Making self-custody usable for everyday users

A native iOS wallet that reached TestFlight beta before the company wound down the product ahead of public release. Familiar web2 patterns applied to onboarding, transactions, and trust in self-custodial crypto.

Role: End-to-end product design — UX/UI, research, prototyping · Native iOS · 2022

Kill Switch sheet listing active allowances — stETH with unlimited allowance to AAVE, MATIC with unlimited allowance to Orca — above a red “Drag to isolate” slider.

Guided onboarding over flexibility

Make first-time setup safe and understandable with clear defaults

Reduce risk, not just friction

Design flows that prevent irreversible mistakes

End-to-end wallet flows

Cover onboarding, transactions, and key management

Familiar patterns for unfamiliar systems

Use web2 mental models to explain web3

CONTEXT

Understanding web3 shouldn’t feel fragmented

Web3 tools are still built for crypto-native users. Newcomers are expected to manage wallets, fees, and transactions across disconnected interfaces—often without clear feedback or guidance. This creates high cognitive load in environments where mistakes are irreversible.

Portal explores how familiar web2 UX patterns can reduce risk, clarify actions, and make self-custody usable for everyday users.

Portal home screen in dark mode: a balance of 1.354,52 €, action buttons, and a list of assets — Ether, Matic, Uniswap and Lukso — with their values in euros.
The home screen leads with what you own, not what the chain calls it — balances in euros, actions in plain words.

CHALLENGES

No undo, no support desk, no second chances

The core problem is that self-custody removes every safety net users have spent twenty years learning to rely on. In web2, mistakes are recoverable — a wrong transfer can be reversed, a support team can restore access, a fraudulent charge can be disputed. On-chain, a mistyped address or a malicious approval is final, and no convention existed for communicating that finality without terrifying people out of the product.

The second problem compounds the first: smart contract interactions are opaque by default, so users routinely confirm actions they don't understand — blind-signing is one of the most common ways people lose funds. And there was no established web3 pattern language to borrow from, so the work became adapting the web2 vocabulary users already trust — confirmation, progressive disclosure, undo-adjacent safeguards — to a context where "undo" doesn't exist. The kill switch, the step-by-step approval sheets, and the assets/interactions/permissions IA all come out of that one constraint: designing for irreversibility without designing fear.

Two flows. In web2: mistake, support steps in, reversed. On-chain: mistake, final.

RESEARCH

Key insights from research

Users don’t understand what actions actually do

Transactions feel opaque—users confirm actions without fully understanding outcomes, fees, or consequences.

Fear of irreversible mistakes blocks engagement

Self-custody introduces high perceived risk, leading to hesitation or reliance on external tools.

Web2 mental models don’t transfer

Users expect confirmation, feedback, and reversibility—patterns that are often missing in web3 tools.

These insights shaped how I approached onboarding, transactions, and risk reduction across the product.

Discovery board — personas, problem statements, and HMWs that the three insights above were distilled from. Click in to explore.
Collage of Portal app screens set at an angle: seed phrase setup, the wallet home screen, an NFT gallery and the welcome screen.

APPROACH

Translating web2 UX to web3 systems

Web3 introduces new constraints—irreversible actions, visible transactions, and decentralized logic. Instead of reinventing interaction patterns, I explored how established web2 principles—like feedback, confirmation, and progressive disclosure—can be adapted to these constraints.

This approach makes complex systems more understandable without hiding their underlying mechanics.

Table comparing web2 and web3 for twelve UX principles, from visibility of system status and error prevention to help and documentation.

PRINCIPLES

Designing for clarity, safety, and trust

Make actions understandable

Clearly communicate what will happen before users commit.

Reduce irreversible risk
Design safeguards for high-impact decisions.

Guide users through complexity

Break down flows into manageable steps.

Expose system status

Show what’s happening and what just happened.

Leverage familiar patterns

Use known interaction models to explain new systems.

NFT detail screen showing the artwork “Psychedelic Daphnē”, a “View on OpenSea” button, the network and a description.
Clear transaction summaries reduce uncertainty before committing on-chain.
Token swap screen: ETH to MATIC with an estimated fee, a Swap button and a number pad.
Even simple actions like swapping tokens require understanding fees, networks, and outcomes upfront.

FLOWS

Structuring complex actions into clear flows

I mapped key user journeys—from onboarding to transactions—into structured, step-by-step flows to make complex actions understandable and predictable.

Mapping these flows made friction, decision points, and missing safeguards explicit—especially around irreversible actions and transaction feedback. These insights directly informed how guidance, confirmations, and constraints were introduced across the product.

Token swap flow

Exposed confusion around fees and irreversible confirmations—leading to clearer review steps and stronger transaction feedback.

Flow chart of the token swap: from opening the wallet, choosing tokens and amount, fetching a quote and reviewing, to confirming and seeing the new assets; with a branch for custom fee settings.

Wallet top-up flow

Revealed early drop-off points around funding and network selection—informing where defaults and guidance were needed.

Flow chart of the wallet top-up: download, onboarding and sign-up, then choosing cryptocurrency, amount and payment method, reviewing and confirming, to the new balance.

To support these flows at scale, I defined a clear underlying structure:

Information architecture

Defined a system that separates assets, interactions, and permissions—making complex wallet behavior easier to navigate and reason about.

Information architecture tree: assets, approval and signature, browser and transactions at the top level, with actions such as buy, send, receive, swap, bridge, wallets and profile below.

SOLUTIONS

Making transactions understandable and safe

Interacting with smart contracts is one of the most critical and risky moments in web3. I designed a system of bottom sheets that guides users through approvals, signatures, and confirmations — breaking complex actions into clear, step-by-step decisions.

Contextual information such as fees, outcomes, and risks is surfaced at the right moment, helping users act with confidence.

“Confirm Transaction” sheet: 0.2345 ETH to Aave with the wallet, network, address, estimated fee, and Cancel and Confirm buttons.
Confirm transaction — Clear transaction summaries reduce uncertainty before committing on-chain.
“Transaction fee” sheet with normal, fast, urgent and custom options and fields for base fee and miner tip.
Custom transaction fees —
Flexible fee controls balance simplicity for beginners with control for advanced users.
Real-time feedback helps users understand system state and outcomes.
In-app browser with bookmarks, a gas price widget and recently visited dApps.
Browser — Integrated dApp access reduces context switching and keeps interactions in one place.
Network selection sheet listing Ethereum, Polygon, Solana, Optimism, Avalanche, Gnosis and BNB Smart Chain.
Network selection — Making networks explicit helps users understand where actions happen.
Kill Switch sheet with active allowances and a red “Drag to isolate” slider.
Allowance management — Visibility into permissions reduces hidden risk in DeFi interactions.
Kill Switch sheet after isolating: “No allowances” for both tokens and a green “Success” state.
Kill switch — A single action to revoke permissions enables fast recovery in high-risk situations.

REFLECTION

Designing for responsibility in web3

Designing for self-custody means designing for responsibility. Unlike traditional products, mistakes in web3 are often irreversible, which fundamentally changes how users approach interaction.

This project reinforced that usability in web3 isn’t about removing complexity—it’s about making it understandable and safe to navigate. The goal is not to hide systems, but to expose them in a way that users can build confidence over time.

It also highlighted the importance of designing beyond individual screens. Trust emerges across flows, feedback, and consistency—not from isolated UI decisions.

Ultimately, the challenge is not reducing friction, but placing it intentionally—where it protects users without blocking progress. Portal shipped as a native iOS build and went out through TestFlight. The company wound the product down before public release, so it never reached the App Store — but the flows below shipped in a working build, not a prototype.

I design systems, not just screens—products that stay clear under real-world use.

Back to Top