cloud backups, your search results and your browser extensions. Every documented Photon-related loss so far came from one of those, not from Photon's servers.

The honest verdict

Photon is non-custodial, has no documented breach, faces no regulatory action, and gives you an exportable key you can move into Phantom logo - Solana wallet used to import an exported Photon key Phantom whenever you like. On the questions people usually mean when they ask whether a platform is legit, it holds up.

The gaps are real and worth naming. Its 2FA situation is unresolved between third-party claims and Photon's own silence. The encrypted session key mechanism is reported but unverified. The operator is anonymous. Support is thin, by consistent user report. And the key reveal is a single irreversible moment that new users routinely rush.

Set against that, the one category of loss that is confirmed and ongoing is phishing. A working drainer at speedtrade[.]icu is documented. A probable clone at wwwphoton.com is live. Both are defeated by a bookmark and thirty seconds of reading a domain carefully.

If you want the rest of the picture before you commit capital, the comparison cluster covers how Photon stacks up against the terminals that took its market share, including a full Photon vs Axiom comparison, markets tracks the pairs people actually trade, the referral page explains what Photon does and does not publish about its program, and the full guide library and security section go deeper on each piece.

Verify the domain, then trade

photon-sol.tinyastro.io is the real Solana deployment. Open it through this link, check the address bar character by character, bookmark it, and never arrive from a search result again.

Open Photon

Frequently Asked Questions

Photon is non-custodial, so the platform never holds your funds and cannot freeze or seize them. No hack or exploit of Photon itself has been documented. The two real risks are ones you carry yourself: losing the private key Photon shows you once at signup, and landing on a fake Photon site that drains your wallet the moment you connect it.

There is no evidence that Photon is a scam. It has operated since January 2024 with more than 440 million dollars of lifetime fee revenue tracked publicly by DefiLlama, and no regulator has taken action against it. What does exist are impersonator sites copying Photon's interface. A confirmed fake at speedtrade dot icu drains any wallet that connects to it, so verify the domain before you sign in.

You lose access to that wallet permanently. Photon's Terms of Use state the company has no way of granting you access to the site if you lose access to or control of your wallet, and that you are solely responsible for maintaining the security of your keys. There is no password reset, no support ticket and no recovery path.

No hack or exploit of Photon itself has been found in any public source. The August 2022 Solana wallet drain that people sometimes attribute to Photon was the Slope wallet seed phrase leak, which cost roughly 5.8 to 8 million dollars across about 8,000 wallets and happened well before Photon launched. Elliptic's analysis traces it to Slope, not to any trading terminal.

Sources conflict and we could not resolve it. Several third-party review sites claim Photon offers 2FA, but it is not mentioned anywhere in Photon's Terms of Use, its Settings documentation or its mobile pages. Until Photon documents it, assume your private key is the only thing standing between an attacker and your funds.

Disclaimer: This content is for informational purposes only and does not constitute financial advice. Trading perpetual futures involves substantial risk of loss. Past performance is not indicative of future results. Always do your own research before trading. This site contains referral links - see our disclosure for details.

Ready to Start Trading?

Photon builds a Solana wallet in the browser, shows you the private key once, and charges a flat 1% on every buy and every sell. Our referral link costs you nothing extra, because there is no discount to give.

Open Photon